Method for managing the security of a connection and associated electronic device

EP4740119A1Pending Publication Date: 2026-05-13ORANGE SA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
ORANGE SA
Filing Date
2024-06-26
Publication Date
2026-05-13

AI Technical Summary

Technical Problem

The existing wireless telecommunications network architectures, particularly those defined by the 3GPP consortium, lack flexibility and scalability, making it difficult for operators to ensure consistent security policies across networks, especially with the increased complexity and diversity of traffic demands in 5G networks, and the involvement of multiple service providers leads to a loss of control over security configurations.

Method used

A method is introduced where a security module on the user terminal generates and analyzes a history of security events, transmitting the results to a control module through a secure session, allowing operators to monitor and enforce security policies across the network, even when equipment is not directly under their control, and includes features for anomaly detection, security parameter testing, and automation of security tests.

Benefits of technology

This method enables telecommunications operators to effectively implement and monitor security policies across the network, detecting anomalies and ensuring compliance with defined security measures, even in complex 5G environments with multiple service providers, thereby enhancing network security and reducing the risk of compromised equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024067890_02012025_PF_FP_ABST
    Figure EP2024067890_02012025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for managing the security of a connection between a user terminal and a telecommunications network, the method comprising the following steps, which are implemented by a security module (AVS) of the user terminal (UE): generating a history of events that relate to the security of the connection; analysing the generated history; transmitting, to a control module (AVSC) of the telecommunications network, a result of the analysis through a secure session.
Need to check novelty before this filing date? Find Prior Art

Description

Method for managing the security of a connection and associated electronic device

[0001] The present invention belongs to the general field of telecommunications, and in particular wireless communications implemented on radio-type networks such as mobile networks (e.g. 2G, 3G, 4G, 5G, B5G – the acronym for “Beyond 5G” – etc.), etc. It relates more particularly to a method for managing the security of a connection between a user terminal and a telecommunications network. It also relates to an electronic device configured to implement such a method.

[0002] In order to adapt to the continuous and ever-increasing growth of data traffic emitted by wireless telecommunications systems, various technologies are currently being implemented and are still being refined for optimal operation in the years to come.

[0003] The architecture of wireless telecommunications networks currently deployed or being deployed is defined by the standards consortium known as 3GPP (Third Generation Partnership Project). This is particularly the case for second-generation ("2G or GSM"), third-generation ("3G"), and fourth-generation ("4G") wireless networks.

[0004] Up to the fourth generation, the network architectures defined by the 3GPP consortium are most often based on specific equipment, dedicated to precise functionalities, whether at the level of the access network or the core network, particularly with regard to the transmission of packets from or to a mobile terminal.

[0005] The inherent lack of flexibility and scalability of this type of architecture has led the 3GPP consortium to consider adopting more flexible architectures for the so-called "5G" generation of wireless networks, in order to be able to respond quickly to extremely diverse demands in terms of traffic and / or quality of service.

[0006] To address these extremely diverse constraints, 5G relies in particular on the division of network functions into services, and on the virtualization of these network functions. The virtualization of network functions consists of deploying functions usually satisfied by dedicated and specific equipment on generic servers located in data centers ("data centers" in English terminology). These functions are then implemented in the form of computer programs that can be easily activated, deactivated and configured according to needs. Memory resources or computing capacity can then be dynamically allocated.

[0007] This division of network functions into services ultimately aims to facilitate the deployment of core network (CN) and radio access network (RAN) virtualization. More generally, one of the objectives of the 3GPP consortium is to define a mobile network architecture that allows equipment and / or software modules from different suppliers to communicate.

[0008] The involvement of different service providers to implement a connection between a user terminal and a telecommunications network results in a loss of control on the part of the operator of a telecommunications network to which a customer has subscribed. However, it is important for the operator to be able to ensure the effective implementation, across the entire network, of a previously determined security policy.

[0009] Furthermore, even if an operator correctly configures the various equipment in its telecommunications network, a piece of equipment or network function can be compromised and its security impaired without the operator being alerted. In the context of 5G, this risk is increased by the increase in the number of base stations required to support higher levels of data traffic, and by the increasing complexity of operational models.

[0010] Finally, a user of a roaming terminal is typically dependent on the security policy defined by the network operator in charge of the visited telecommunications network. A roaming agreement defining security measures is generally established between the operator with which the user has subscribed and the operator in charge of the visited telecommunications network, but in this situation, it is also important for the operator with which the user has subscribed to be able to ensure the effective implementation, across the entire network, of a previously determined security policy.

[0011] The present invention aims to remedy all or part of the drawbacks of the prior art, in particular those set out above, by proposing a solution which allows a telecommunications network operator with whom a customer has taken out a subscription to verify whether a given security policy is actually implemented on a network used by this customer, even though certain functions and / or equipment of said network are not directly under the control of said operator.

[0012] The invention can also contribute to the automation of security tests, during the experimental phases (verification of suitability for proper functioning carried out on a representative configuration of the network, tests in experimental areas with test or commercial terminals) or be used for monitoring the production phases of new functionalities or new equipment.

[0013] In certain use cases, the invention is also implemented for the purpose of diagnosing or resolving a security incident ticket opened by a customer.

[0014] To this end, and according to a first aspect, the invention relates to a method for managing the security of a connection between a user terminal and a telecommunications network managed by a telecommunications operator, the method comprising: generation, by a security module of the user terminal, of a history of events relating to the security of said connection, the security module being managed by the telecommunications operator; analysis, by the security module, of the generated history; and transmission, by the security module and to a control module of the telecommunications network, of a result of the analysis through a secure session, the control module being managed by the telecommunications operator.

[0015] Generally speaking, it is considered that the steps of a process should not be interpreted as being linked to a notion of temporal succession.

[0016] In particular modes of implementation, the management method may further comprise one or more of the following characteristics, taken individually or in all technically possible combinations.

[0017] In particular embodiments, security is managed only on a portion of the connection between the user terminal and the telecommunications network. Thus, according to a first example, security is managed on the connection between the user terminal and a base station to which said user terminal is attached. According to a second example, security is managed on the connection between the user terminal and a unit – e.g., distributed (O-DU) or centralized (O-CU) – of the radio access network of the telecommunications network or of a visited telecommunications network. According to a third example, security is managed on the connection between the user terminal and a “User Plane Function” (UPF) module of the core network of the telecommunications network.

[0018] This “user plane function” module then acts as a gateway between the radio access network (RAN) and a data network (DN), such as the Internet or a local / private network.

[0019] In particular embodiments, the user terminal is connected to the telecommunications network through a visited telecommunications network managed by another telecommunications operator, and the event history includes data relating to the security of said visited telecommunications network.

[0020] The said telecommunications network then corresponds to the so-called “nominal” or “home” network according to Anglo-Saxon terminology.

[0021] This feature offers the advantage of allowing the detection of possible anomalies in the security controls falling under the responsibility of the other operator. Indeed, this other operator (known as the partner operator) manages the configuration of its equipment (hardware and software versions, equipment configuration parameters), but certain parameters may be incorrectly configured and become inoperative in their effects (e.g., parameter incompatibilities, incompatibilities with installed software, etc.).

[0022] In particular embodiments, said data includes data relating to the encryption and / or integrity control of the connection between said user terminal and a base station of the visited telecommunications network to which said user terminal is connected.

[0023] In particular embodiments, the method further comprises a transmission, by the security module, of a plurality of security parameter test requests to the telecommunications network or a visited telecommunications network managed by another telecommunications operator, and the analysis comprises a determination of a behavior of the telecommunications network or the visited telecommunications network in response to the transmissions.

[0024] In particular modes of implementation, the analysis includes determining a score representative of a degree of security of said connection based on the generated history.

[0025] In particular embodiments, the method further comprises: reception, by a radio module of the user terminal, of a signaling message originating from the telecommunications network or from a visited telecommunications network managed by another telecommunications operator; and, access, by the security module, to the signaling message through an application programming interface provided by the radio module.

[0026] In particular implementations, access to the API is secured by an encryption algorithm.

[0027] In particular embodiments, the user terminal comprises a second security module, the security module – called the first security module – and the second security module being isolated from each other, the method further comprising, following reception, by a radio module of the user terminal of a signaling message, a determination, by the radio module, of a recipient security module from among the first security module and the second security module.

[0028] In particular embodiments, the first and second security modules are managed by the same telecommunications operator. Alternatively, the first and second security modules are managed by separate telecommunications operators.

[0029] In particular modes of implementation, the session is secured by the use of “Non Access Stratum” protocols between the security module and an access and mobility management module of said telecommunications network or of a visited telecommunications network; or the use of a secure hypertext transfer protocol between the security module and the control module.

[0030] In particular implementation modes, the access and mobility management module is configured to register user terminals, and to manage a location of said user terminals on said telecommunications network (3GPP and / or non-3GPP).

[0031] In particular implementation modes, the telecommunications network is compliant with the fifth generation (5G or 5GS), and the access and mobility management module of the telecommunications network corresponds to the AMF entity (acronym for “Access and Mobility Management Function”).

[0032] In particular modes of implementation, the security module includes an application programming interface (or API) comprising a function for accessing the event history and / or the result of the analysis, said application programming interface being accessible by a computer application of the user terminal.

[0033] These features are advantageous in that they allow a computer application on the user terminal to communicate with the security module without having to know the implementation details of the functions of this module. In addition, these features allow the functions implemented by the security module to be presented as services accessible through the HTTP / 1.1 or HTTP / 2 protocol.

[0034] In particular implementation modes, the application programming interface is REST-based.

[0035] Using a REST (REpresentational State Transfer) type API is advantageous in that it provides a standardized means of communication using the HTTP protocol between the security module and the user terminal's computer application.

[0036] In particular embodiments, the event history is generated from at least one of: data relating to a use of an authentication protocol for at least one portion of the connection between the user terminal and said telecommunications network, such as the connection portion between the user terminal and a base station to which said user terminal is connected; data relating to a use of an encryption algorithm for at least one portion of the connection between the user terminal and the telecommunications network, such as the connection portion between the user terminal and a base station to which said user terminal is connected; data relating to the integrity control implemented by the user terminal and / or a base station to which said user terminal is connected;data relating to the use of an encryption algorithm to encrypt context data of the user terminal; a modification of a temporary identifier of the user terminal; a transmission, by the user terminal, of an IMSI identifier (the acronym for “International Mobile Subscriber Identity”), or a SUCI identifier (the acronym for “Subscription Concealed Identifier”); data relating to encryption or integrity control of a PDCP layer; data relating to context switching in the context of an intercellular transfer (or “handover” according to English terminology); data relating to the security of the “Non Access Stratum” protocols used between the user terminal and the telecommunications network; data relating to the switching of a connection to a previous generation connection;and, data resulting from the reception of messages from a cell neighboring the cell in which said user terminal is located;

[0037] According to a second aspect, the invention relates to a computer program comprising instructions for implementing a management method, when said program is executed by a processor.

[0038] According to a third aspect, the invention relates to a computer-readable recording medium on which the computer program according to the invention is recorded.

[0039] According to a fourth aspect, the invention relates to an electronic device capable of managing the security of a connection between a user terminal and a telecommunications network managed by a telecommunications operator,

[0040] the electronic device comprising a security module managed by the telecommunications operator, the security module comprising: a sub-module for generating a history of events relating to the security of said connection; a sub-module for analyzing the generated history; a sub-module for transmitting, to a control module managed by said telecommunications operator and belonging to said telecommunications network, a result of said analysis through a secure session.

[0041] In particular embodiments, the electronic device is a secure element including an application managed by the telecommunications operator, and the application includes the security module.

[0042] In particular embodiments, the electronic device is a user terminal and the security module is deployed in a secure execution environment of said user terminal.

[0043] According to a fifth aspect, the invention relates to a communication system comprising an electronic device according to the invention, and another electronic device comprising a control module, the control module comprising: a sub-module for receiving, from the security module of the first electronic device, a result of said analysis through a secure session; and, a sub-module for verifying the security of the connection as a function of said result.

[0044] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate an exemplary embodiment thereof without any limiting character. In the figures:

[0045] is a first example of a wireless communication system in which a management method according to the invention is implemented;

[0046] is a second example of a wireless communication system in which a management method according to the invention is implemented;

[0047] is a third example of a wireless communication system in which a management method according to the invention is implemented;

[0048] schematically represents sub-modules of a security module embedded in a user terminal, according to an exemplary implementation of the invention;

[0049] represents an example of hardware architecture of an electronic device in which a security module is embedded;

[0050] schematically represents sub-modules of a control module, according to an exemplary implementation of the invention;

[0051] represents an example of hardware architecture of an electronic device comprising a control module; and,

[0052] illustrates, in the form of a flowchart, an example of security management of a connection between a user terminal and a telecommunications network.

[0053] This is an example of a wireless communication system in which a management method according to the invention is implemented.

[0054] This system comprises a telecommunications network (HPMN) – also referred to as a “home telecommunications network” in the remainder of the description – including a radio access network (RAN) and a core network (CN) connected to the radio access network (RAN). The radio access network (RAN) comprises at least one base station. The communication system further comprises at least one user terminal (UE) connected to the radio access network (RAN).

[0055] In the present embodiment, and for the purpose of simplifying the description, it is considered that the wireless communication system comprises a single user terminal (UE), as well as a radio access network (RAN) comprising a single transmitting device (gNB). It should however be noted that no limitation is attached to the number of transmitting devices (gNB) or to the number of user terminals (UE). The following developments are indeed generalizable without difficulty by those skilled in the art to the case where more than one transmitting device (gNB) and one user terminal (UE) are considered.

[0056] The user terminal (UE), the radio access network (RAN) and the core network (CN) belong to a wireless telecommunications network and are able to communicate with each other in a frequency band associated with this wireless telecommunications network. For the remainder of the description, it is considered in a non-limiting manner that said telecommunications network is a mobile network of the 5G or 5GS type (the fifth generation of mobile telephone network standards). However, it should be noted that the invention remains applicable to other types of telecommunications network, such as for example a 4G mobile network (the fourth generation of mobile telephone network standards), and / or B5G (acronym for "Beyond 5G").

[0057] For example, the Radio Access Network (RAN) is compliant with 3GPP TS 38.401, “NG-RAN; Architecture description”, version 17.4.0 published on April 3, 2023. The Radio Access Network architecture defined by the 3GPP consortium aims to facilitate the deployment of Radio Access Network (RAN) virtualization, and to enable equipment and / or software modules from different vendors to communicate with each other.

[0058] Alternatively, the radio access network (RAN) is, for example, compliant with the C-RAN paradigm ("Cloud-RAN"). This architecture combines virtualization and centralization of the functionalities of a base station by means of cloud computing ("cloud computing"). In a C-RAN architecture, the processing units ("baseband units") are no longer located in the immediate vicinity of the base station, but are relocated and centralized within a centralized pool ("BBU pool").

[0059] Alternatively, the radio access network (RAN) is, for example, compliant with the V-RAN (“Virtual-RAN”) paradigm. A virtual radio access network (vRAN) is a radio access network (RAN) whose network functions are deployed as virtualized instances located at different locations on the network, for example, according to a deployment strategy of the telecommunications operator. This approach offers the advantage of limiting the use of expensive equipment, and allows the creation of isolated subnetworks (“slices” in English terminology), which coexist simultaneously on the same hardware.

[0060] Thus, this radio access network (RAN) comprises at least one base station whose network functions are deployed on – or in the immediate vicinity of – the same equipment, or virtualized and deployed on remote equipment. A base station is sometimes called a "nodeB" in 3G networks, "eNodeB" according to the LTE standard (acronym for "Long Term Evolution") and "gNB" in 5G networks.

[0061] As illustrated by the, the core network (CN) comprises a “user plane function” (UPF) module connected to the radio access network RAN ​​through an N3 interface. This “user plane function” (UPF) module is also connected to a data network DN (such as the Internet or a local / private network) through an N6 interface.

[0062] The “user plane function” module corresponds for example to the UPF module defined by the 3GPP 23.501 specification “System architecture for the 5G System (5GS)”, version 18.1.0, published on April 5, 2023. In this case, the “user plane function” (UPF) module is configured to route data from the user terminal (UE) through the core network (CN). More specifically, this “user plane function” module acts as a gateway between the radio access network (RAN) and a data network (DN) of the core network (CN).

[0063] The core network (CN) further comprises an access and mobility management module (AMF) of the telecommunications network connected to the radio access network (RAN) via an N2 interface. This access and mobility management module (AMF) corresponds for example to the AMF module defined by the 3GPP TS 23.501 specification “System architecture for the 5G System (5GS)”, version 18.1.0 published on April 5, 2023 and / or by the TS 33.501 specification “Security architecture and procedures for 5G System”, version 18.1.0, published on March 30, 2023. In this case, the access and mobility management module (AMF) is configured to control the user terminals (UE) wishing to access the telecommunications network (HPMN) to exchange data via the DN data network.

[0064] In the case where the user terminals are mobile, this AMF module is also responsible for managing a cell change (e.g., a switch from one base station to another), while ensuring that the data transfer is not interrupted.

[0065] This AMF module is connected through an N8 interface to a user profile management module (UDM). This user profile management module corresponds for example to the UDM module defined by the 3GPP TS 29.503 specification, “5G System; Unified Data Management Services; Stage 3”, version 18.1.0, published on March 29, 2023. In this case, the UDM module (acronym for “Unified Data Management”) is configured to manage the profile associated with the user terminal UE.

[0066] The core network also includes a module (AVSC) for controlling the security of a connection between the user terminal (UE) and the core network (CN), the functionalities of which are described with reference to the. This control module (AVSC) is managed by the telecommunications operator with which the user of the user terminal (UE) has taken out a subscription, i.e. the nominal operator in charge of the telecommunications network known as the “home network” in the event of roaming.

[0067] As illustrated by the, the communication system further comprises a user terminal (UE). The user terminal (UE) corresponds for example to a laptop, a personal assistant, a connected object, or a mobile telephone of the “smartphone” type.

[0068] This user terminal (UE) includes a secure element of the UICC card type (the acronym for "Universal Integrated Circuit Card") in which a USIM application (the acronym for "Universal Subscriber Identity Module") is deployed, comprising the parameters of a subscription taken out with the telecommunications operator in charge of the HPMN telecommunications network. This secure element (UICC) is connected to a radio module (BP) also called a "baseband processor" and providing application programming interfaces (APIs) to allow the applications of the user terminal (UE) to access data controlled - or even stored - by this radio module. These APIs are, for example, of the REST type, and their access is secured by the use of encryption keys.

[0069] The user terminal (UE) also includes a secure environment and referenced TEE, the acronym for "Trusted Execution Environment". This secure environment is isolated from other execution environments, and typically executed in parallel with a standard execution environment (e.g., Android or iOS (registered trademarks)). This secure environment offers a set of guarantees such as the integrity of the executed code, the use of secure communications, secure storage. This environment is for example based on the TrustZone technology from ARM (registered trademarks), or on the "Trusted Foundations" technology developed by Trusted Logic (registered trademarks).

[0070] This secure environment (TEE) includes a security module (AVS) managed by the telecommunications operator with which the user of the user terminal (UE) has subscribed, and whose functionalities are described with reference to the. This security module (AVS) comprises at least one application (APP). In particular implementation modes, the security module (AVS) provides at least one application programming interface (API) in order to be able to expose functions to other applications of the user terminal (UE), without the latter having to know the implementation details of these functions. These exposed functions are intended, for example, to allow access to an event history and / or to the result of the security analysis of at least one portion of the connection, or even to allow a display of this data on the user terminal (UE) through a graphical interface.

[0071] The is a second example of a wireless communication system in which a management method according to the invention is implemented. The HPMN telecommunications network is similar to that described with reference to the, and is therefore not redescribed, for the sake of brevity.

[0072] As illustrated in, the user terminal (UE) comprises a secure element of the UICC card type (the acronym for “Universal Integrated Circuit Card”) in which is deployed a USIM application (the acronym for “Universal Subscriber Identity Module”) comprising the parameters of a subscription taken out with the telecommunications operator in charge of the HPMN telecommunications network.

[0073] This secure element (UICC) also includes a security module (AVS) managed by the telecommunications operator with which the user of the user terminal (UE) has subscribed, and whose functionalities are described with reference to the. This security module (AVS) comprises at least one application (APP). In particular implementation modes, the security module (AVS) provides at least one application programming interface (API), in order to be able to expose functions to other applications of the user terminal (UE), without the latter having to know the implementation details of these functions.

[0074] This secure element (UICC) is connected to a radio module (BP) also called a “baseband processor” and providing application programming interfaces (APIs) to allow applications of the user terminal (UE) to access data controlled – or even stored – by this radio module.

[0075] Until now, the secure element has been described as a UICC type card. The invention nevertheless remains applicable in the case where this secure element is a so-called "embedded secure element", i.e. a chip separate from the processor of the user terminal (UE) and which contains a secure processor and tamper-proof storage. The invention nevertheless also remains applicable in the case where this secure element is a so-called "integrated" secure element, iUICC, currently under development by the industry and the GSMA (acronym for GSM Association).

[0076] This is a third example of a wireless communication system in which a management method according to the invention is implemented.

[0077] As illustrated by the, the system includes a user terminal (UE). This terminal is similar to that described with reference to the or to the, and is therefore not redescribed, for the sake of brevity.

[0078] This user terminal (UE) is connected to a data network (DN) managed by the telecommunications network operator through a so-called "visited" telecommunications network and referenced VPMN. This visited network VPNM comprises a radio access network (RAN) including at least one base station (gNB), as well as a visited core network (VCN). The radio access network (RAN) and this visited core network (VCN) are connected to each other through an N3 interface. The visited core network (VCN) comprises a VUPF "user plane function" module. The VUPF "user plane function" module corresponds for example to a UPF module as defined by the 3GPP 23.501 specification "System architecture for the 5G System (5GS)", version 18.1.0, published on April 5, 2023.In this context, the VUPF “user plane function” module is, for example, configured to route data between the user terminal (UE) and a “user plane function” (HUPF) module of the core network (HCN) of the telecommunications network (HPMN) via an N9 interface.

[0079] The visited core network (VCN) further comprises a module (AMF) for managing access and mobility of the visited telecommunications network (VPMN), this module being similar to that of the same name described with reference to the.

[0080] The visited telecommunications network (VPMN) is also connected to the telecommunications network (HPMN) with which the user of the user terminal (UE) has subscribed via an IPX network. This IPX network is, for example, compliant with specification IR.34, “Guidelines for IPX Provider networks”, version 17.0, published on May 18, 2021 by the GSM Association. This IPX network is typically of the IP type and allows the interconnection of several telecommunications operators, whose connection and service conditions are defined within the framework of commercial agreements.

[0081] As mentioned above, the HPMN telecommunications network comprises a core network (HCN) including a “user plane function” (HUPF) module. The “user plane function” (HUPF) module corresponds for example to a UPF module as defined by the 3GPP 23.501 specification “System architecture for the 5G System (5GS)”, version 18.1.0, published on April 5, 2023. In this context, the “user plane function” (HUPF) module is configured to route data between the visited network (VPMN) and a data network (DN) of the telecommunications network (HPMN) through an N6 interface.

[0082] The core network (HCN) of the HPMN telecommunications network further includes an AVSC module and a user profile management module (UDM), these modules being similar to those of the same name described with reference to the.

[0083] Alternatively, the data from the user terminal (UE) is no longer routed to a data network (DN) of the HPMN telecommunications network, but the “user plane function” VUPF module of the visited telecommunications network is then configured to route data between the user terminal (UE) and a data network (not shown) connected to said visited telecommunications network VPMN.

[0084] The diagram schematically represents sub-modules of a security module (AVS) embedded in a user terminal (UE), according to an exemplary implementation of the invention.

[0085] As illustrated by the, the user terminal (UE) embeds a security module (AVS). This security module (AVS) is managed by the telecommunications network operator, and includes the sub-modules MOD_GEN, MOD_DET and MOD_TX whose functionalities are described with reference to the.

[0086] It represents an example of hardware architecture of an electronic device, such as a user terminal (UE) or a secure element of the UICC or eSE card type, in which a security module (AVS) is embedded.

[0087] As illustrated by the, the electronic device has the hardware architecture of a computer. Thus, the electronic device comprises, in particular, a processor 1, a random access memory 2, a read-only memory 3 and a non-volatile memory 4. It also comprises a communication module 5.

[0088] The read-only memory 3 or the non-volatile memory 4 of the electronic device constitutes a recording medium as proposed, readable by the processor 1 and on which is recorded a computer program PROG_AVS in accordance with the invention, comprising instructions for the execution of steps of the management method as proposed below. The program PROG_AVS defines one or more functional sub-modules of the user terminal, which rely on or control the hardware elements 1 to 5 cited above, and which comprise in particular: a sub-module MOD_GEN for generating a history of events relating to the security of a connection; a sub-module MOD_DET for analyzing the generated history; a sub-module MOD_TX for transmitting, to a control module (AVSC) managed by the operator of the telecommunications network and belonging to said telecommunications network, a result of said analysis through a secure session.

[0089] Furthermore, the electronic device may also include other modules, in particular to implement particular modes of the management method, as described in more detail later.

[0090] Schematically represents sub-modules of a control module (AVS) of an electronic device, according to an exemplary implementation of the invention.

[0091] As illustrated by the, an electronic device (ED) embeds a control module (AVSC). This electronic device (ED) corresponds for example to a server controlled by the operator with which the user has subscribed. The control module (AVSC) is managed by the operator of the telecommunications network with which the user has subscribed, and includes the sub-modules MOD_RX and MOD_VER whose functionalities are described with reference to the.

[0092] The represents an example of hardware architecture of an electronic device (ED) including a control module (AVSC).

[0093] As illustrated by the, the electronic device (ED) has the hardware architecture of a computer. Thus, the electronic device (ED) comprises, in particular, a processor 1, a random access memory 2, a read only memory 3 and a non-volatile memory 4. It also comprises a communication module 5.

[0094] The read-only memory 3 or the non-volatile memory 4 of the electronic device (DE) constitutes a recording medium as proposed, readable by the processor 1 and on which is recorded a computer program PROG_AVSC in accordance with the invention, comprising instructions for the execution of steps of the management method as proposed below. The program PROG_AVSC defines one or more functional sub-modules of the electronic device (DE), which rely on or control the hardware elements 1 to 5 cited above, and which comprise in particular: a sub-module MOD_RX for receiving, from a security module (AVS) of another electronic device, a result of said analysis through a secure session; and, a sub-module MOD_VER for verifying the security of the connection as a function of said result.

[0095] Furthermore, the electronic device (ED) may also include other modules, in particular to implement particular modes of the management method, as described in more detail later.

[0096] Illustrates, in the form of a flowchart, an example of security management of a connection between a user terminal (UE) and a telecommunications network.

[0097] Steps S100 to S240 correspond to configuration steps of a security module (AVS) within a user terminal (UE). During this configuration, the user profile management module (UDM) uses, for example, the “UE Parameters Update” procedure. This procedure is notably defined in the 3GPP TS 33.501 specification, version 18.1.1 published on March 30, 2023, to provide the user terminal (UE) with configuration data.

[0098] In particular implementations, this configuration data includes a "fully qualified domain name" (FQDN) or a uniform resource identifier (Uniform Resource Identifier) ​​associated with the control module (AVSC).

[0099] In particular implementations, this configuration data includes data for instantiating a security module (AVS) on a user terminal (UE).

[0100] In particular implementations, this configuration data includes a data network name (DNN) and an identifier of type S-NSSAI, the DNN and S-NSSAI together providing access to a data network enabling access to a control module (AVSC). Thus, the DNN and S-NSSAI are used to initiate a PDU (acronym for “Protocol Data Unit”) session connecting the security module (AVS) and the control module (AVSC).

[0101] As illustrated in Figure 6, the method comprises a first step S10 during which the user terminal (UE) transmits, to the AMF module, a registration request REG REQ received during a step referenced S20. This step S20 triggers the transmission S30, by the AMF module and to the UDM module, of a registration request for example compliant with the protocol “Nudm_UECM_Registration” as described in the specification ETSI TS 129 503, “5G; 5G System; Unified Data Management Services; Stage 3”, v17.10.0, published in April 2023 (3GPP TS 29.503 version 17.10.0 Release 17). This registration request is then received during a step S40 by the UDM module, which triggers an initialization step S100. In this step S100, it is determined whether configuration data of a security module (AVS) must be sent to the UE, for example because the user terminal (UE) is connecting to the telecommunications network for the first time, or because it has never received the configuration data or because this data has been modified since the last sending to the EU. This step is implemented by the user profile management module (UDM) belonging to the telecommunications network.

[0102] During this initialization step S100, the user profile management module (UDM) obtains this configuration data associated with a security module (AVS). This configuration data is, for example, received from a control module (AVSC) of the telecommunications network, following the transmission of a request sent by the UDM module to the AVSC module and aimed at obtaining such data.

[0103] The management method further comprises a step S110 during which the user profile management module (UDM) transmits this configuration data. to a telecommunications network access and mobility management module (AMF), via an N8 interface. This data are received by the access and mobility management module (AMF) during a step S120, then retransmitted to the radio module (BP) of the user terminal (UE) using for example the “Non Access Stratum” (NAS) protocols, during a step S130.

[0104] The data configuration data transmitted using for example the NAS protocols are received by the radio module (BP) of the user terminal (UE) during a step S140.

[0105] Step S150 corresponds to a test during which it is determined whether a security module (AVS) has previously been instantiated on said user terminal (UE) by the telecommunications operator. If this is the case, the configuration data are transmitted to the security module (AVS), during a step S160, then received by this same security module (AVS) during a step S170. Then, during a configuration step S180-1, the security module (AVS) adapts its configuration parameters using the data received in step S170, so as to be able to establish a secure session with the control module (AVSC).

[0106] Returning to step S150, if on the other hand no security module (AVS) has previously been instantiated on said user terminal (UE) by said telecommunications operator (with which the user has subscribed), configuration step S180-2 is implemented during which a new security module (AVS) is instantiated. In this case, the data correspond for example to a web address (Uniform Resource Locator, URL, according to Anglo-Saxon terminology) identifying the location of a package to be installed. The configuration step S180-2 then includes the download using for example an IP connection in the user plane then the installation, by the AVS module, of this package.

[0107] Once the configuration or initialization has been carried out, a step S190 is implemented during which the security module (AVS) transmits an acknowledgment to the access and mobility management module (AMF), using for example the NAS protocols. This acknowledgment includes for example information characterizing that the configuration or initialization of an AVS security module was carried out correctly, without generating an error or warning. Alternatively, this acknowledgment includes data relating to the error(s) and / or warning(s) generated during the configuration or initialization. This acknowledgment is received by the access and mobility management module (AMF) during a step S200, then retransmitted to the UDM module during a step S210. This acknowledgment is received by the UDM module during a step S220, then retransmitted to the control module (AVSC) during a step S230.This acknowledgment is then received by the control module (AVSC) during a step S240.

[0108] The management method further comprises a step S250 of generation, by the security module (AVS) of the user terminal (UE), of a history of events relating to the security of at least one connection portion. This step is for example implemented by the sub-module MOD_GEN of the control module (AVS).

[0109] In particular modes of implementation, the event history is constructed from messages received from a remote device by the radio module (BP) of the user terminal (UE) or transmitted by this same radio module (BP) to a remote device.

[0110] Thus, when a message is received – such as a signaling message – the radio module (BP) makes the message accessible to said security module (AVS). Access to this message is made possible, for example, through application programming interfaces (APIs) provided by the radio module (BP).

[0111] The APIs allow, for example, the security module (AVS) or an application (APP) of said module to subscribe to the reception of new messages relating to the security of at least one portion of the connection. The messages received and intended to be processed by the security module (AVS) are then made accessible to the security module (AVS) or to said application (APP), according to a “push” or “pull” type mechanism.

[0112] Relatively symmetrically, in particular implementation modes, the event history is constructed from events generated by the processor of the user terminal (UE). Access to these events is, for example, made possible through application programming interfaces (APIs) provided by the processor.

[0113] In particular modes of implementation, the event history is generated from data relating to a use of an authentication protocol for at least a portion of the connection between the user terminal (UE) and said telecommunications network, such as the portion of the connection between the user terminal (UE) and a base station (gNB) to which said user terminal (UE) is connected;

[0114] More specifically, if the EAP protocol (acronym for “Extensible Authentication Protocol”) is used, the user terminal receives from the AMF module (and via the gNB base station) an “AUTHENTICATION REQUEST” message containing an “EAP-request” message (see TS 24.501, Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3, version 18.2.1, published on April 6, 2023, § 5.4.1.2.1). The “AUTHENTICATION REQUEST” message is for example specified in this same document in paragraph 8.2.1.1. The “EAP-request” message is for example specified in the IETF standard RFC 3748, “Extensible Authentication Protocol (EAP)” published in June 2004.

[0115] Alternatively, if the 5G AKA protocol is used, the user terminal (UE) receives from the AMF an “AUTHENTICATION REQUEST” message not containing an “EAP-request” message (see for example the previously mentioned TS 24.501 document, paragraph 5.4.1.3.2).

[0116] In particular embodiments, the event history is generated from data relating to a use of an encryption algorithm for at least a portion of the connection between the user terminal (UE) and the telecommunications network, such as the portion of the connection between the user terminal (UE) and a base station (gNB) to which said user terminal (UE) is connected.

[0117] More specifically, for encryption at the NAS (acronym for "Non Access Stratum") level between the user terminal and the AMF module, a SECURITY MODE COMMAND message is sent by the AMF to the user terminal UE (via the gNB base station). This message is for example specified in the TS 24.501 document (paragraph 8.2.25) previously mentioned.

[0118] More specifically, for AS-level encryption (acronym for “Access Stratum”) between the user terminal and the gNB base station, the user terminal UE receives from the gNB base station a “SecurityModeCommand” message, for example defined in TS 38.331 “NR; Radio Resource Control (RRC); Protocol specification”, version 17.4.0, published on March 30, 2023), or an “RRC reconfiguration” message also defined in TS 38.331 and containing a “SecurityAlgorithmConfig” information element indicating the algorithms to be used for integrity protection (IntegrityProtAlgorithm) and encryption (CipheringAlgorithm).

[0119] In particular modes of implementation, the event history is generated from data relating to the integrity control implemented by the user terminal (UE) and / or a base station (gNB) to which said user terminal (UE) is connected (eg, “IntegrityProtAlgorithm” previously mentioned);

[0120] In particular implementations, the event history is generated from data relating to a use of an encryption protocol to encrypt context data of the user terminal (UE);

[0121] In particular implementation modes, the event history is generated from a modification of a temporary identifier (e.g., the 5G-GUTI, the acronym for “Global Unique Temporary Identifier”) of the user terminal (UE). The 5G-GUTI is for example provided by the AMF module to the user terminal UE in a “Registration Accept” message, this message being for example defined in the document TS 23.502, “Procedures for the 5G System (5GS)”, version 18.1.1, published on April 5, 2023.

[0122] In particular implementations, the event history is generated from a transmission, by the user terminal (UE), of an IMSI identifier or a SUCI identifier. More specifically, these identifiers may be transmitted in the “Mobile identity”, “EPS Mobile identity” or “5GS Mobile identity” field of one of the following messages: “IDENTITY RESPONSE”, for example defined in TS 24.501 § 8.2.22 for 5GS. “ATTACH REQUEST”, for example defined in TS 24.301, “Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3”, version 18.2.1, published on April 6, 2023 for EPS, and TS 24.008 “Mobile radio interface Layer 3 specification; Core network protocols; Stage 3”, version 18.2.0, published on 1 er April 2023 for 2G / 3G technologies.

[0123] In particular implementation modes, the event history is generated from data relating to encryption or to an integrity check of a PDCP (acronym for “Packet Data Convergence Protocol”) layer. More specifically, the user terminal UE receives for example from the gNB an “RRC reconfiguration” message (for example defined in the document TS 38.331 previously mentioned) containing the “PDCP-Config” information element indicating in the “IntegrityProtection” field whether the integrity protection of the user plane must be activated or not.

[0124] In particular modes of implementation, the event history is generated from data relating to a context switch in the context of an intercellular transfer (or “handover” according to Anglo-Saxon terminology);

[0125] In particular modes of implementation, the event history is generated from data relating to the security of the “Non Access Stratum” (NAS) protocols used between the user terminal (UE) and the telecommunications network;

[0126] In particular implementation modes, the event history is generated from data relating to the switch to a previous generation connection. More specifically, this involves observing the generation currently in use to detect a switch, for example through the NAS messages exchanged between the user terminal UE and the network. Thus, if the messages exchanged comply with the previously mentioned specification TS 24.501, then the generation is 5G (5GS), if the messages exchanged comply with the previously mentioned specification TS 24.301, then the generation is 4G (EPS) and if the messages exchanged comply with the previously mentioned specification TS 24.008, then the generation is 2G (GSM) or 3G (UMTS).

[0127] In particular implementation modes, the event history is generated from data resulting from the reception of messages from a neighboring cell of the cell in which said user terminal (UE) is located. More specifically, the user terminal receives, for example, from a neighboring cell the information “SIB1 (SystemInformationBlockType1)” in the “DL-SCH” channel. This information is for example defined in document TS 36.331, “Evolved Universal Terrestrial Radio Access (E-UTRA); Radio Resource Control (RRC); Protocol specification”, version 17.4.0, published on March 30, 2023. This SIB1 information contains in particular a “CellAccessRelatedInfo” field, which contains a “plmn-IdentityList” subfield, which itself contains a “PLMN-IdentityInfo” subfield, which itself contains a “cellIdentity” subfield.

[0128] In particular modes of implementation, the event history is generated from a combination of at least two of said previously mentioned data.

[0129] In particular modes of implementation, the management method comprises a transmission, by the security module (AVS), of a plurality of security parameter test requests to the telecommunications network (HPMN) or a visited telecommunications network (VPMN) managed by another telecommunications operator, and the event history is constructed from reactions – or lack of reaction – of the network in response to this transmission of all or part of these requests.

[0130] Returning to the, the method further comprises a step S260 of processing the event history generated in step 250. This step is for example implemented by the sub-module MOD_DET of the security module (AVS).

[0131] In particular embodiments, the processing step S260 comprises determining a modification frequency of a temporary identifier, such as a GUTI. If the modification frequency is greater than a given threshold value, for example 6 minutes, it may then be considered that the security of the connection is potentially compromised or about to be, or that the security level is lower than expected.

[0132] Alternatively, step S260 comprises determining a frequency of modification of a temporary identifier. More specifically, the number of “Registration Update” procedures between two modifications of the 5G-GUTI identifier is determined (eg, by incrementing a counter).

[0133] In particular embodiments, the processing step S260 comprises determining a frequency of transmission, by the user terminal (UE), of an IMSI identifier of the user terminal (UE). Thus, if the number of transmissions of an identifier "in the clear" during a given period of time is greater than a threshold value, for example once per day, it may then be considered that the security of the connection is potentially compromised or about to be, or that the level of security is lower than expected.

[0134] In particular embodiments, the processing step S260 comprises determining a number of attempts to connect to the telecommunications network. Thus, if the number of attempts is greater than a threshold value, for example 3, it may then be considered that the security of the connection is potentially compromised or about to be.

[0135] In particular embodiments, the processing step S260 comprises determining a score representative of a degree of security of at least one portion of the connection between the user terminal (UE) and the data network (DN) of the telecommunications network (HPMN).

[0136] More specifically, this score corresponds for example to a value in the interval [0;1] resulting from a weighted average of a set of sub-scores, each sub-score having a value in the interval [0;1] and being associated with one of the determinations previously mentioned.

[0137] In particular embodiments, the processing step S260 comprises the generation of performance indicators relating to the security of the at least one connection portion.

[0138] In particular embodiments, the processing step S260 comprises the generation of a security alarm, which can be triggered when the score representative of a degree of security is lower than a first predetermined threshold value, for example 0.50, or when the value of one of the performance indicators is lower than a second threshold value lower than the first threshold value (eg, 0.30).

[0139] In particular embodiments, the processing step S260 comprises the transmission of raw data from the event history or data resulting from an analysis of this history to applications of said user terminal (UE) or to remote application servers.

[0140] Returning to the, the method further comprises a step S270 of transmission, by the security module (AVS) and to a control module (AVSC) of the core network (CN), of a result of the analysis through a secure session. This step S270 is for example implemented by the sub-module MOD_TX of the security module (AVS). It can be carried out immediately, periodically – which makes it possible to prevent a possible retention attack from a base station of the radio access network –, or conditionally.

[0141] The result is then received by the control module (AVSC) during step S280. This step S280 is for example implemented by the MOD_RX sub-module of the control module (AVSC).

[0142] In particular implementations, the session is secured end-to-end by applying the secure hypertext transfer protocol HTTPS between the security module (AVS) and the control module (AVSC). Alternatively, the session is secured by applying NAS protocols between the security module (AVS) and the access and mobility management module (AMF) of the telecommunications network (HPMN).

[0143] Finally, in step S290, the security of the connection is checked based on the result obtained in the previous step. This step is implemented, for example, by the MOD_VER sub-module of the control module (AVSC).

[0144] In particular embodiments, the result received in step S270 is presented to a telecommunications operator or to a network manager via a graphical interface. In particular embodiments, the telecommunications network is represented on a graphical interface, and the connection portion for which security is compromised is highlighted on said representation. In particular embodiments, the analysis result comprises security parameters actually implemented, and the verification comprises a comparison of the security parameters actually implemented with those of a security policy previously established by the telecommunications operator.In particular embodiments, the verification comprises the transmission, to a base station or an electronic device implementing a network function specific to a base station, of an instruction aimed at adapting at least one security parameter of the base station.

[0145] The invention has so far been described in the case where the user has only subscribed to a single subscription with a single telecommunications network operator. However, the invention remains applicable in the case where the user terminal comprises several subscriptions. In this particular case, the user terminal (UE) comprises several security modules (AVS) isolated from each other. In this case, upon receipt of a message – such as a signaling message – by the radio module (BP), the latter determines whether the user terminal (UE) comprises a security module (AVS) managed by the operator with which the user has subscribed. This radio module BP is then capable of managing a plurality of contexts, and of associating each message received from the network with the correct context.Thus, when it receives, for example, a reauthentication request from the network, the BP radio module is then configured to determine with which SIM card the reauthentication should be implemented.

[0146] More specifically, following step S190, the AVS module calls the API offered by the BP radio module, in order to be informed, for example, of the occurrence of messages that interest it. The BP radio module then associates this subscription with the correct attachment context by comparing the PLMN ID identifier of the AVS and the PLMN ID identifier of the USIM profile used for the attachment, and stores the identity of the AVS at the origin of the subscription. When receiving a message, the BP radio module determines the attachment context, then checks whether this message is relevant for a subscription in progress in this context. If this is the case, the recipient AVS is the one that is at the origin of the subscription.

Claims

Method for managing the security of a connection between a user terminal (UE) and a telecommunications network (HPMN) managed by a telecommunications operator, the method comprising: a generation (S250), by a security module (AVS) of the user terminal (UE), of a history of events relating to the security of said connection, the security module (AVS) being managed by the telecommunications operator; an analysis (S260), by the security module (AVS), of the generated history; and, a transmission (S270), by the security module (AVS) and to a control module (AVSC) of the telecommunications network, of a result of the analysis through a secure session, the control module (AVSC) being managed by the telecommunications operator. Management method according to claim 1, in which the user terminal (UE) is connected to the telecommunications network (HPMN) through a visited telecommunications network (VPMN) managed by another telecommunications operator, and the event history includes data relating to the security of said visited telecommunications network. The management method of claim 1, further comprising a transmission, by the security module (AVS), of a plurality of security parameter test requests to the telecommunications network or a visited telecommunications network managed by another telecommunications operator, and the analysis (S260) comprises a determination of a behavior of the telecommunications network or the visited telecommunications network in response to the transmissions. Management method according to one of claims 1 to 3, in which the analysis (S260) comprises the determination of a score representative of a degree of security of said connection based on the history generated. Management method according to one of claims 1 to 4, further comprising: reception, by a radio module (BB) of the user terminal (UE) of a signaling message from the telecommunications network (HPMN) or from a visited telecommunications network (VPMN) managed by another telecommunications operator; and, access, by the security module (AVS), to the signaling message through an application programming interface (API) provided by the radio module. Management method according to one of claims 1 to 5, in which the user terminal (UE) comprises a second security module, the security module (AVS), called the first security module, and the second security module being isolated from each other, the method further comprising, following reception, by a radio module (BB) of the user terminal (UE) of a signaling message, a determination, by the radio module (BB), of a recipient security module from among the first security module (AVS) and the second security module (AVS). Management method according to one of claims 1 to 6, in which the session is secured by the use of “Non Access Stratum” protocols between the security module (AVS) and a module (AMF) for managing access and mobility of the telecommunications network; or the use of a secure hypertext transfer protocol (HTTPS) between the security module (AVS) and the control module (AVSC). Management method according to one of claims 1 to 7, in which the security module (AVS) includes an application programming interface (API) comprising a function for accessing the event history and / or the result of the analysis, said application programming interface being accessible by a computer application of the user terminal (UE). Management method according to one of claims 1 to 8, wherein the event history is generated from at least one of: data relating to a use of an authentication protocol for at least one portion of the connection between the user terminal (UE) and said telecommunications network, such as the connection portion between the user terminal (UE) and a base station (gNB) to which said user terminal (UE) is connected; data relating to a use of an encryption algorithm for at least one portion of the connection between the user terminal (UE) and the telecommunications network, such as the connection portion between the user terminal (UE) and a base station (gNB) to which said user terminal (UE) is connected; data relating to the integrity control implemented by the user terminal (UE) and / or a base station (gNB) to which said user terminal (UE) is connected;data relating to the use of an encryption algorithm to encrypt context data of the user terminal (UE); a modification of a temporary identifier (GUTI) of the user terminal (UE); a transmission, by the user terminal (UE), of an IMSI identifier or a SUCI identifier; data relating to encryption or an integrity check of a PDCP layer; data relating to a context switch in the context of an intercellular transfer; data relating to the security of the “Non Access Stratum” (NAS) protocols used between the user terminal (UE) and the telecommunications network; data relating to the switch to a previous generation connection; and, data resulting from the reception of messages from a cell neighboring a cell in which said user terminal (UE) is located.; Computer program comprising instructions for implementing a management method according to any one of claims 1 to 9, when said program is executed by a computer. A computer-readable recording medium on which a computer program according to claim 10 is recorded. Electronic device (UE, UICC) capable of managing the security of a connection between a user terminal (UE) and a telecommunications network (HPMN) managed by a telecommunications operator, the electronic device (UE, UICC) comprising a security module (AVS) managed by the telecommunications operator, the security module (AVS) comprising: a sub-module (MOD_GEN) for generating a history of events relating to the security of said connection; a sub-module (MOD_DET) for analyzing the generated history; and, a sub-module (MOD_TX) for transmitting, to a control module (AVSC) managed by said telecommunications operator and belonging to said telecommunications network, a result of said analysis through a secure session. Electronic device according to claim 12, the electronic device being a secure element (UICC) including an application (USIM) managed by the telecommunications operator, said application (USIM) comprising the security module (AVS). Electronic device according to claim 12, the electronic device being a user terminal (UE), and the security module (AVS) being deployed in a secure execution environment (TEE) of said user terminal (UE). Communication system comprising a first electronic device (UE, UICC) according to any one of claims 12 to 14, and a second electronic device (DE) comprising a control module (AVSC), the control module (AVSC) comprising: a sub-module (MOD_RX) for receiving, from the security module (AVS) of the first electronic device, a result of said analysis through a secure session; and, a sub-module (MOD_VER) for verifying the security of the connection based on said result.