Method for generating an authentication token for a user terminal with a core network based on the use of a blockchain and method for authenticating the corresponding user terminal
The method employs a blockchain-based authentication system to securely register user terminals with core networks in shared RAN environments, addressing security flaws and operational complexities while reducing financial burdens on telecommunications operators.
Patent Information
- Application Number
- FR2023013587
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-05
- Publication Date
- 2025-06-06
AI Technical Summary
Existing methods for registering user terminals with core networks in shared Radio Access Networks (RAN) face security flaws due to the involvement of multiple entities with varying interests, leading to increased operational complexity and financial challenges for telecommunications operators.
A method utilizing a blockchain network with smart contracts to generate and manage authentication tokens for user terminals, allowing secure registration and authentication with core networks without relying on the shared RAN infrastructure.
This solution enhances security and reduces operational complexity by decentralizing authentication processes, making it difficult for malicious parties to usurp authentication tokens, and allowing for efficient registration of user terminals across multiple core networks.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for generating an authentication token for a user terminal on a core network based on the use of a blockchain and method for authenticating the corresponding user terminal Technical field
[0001] The present invention belongs to the general field of telecommunications, and in particular wireless communications implemented on radio type networks such as mobile networks (e.g. 4G, 5G, B5G etc.), etc.
[0002] It relates more particularly to a method for generating an authentication token for a user terminal as well as a method for authenticating the user terminal to a communication network, such as a core network, by means of the authentication token, these two methods being based on a decentralized information storage technology of the blockchain type.
[0003] More specifically, the invention relates to mechanisms, implemented by a computer interfacing with at least one node of a blockchain network executing one or more smart contracts, leading on the one hand to obtaining the authentication token of the user terminal and on the other hand to the authentication of the user terminal with the communication network by means of this authentication token. Prior art
[0004] Radio Access Networks or RANs are an essential component of telecommunications networks compliant with the fifth generation of radio communications standards or 5G as well as with earlier generations of radio communications standards such as 4G or 3G which correspond respectively to the fourth generation and the third generation of radio communications standards.
[0005] In order to offer extensive and robust coverage, guaranteeing both access to the greatest number, even in the most remote geographical areas, as well as a quality of service best suited to the needs of their users, telecommunications operators are investing massively in the development and maintenance of the infrastructures constituting the RAN.
[0006] It is indeed important for a telecommunications operator to upgrade the components of its RANs in order to ensure that the latter are always able to meet the growing needs in terms of capacity and performance due to the increase in the number of user terminals and the growing demand for services requiring very high speeds.
[0007] Telecommunications operators are therefore facing financial challenges related to the need to constantly modernize and expand their RANs to remain competitive. Since RAN operating, maintenance and upgrade costs represent a significant portion of a telecommunications operator's operational expenses, it is increasingly common for telecommunications operators to seek to pool their RAN.
[0008] RAN pooling is a practice that consists of sharing all or part of the software and / or hardware infrastructures of these RANs between several actors such as telecommunications operators, service providers, content providers, etc. This approach aims to optimize the use of resources, reduce costs and promote greater efficiency in the deployment and management of RANs.
[0009] Although RAN sharing offers economic advantages, it leads to increased operational complexity. Beyond the management of relationships between the different entities sharing the same RAN, there is the question of registering user terminals with RAN equipment in order to be granted access to the services provided by a telecommunications operator with whom the user has signed a service provision contract.
[0010] To date, the procedures for registering a user terminal are based on mutual authentication of the user terminal and the core network of the telecommunications operator. This ensures that both parties are legitimate, the user terminal proving its identity using a SIM certificate for "Subscriber Identity Module" or an equivalent, while the core network uses a certificate confirming its identity. However, the fact that the RAN through which the protocol exchanges occurring between the user terminal and the core network are a shared RAN introduces a security flaw in this registration procedure.
[0011] There is therefore a need for a technique for registering a user terminal with a core network which does not have all or part of the drawbacks of the prior art, and which can be implemented in a context of sharing a RAN between several participants having varied interests. Statement of the invention
[0012] The present invention aims to remedy all or part of the drawbacks of the prior art, in particular those set out above, by proposing a solution which allows the registration of a user terminal with a core network operated by an entity distinct from that operating the RAN through which the protocol exchanges school documents relating to the user terminal registration procedure are transmitted.
[0013] To this end, and according to a first aspect, the invention relates to a method for generating an authentication token of a user terminal with a core network implemented by a node belonging to a blockchain network configured to execute a smart contract of said blockchain, said method comprising the following steps: • obtaining a registration request for the user terminal comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter, and an identifier of the core network with which the user terminal is intended to be authenticated, • decryption of the identification token using a public key of the user terminal, • generation of the user terminal authentication token with the core network in the case where the identification token and the control parameter have the same value, • encryption of the authentication token using an encryption key public associated with the core network.
[0014] Blockchain is a technology for storing and transmitting information that is transparent, secure, and operates without a central control body. More precisely, a blockchain is a distributed database that contains the history of all exchanges made between its users since its creation: the information sent by users and the exchanges internal to the database are verified and grouped at regular time intervals into blocks, thus forming a chain. The whole is secured by cryptography.
[0015] More specifically, transactions between users of the blockchain network are grouped into blocks. Each block is validated by the network's nodes, using cryptographic techniques that depend on the type of blockchain used. Once the block is validated, it is timestamped and added to the blockchain, which is accessible to all users. The transaction is then visible to all nodes in the network. Once added to the blockchain, a block can no longer be modified or deleted, ensuring the authenticity and security of the network.
[0016] There are public blockchains, open to all, and private, or consortium, blockchains, whose access and use are limited to a certain number of actors defined in advance.
[0017] The first blockchains found applications in the field of digital currency, such as bitcoin, which is an example of a pro currency grammable. However, the decentralized nature of the blockchain, coupled with its security and transparency, suggests applications far broader than just the monetary domain.
[0018] Blockchain infrastructures have recently been enriched with smart contracts, which can be defined as programs that automatically execute the conditions and terms of a contract, without requiring human intervention. In other words, a smart contract is a compiled computer program that includes a set of characteristics allowing it to automatically and autonomously execute at least some of the specific clauses of the contract it carries.
[0019] The use of a blockchain, a smart contract and decentralized databases to generate an authentication token makes it possible to bypass the involvement of the RAN in the procedure for registering a user terminal with a core network. Thus, even if the RAN is not operated by the telecommunications operator managing the core network, this has no impact on the registration procedure since all exchanges are carried out via the blockchain.
[0020] In particular embodiments of the method for generating an authentication token, the authentication token is recorded in the blockchain.
[0021] Such a registration step in the blockchain makes the authentication token accessible to all users of the latter.
[0022] In particular embodiments of the method for generating an authentication token, the authentication token is generated by means of an identifier of the user terminal and at least one of the following data belonging to a group comprising: - a digest, or "hash", of the transaction, - a digest of a transaction identifier, - a digest of a block in the blockchain in which the transaction is stored, - a digest of an identifier of the block of the blockchain in which the transaction is stored, - a block timestamp data.
[0023] Such an authentication token generated using all or part of this data has a high level of security. It is therefore difficult for a third party to usurp this authentication token.
[0024] In particular embodiments of the method for generating a token, the latter comprises a step of obtaining the public encryption key of the user terminal stored in the blockchain by means of an identifier of the terminal. user included in the user terminal registration request.
[0025] In particular embodiments of the method for generating a token, the identification token is generated using the identifier of the user terminal and a random number.
[0026] Using a random number helps reduce the risk of authentication token spoofing or registration request being reused by a malicious third party.
[0027] In particular embodiments of the method for generating a token, the control parameter is generated by means of the identifier of the user terminal and the random number.
[0028] In particular embodiments of the method for generating a token, the registration request from the user terminal further comprises data relating to the type of service required, and / or data relating to the type of registration required.
[0029] As examples, such additional data may be an identifier of a slice of the communications network, a required throughput value, a latency value to be respected, etc.
[0030] In particular embodiments of the method for generating a token, the random number is generated by equipment of an access network to which the user terminal is attached.
[0031] In particular modes of implementation of the method for generating a token, the identifier of the core network with which the user terminal is intended to be authenticated is provided by the equipment of the access network to which the user terminal is attached.
[0032] In particular modes of implementation of the method for generating a token, the identifier of the core network with which the user terminal is intended to be authenticated is stored in the blockchain.
[0033] According to another aspect, the invention relates to a method for authenticating a user terminal implemented by equipment belonging to a core network, said method comprising the following steps: • receiving a connection request sent by the user terminal comprising a first identifier of the user terminal and a first authentication token of the user terminal encrypted using a public encryption key associated with the core network, • obtaining, by means of the first identifier of the user terminal, a second authentication token of the user terminal encrypted by means of a public encryption key associated with the core network from a node belonging to a blockchain network configured to execute a smart contract of said blockchain, • decryption of the first authentication token and the second authentication token using a private key associated with the core network, • establishment of a connection with the user terminal in the case where the first authentication token and the second authentication token have the same value.
[0034] In particular embodiments of the authentication method, the generation of the authentication token by the smart contract constituting a transaction stored in at least one block of the blockchain, the authentication token comprises a digest, or “hash”, of the transaction, a digest of the block of the blockchain in which the transaction is stored, a second identifier of the user terminal and a time stamp of the block, [claim 8]
[0035] In particular modes of implementation of the authentication method, the latter further comprises the following steps: • obtaining from a decentralized database, by means of the first identifier of the user terminal, data relating to the user terminal encrypted by means of a symmetric encryption key and the symmetric encryption key encrypted by means of the public encryption key associated with the core network, the data relating to the user terminal comprising at least a third identifier of the user terminal, • decryption of the symmetric encryption key using the private key associated with the core network, • decryption of data relating to the user terminal using the symmetric encryption key, • establishing a connection with the user terminal in the event that the first identifier and the third identifier of the user terminal have the same value.
[0036] In particular modes of implementation of the authentication method, the establishment of the connection with the user terminal is triggered in the case where the first identifier, the second identifier and the third identifier of the user terminal have the same value.
[0037] In particular modes of implementation of the authentication method, the connection with the user terminal is intended to be established by means of data relating to the user terminal obtained from a decentralized database.
[0038] In particular modes of implementation of the authentication method, the authentication of the user terminal is stored in the blockchain.
[0039] According to another aspect, the invention relates to a node belonging to a blockchain network configured to execute a smart contract of said blockchain. intended to generate an authentication token of a user terminal with a core network, the node comprising at least one processor configured to: • obtain a registration request from the user terminal comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter, and an identifier of the core network with which the user terminal is intended to be authenticated, • decrypt the identification token using a public key of the terminal user, • generate the user terminal authentication token with the core network in the case where the identification token and the control parameter have the same value, • encrypt the authentication token using a public encryption key associated with the core network, • save the authentication token in the blockchain.
[0040] According to another aspect, the invention also relates to equipment belonging to a core network intended to authenticate a user terminal, said equipment comprising at least one processor configured to: • receive a connection request issued by the user terminal comprising a first identifier of the user terminal and a first authentication token of the user terminal encrypted using a public encryption key associated with the core network, obtaining, by means of the first identifier of the user terminal, a second authentication token of the user terminal encrypted by means of a public encryption key associated with the core network from a node belonging to a blockchain network configured to execute a smart contract of said blockchain, • decrypting a first authentication token and the second authentication token by means of a private key associated with the core network, • establish a connection with the user terminal in the case where the first authentication token and the second authentication token have the same value.
[0041] Finally, the invention also relates to a user terminal intended to authenticate itself to a core network, the user terminal comprising at least one processor configured to: • transmit a registration request comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter to a node belonging to a blockchain network configured to execute a smart contract of said blockchain intended to generate an authentication token for the user terminal with the core network, • receive, from the node belonging to a blockchain network, the authentication token of the user terminal with the core network encrypted using a public encryption key associated with the core network, • send, to a device in the core network, a connection request including a user terminal identifier and the encrypted authentication token, • receive, from the core network equipment, a message relating to the establishment of the connection. Brief description of the drawings
[0042] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate an exemplary embodiment thereof without any limiting character. In the figures:
[0043] [Fig-1] [Fig.l] represents a system for authenticating a user terminal to blockchain base in which the methods of generating an authentication token of a user terminal and of authenticating the user terminal according to the invention are implemented;
[0044] [Fig.2] [Fig.2] illustrates, in the form of a flowchart, the main stages of a method for generating an authentication token of a user terminal with a core network implemented by a node Ni belonging to a blockchain network according to an exemplary implementation of the invention;
[0045] [Fig.3] [Fig.3] illustrates, in the form of a flowchart, an example of a process authentication of a user terminal implemented by equipment belonging to a core network according to an exemplary implementation of the invention;
[0046] [Fig.4] [Fig.4] represents a node belonging to a blockchain network capable of implementing certain steps of the methods for generating an authentication token of a user terminal and for authenticating the user terminal according to the invention;
[0047] [Fig.5] [Fig.5] represents equipment belonging to the core network capable of putting implement certain steps of the user terminal authentication method according to the invention. Description of the embodiments
[0048] The present invention is based on the use of a blockchain structure to design an authentication platform for a user terminal wishing to register with a core network operated by a telecommunications operator with which the user of the user terminal has subscribed to a service offer. More particularly, the present solution is based on the delegation of certain authentication operations of a user terminal to a third-party service interfacing the structure of the blockchain with at least one radio access network, or RAN, and a plurality of core networks, in order to guarantee the integrity and authenticity of the authentication process of the user terminals, in particular in a context of pooling of the RAN between a plurality of actors among which may or may not be the telecommunications operator with which the user of the user terminal has subscribed to a service offer.
[0049] Such a platform corresponds to a system for authenticating a user terminal based on a blockchain described with reference to [Fig. 1].
[0050] Such a system may comprise a blockchain network 100, also referred to hereinafter as the blockchain network 100, comprising a plurality of nodes NI to N5 interconnected to each other. The structure of the node NI is illustrated in more detail in this [Fig.l] in order to enlighten the reader. Each node N2 to N5 has an architecture similar to that of the node NI, although this has not been detailed, for the sake of simplification, in [Fig.l]. In this document, the term node refers exclusively to the nodes N1-N5 belonging to the blockchain network 100.
[0051] It is noted that the term node can correspond to a software component as well as to a hardware component or a set of hardware and software components, a software component itself corresponding to one or more computer programs or sub-programs or more generally to any element of a program capable of implementing a function or a set of functions.
[0052] More generally, a node Ni comprises a random access memory (for example a RAM memory), a processing unit equipped for example with a processor, and driven by a computer program, representative of the code instructions of one or more smart contracts SC 11, SCUE, SC102, stored in a read-only memory (for example a ROM memory or a hard disk). When the node Ni is initialized, the code instructions of the computer program are for example loaded into the random access memory before being executed by the processor of the processing unit.
[0053] Thus, in certain embodiments, the NI node may further comprise:
[0054] - an Ethereum EVM 10 virtual machine, which is the execution environment of the Smart contracts in Ethereum. Remember that Ethereum is a decentralized exchange protocol that allows users to create smart contracts using a Turing-complete language. Other decentralized exchange protocols can be used, such as Polkadot, Solana, or Cardano;
[0055] - a data storage area STOR 12;
[0056] - the bytecode of the smart contracts SC 11, SCue, SC 102, i.e. the deterministic codes executable on the blockchain network 100, the variables can be stored on the 100 network, and whose functions can be called.
[0057] The backend system of the authentication platform of a user terminal is thus decentralized, and resides in the smart contracts SC 11, SCUE, SC io2, implementing a panel of functions necessary for the authentication of a user terminal.
[0058] The users of the platform are for example equipment 101 belonging to the RAN, such as a base station or gNodeB, and equipment 102 belonging to a core network such as equipment executing an access and mobility management function or AMF for "Access and Mobility Management". These equipment 101 and 102 can interact with the platform via their interface, or "frontend" according to the English terminology. API requests (for "Application Programming Interface") allow interaction between the equipment 101, 102 on the one hand, and the smart contracts SC 11, SCue, SC102, deployed on the blockchain network 100 on the other hand.
[0059] The equipment belonging to the core network 102 may comprise a transmission / reception module RX / TX 1020, configured to transmit requests to the platform and to obtain an authentication token from a user terminal. Equipment 102 may comprise in particular one or more processors, configured to execute program code instructions to authenticate a user terminal, in particular conforming to the programming languages HTML (for “HyperText Markup Language” and JS (for Java Script).
[0060] The equipment belonging to the RAN 101 comprises a transmission / reception module RX / TX 1010, configured to transmit requests for registration of user terminals to the platform. Such equipment belonging to the RAN 101 notably comprises one or more processors, configured to execute program code instructions for the transmission of such data, notably conforming to the programming languages HTML (for “HyperText Markup Language”), and JS (for Java Script).
[0061] The listed and validated transactions between the equipment belonging to the RAN 101 and the equipment belonging to a core network 102 can be stored in the form of blocks in the nodes NI to N5 of the blockchain 100. Consensus rules can help to limit malicious nodes, and to identify invalidated transactions. Cryptographic rules can help to ensure pseudo-anonymity of transactions and users, and the authenticity of the authentication tokens generated in accordance with the solution of the present invention.
[0062] [Fig.l] illustrates only one particular way, among several possible ones, of realizing a node Ni so that it carries out the steps of the methods of generating a token authentication and authentication of the user terminal UE detailed below, in relation to figures 2 and 3 (in any of the different embodiments, or in a combination of these embodiments). Indeed, these steps can be carried out indifferently on a reprogrammable computing machine (a computer, a processor or a microcontroller) executing a program comprising a sequence of instructions, or on a dedicated computing machine (for example a set of logic gates such as an FPGA or an ASIC, or any other hardware module).
[0063] In the case where the node Ni is produced with a reprogrammable computing machine, the corresponding programs (i.e. the sequences of instructions) may be stored in a removable storage medium (such as for example a floppy disk, a CD-ROM or a DVD-ROM) or not, this storage medium being partially or totally readable by a computer or a processor.
[0064] [Fig.2] illustrates, in the form of a flowchart, the main steps of a method for generating an authentication token for a user terminal with a core network implemented by a node Ni belonging to a blockchain network 100 according to an exemplary implementation of the invention.
[0065] As illustrated by [Fig.2], the method for generating an authentication token comprises a first step E1 during which a user terminal UE (not shown in the figures) attached to the equipment belonging to the RAN 101 transmits a request for registration of the user terminal RQT to the latter.
[0066] Such a registration request RQT comprising at least one identification token IdTokUE encrypted using a private encryption key KPrivUE of the user terminal UE and a control parameter PCheckUE. The use of such a private encryption key KPrivUE makes it possible to verify the authenticity of the user terminal UE at the origin of the transmission of the registration request.
[0067] In other implementation modes, the RQT registration request may also include a random number Rand, an identifier IdUE of the user terminal UE or even additional data such as an identifier of a slice of the communications network or “slice” in English, a required throughput value, a latency value to be respected, etc.
[0068] As a reminder, network slicing is a key concept in the development of 5G telecommunications networks, playing a vital role in supporting the diversity of services and applications offered by 5G. A network slice is essentially an end-to-end virtualized network, providing specific and customized service capabilities to meet the requirements of a particular use case or application.
[0069] Generally, the identification token IdTokUE of the user terminal UE is obtained by encrypting, using the private encryption key KPrivUE, a pair consisting of the identifier IdUE of the user terminal UE and the random number Rand. In other implementations, the identification token IdTokUE of the user terminal UE is obtained by encrypting, using the private encryption key KPriv UE, a digest or “hash” of the pair consisting of the identifier IdUE of the user terminal UE and the random number Rand.
[0070] The use of a random number in the generation of the IdTok UE identification token of the user terminal UE makes it possible to reduce the risks that a malicious third party can reuse the RQT registration request. This random number Rand can be generated by the user terminal UE itself or by the equipment belonging to the RAN 101. In this second case, the random number Rand is transmitted by the equipment belonging to the RAN 101 at the request of the user terminal UE.
[0071] In the same way, the control parameter PCheckUE corresponds to the pair consisting of the identifier IdUE of the user terminal UE and the random number Rand or a digest of the latter.
[0072] In a step E2, the equipment belonging to the RAN 101 transmits the registration request RQT received in step E1 to a node N1-5 belonging to the blockchain network 100.
[0073] In other implementations, prior to transmitting the registration request RQT to a node Nl-5, the equipment belonging to the RAN 101 selects a core network with which the user terminal UE wishes to register. The equipment belonging to the RAN 101 makes, for example, this selection on the basis of information included in the registration request RQT, such as an identifier of the core network IdCore, or on the basis of information made available to it by parties other than the user terminal UE.
[0074] Thus, the equipment belonging to the RAN 101 can contact a node Nl-5 executing a smart contract whose function is to store a list of core network identifiers IdCore with which the user terminal can register. Such a smart contract is updated periodically by equipment belonging to these different core networks. In order to select the core network with which the user terminal will register, the equipment belonging to the RAN 101 uses data associated with the identifier IdCore of each core network stored in the smart contract in order to determine which, among all of these core networks, best meets the needs of the user terminal UE in terms of, for example, quality of service, throughput, latency, etc.
[0075] For example, the core network identifier IdCore points to the equipment belonging to the core network 102. This may be a network address, such as an address IP associated with this equipment belonging to the core network 102.
[0076] Thus, at the end of step E2, the node Nl-5 has all or part of the following data, provided by the equipment belonging to the RAN 101: the identification token IdTokUE of the user terminal UE, the control parameter PCheckUE, the additional data and the identifier of the selected core network IdCore. Thus, indirectly, the node Nl-5 has the identifier IdUE of the user terminal UE and the random number Rand.
[0077] The reception of the registration request RQT by the node Nl-5 triggers the execution of the smart contract SC 11 in a step E3. The smart contract SC 11 has the function of generating an authentication token AuthTokUE 102 allowing the user terminal UE to authenticate itself with the core network via the equipment belonging to the core network 102 in order to be able to access one or more services provided by the telecommunications operator managing the core network. The smart contract SC 11 can, for the same user terminal UE, generate a plurality of authentication tokens, each authentication token generated corresponding to a core network with which the user terminal UE can register without it being necessary for the user terminal UE to be equipped with several SIM cards (for “Subscriber Identification Module” or module identifying the user in French).
[0078] In a step E4, the node Nl-5 contacts another node Nl-5 also belonging to the blockchain network 100 and executing the smart contract SCue in order to obtain the public encryption key KPubUE of the user terminal UE. The smart contract SCUE is a smart contract which, when executed, provides a CIDUE identifier pointing to a section of a distributed database BdD in which data relating to the user terminal UE are stored. The nature of this data relating to the user terminal UE will be discussed in more detail later in this document. Such a database BdD may be, for example, an IPFS database for “InterPlanetary File System”.
[0079] The IPFS system is a distributed peer-to-peer file system that does not rely on the use of centralized servers. This system allows a set of computer equipment to be connected with the same file system. More particularly, the IPFS system provides a block file storage model that can be addressed by means of hyperlinks.
[0080] The node Nl-5 executing the smart contract SC 11 addresses the node Nl-5 executing the smart contract SCue by means of the Mue identifier of the user terminal UE included in the registration request RQT.
[0081] In other implementations, the two smart contracts SC 11 and SCue are executed by the same node Nl-5.
[0082] Once the SCue smart contract has been executed, the CIDue identifier is transmitted to node Nl-5 executing smart contract SC 11 in step E5.
[0083] Using the identifier CIDUE, the node Nl-5 executing the smart contract SC 11 addresses the database BdD in order to obtain all or part of the data relating to the user terminal UE that it contains, and more particularly the public encryption key KPubUE of the user terminal UE, in a step E6.
[0084] The database BdD comprises numerous DUE data relating to the user terminal UE which are all encrypted with the exception of the public encryption key KPubUE of the user terminal UE. More particularly, the DUE data relating to the user terminal UE are encrypted using a symmetric encryption key KSym known to the core network. This symmetric encryption key KSym is then encrypted using a public encryption key KPubi02 of the equipment belonging to the core network 102. This limits the risks of fraudulent use of the data relating to the user terminal UE.
[0085] This encrypted version of the symmetric encryption key KSym is stored in the database BdD with the encrypted version of the data DUE relating to the user terminal UE and the public encryption key KPubUE of the user terminal UE.
[0086] In other implementation modes, the database BdD stores, for a given user terminal UE, as many encrypted versions of the data DUE relating to the user terminal UE, and as many encrypted versions of a symmetric encryption key KSym, as there are core networks with which the user terminal UE can register.
[0087] The database BdD thus queried, transmits the public encryption key KPubUE of the user terminal UE to the node Nl-5 executing the smart contract SC 11 in a step E7. In other modes of implementation, the database BdD transmits to the node Nl-5 executing the smart contract SC 11 all of the data concerning the user terminal that it contains.
[0088] Once in possession of the public encryption key KPubUE of the user terminal UE, the node Nl-5 executing the intelligent contractor SC 11 proceeds to decrypt the identification token IdTokUE of the user terminal UE in a step E8.
[0089] At the end of step E8, the node Nl-5 executing the smart contract SC 11 has the decrypted identification token IdTokUE, which, as a reminder, can be the pair consisting of the identifier IdUE of the user terminal UE and the random number Rand or the digest of this pair.
[0090] In a step E9, the node Nl-5 executing the smart contract SC 11 compares the decrypted identification token IdTokUE with the control parameter PCheckUE.
[0091] If the value of the decrypted identification token IdTokUE matches the value of the control parameter PCheckUE then the node executing the smart contract SC 11 executes step E10. Otherwise, i.e., when the value of the decrypted identification token IdTokUE does not match the value of the control parameter PCheckUE, this means that a possible fraudulent use of the registration request is at work. The execution of the smart contract SC 11 is then interrupted.
[0092] Step E10 corresponds to the generation of the authentication token AuthTokUE_i02 of the user terminal with the core network by the node N1-5 executing the smart contract SC 11.
[0093] In order to be able to generate the authentication token AuthTokUE_i02 of the user terminal UE with the core network, the node N1-5 executing the smart contract SC 11 contacts, in a step El 1, another node N1-5 also belonging to the blockchain network 100 and executing the smart contract SC 102 in order to obtain the public encryption key KPubi02 of the equipment belonging to the core network 102. The smart contract SC102 is a smart contract which, when executed, provides the public encryption key KPubio2 of the equipment belonging to the core network 102.
[0094] The node N1-5 executing the smart contract SC 11 addresses the node N1-5 executing the smart contract SCue by means of the identifier IdCore of the equipment belonging to the core network 102 which it received from the equipment belonging to the RAN 101 during step E2.
[0095] In other implementations, the two smart contracts SC 11 and SC102 are executed by the same node Nl-5.
[0096] Once the smart contract SC102 has been executed, the public encryption key KPubio2 of the equipment belonging to the core network 102 is transmitted to the node Nl-5 executing the smart contract SC 11 in a step El2.
[0097] Steps E1 1 and E12 can be implemented by node Nl-5 executing smart contract SC 11 at any time between steps E3 and E9 or concomitantly with one of these two steps E3 or E9.
[0098] Returning to step E10, the node Nl-5 executing the smart contract SC 11 generates the authentication token AuthTokUE_i02 of the user terminal with the core network. Such an authentication token AuthTokUE_i02 is obtained by encrypting, using the public encryption key KPubi02 of the equipment belonging to the core network 102, the identifier IdUE of the user terminal UE and at least one of the following data:
[0099] - a digest of a transaction carried out within the blockchain network 100, this transaction comprising all exchanges and actions carried out during steps E3 to El2,
[0100] - an identifier of the transaction carried out within the blockchain network 100 or the digest of this identifier,
[0101] - a digest of a block B constituting the block chain in which the transaction is memorized / stored,
[0102] - an identifier of the block B constituting the block chain in which the transaction is memorized / stored or a digest of this identifier, and
[0103] - a TSB timestamp data of block B.
[0104] Thus, by way of example, the authentication token AuthTokUE_i02 can be obtained by encrypting, using the public encryption key KPubi02 of the equipment belonging to the core network 102, the identifier IdUE of the user terminal UE, the digest of the transaction carried out within the blockchain network 100, the digest of the block B constituting the chain of blocks in which the transaction is memorized / stored, and the timestamp data TSB of the block B.
[0105] Once the authentication token AuthTokUE_i02 of the user terminal with the core network has been generated, it is then stored in the blockchain network 100 in a step E1 1. It is thus accessible to any stakeholder in the blockchain network 100.
[0106] In other implementation modes, the authentication token AuthTokUE_i02 of the user terminal to the core network is transmitted, via the equipment belonging to the RAN 101, to the user terminal UE.
[0107] [Fig.3] illustrates, in the form of a flowchart, an example of a method for authenticating a user terminal implemented by equipment belonging to a core network 102.
[0108] As illustrated by [Fig.3], the method for authenticating a user terminal implemented by equipment belonging to a core network 102 comprises a first step G1 during which a user terminal UE (not shown in the figures) attached to the equipment belonging to the RAN 101 transmits a ConR connection request sent by the user terminal UE. Such a ConR connection request comprises the identifier IdUE of the user terminal UE and a first value of the authentication token AuthTokUE_i02 of the user terminal to the core network.
[0109] In a step G2, the equipment belonging to the core network 102 obtains from the blockchain network 100 a second value of the authentication token AuthTokUE402 of the user terminal to the core network by means of the identifier IdUE of the user terminal UE. This second value of the authentication token AuthTokUE_i02 of the user terminal to the core network can be obtained from a node N1-5 belonging to the blockchain network 100 executing a smart contract whose function is to provide this second value of the authentication token AuthTokUE_i02 of the user terminal to the core network.
[0110] At the end of step G2, the equipment belonging to the core network 102 is in possession of the two values of the authentication token AuthTokUE_i02 of the user terminal with the core network, that provided by the user terminal UE and that, reliable and therefore serves as a control value, provided by an N1-5 node belonging to the blockchain network 100.
[0111] The equipment belonging to the core network 102 then proceeds to decrypt the first value of the authentication token AuthTokUE_i02 of the user terminal with the core network and the second value of the authentication token AuthTokUE_i02 of the user terminal with the core network by means of a private encryption key KPrivi02 of the equipment belonging to the core network 102 in a step G3.
[0112] Once the two values of the authentication token AuthTokUE i02 of the user terminal are with the core network, the equipment belonging to the core network 102 compares one by one the values of the digest of a transaction carried out within the blockchain network 100, of the digest of block B of the chain of blocks in which the transaction is memorized / stored, of the identifier IdUE of the user terminal UE, and of the time stamp data TSB of block B included in the two authentication tokens AuthTokUE_i02 of the user terminal with the core network in possession of the equipment belonging to the core network 102 during a step G4.
[0113] If all the values of the digest of a transaction carried out within the blockchain network 100, of the digest of block B of the chain of blocks in which the transaction is memorized / stored, of the identifier IdUE of the user terminal UE, and of the time stamp data TSB of block B included in the two authentication tokens AuthTokUE_i02 of the user terminal with the core network correspond, the equipment belonging to the core network 102 then executes step G5.
[0114] Otherwise, that is to say, when at least one of the values of the digest of a transaction carried out within the blockchain network 100, of the digest of block B of the blockchain in which the transaction is memorized / stored, of the identifier IdUE of the user terminal UE, and of the timestamp data TSB of block B included in the authentication token AuthTokUE_i02 of the user terminal with the core network provided by the user terminal UE does not correspond to the corresponding value included in the authentication token AuthTokUE_i02 of the user terminal with the core network provided by the node Nl-5, this means that a possible fraudulent use of the connection request ConR is at work. The execution of the authentication method is then interrupted.
[0115] Returning to step G5, the equipment belonging to the core network 102 contacts a node Nl-5 belonging to the blockchain network 100 and executing the smart contract SC UE in order to obtain the identifier CIDUE pointing to the section of the distributed database BdD in which data relating to the user terminal UE are stored.
[0116] Once the smart contract SCue has been executed, the identifier CIDUE is transmitted to the equipment belonging to the core network 102 in a step G6.
[0117] Using the identifier CIDUE, the equipment belonging to the core network 102 addresses the database BdD in order to obtain all or part of the data relating to the user terminal UE that it contains in a step G7.
[0118] As discussed earlier in this document, the database BdD includes numerous DUE data relating to the user terminal UE which are all encrypted except for the public encryption key KPubUE of the user terminal UE. More particularly, the DUE data relating to the user terminal UE are encrypted using the symmetric encryption key KSym known to the core network. This symmetric encryption key KSym is then encrypted using a public encryption key KPubi02 of the equipment belonging to the core network 102.
[0119] This encrypted version of the symmetric encryption key KSym is stored in the database BdD with the encrypted version of the data DUE relating to the user terminal UE and the public encryption key KPubUE of the user terminal UE.
[0120] The database BdD thus queried transmits all of the data concerning the user terminal that it contains to the equipment belonging to the core network 102 during a step G8.
[0121] Upon receipt of the data relating to the user terminal UE from the database BdD, the equipment belonging to the core network 102 proceeds to decrypt the symmetric encryption key KSym using its private encryption key KPrivio2 in a step G9.
[0122] Then, once in possession of the symmetric encryption key KSym, the equipment belonging to the core network 102 proceeds to decrypt the data DUE relating to the user terminal UE by means of the latter in a step G10.
[0123] The equipment belonging to the core network 102 then establishes, in a step G11, a connection with the user terminal UE by means of the DUE data relating to the user terminal UE.
[0124] In other implementation modes, the connection with the user terminal UE is established in the case where the identifier IdUE of the user terminal UE from the database BdS corresponds to the identifier IdUE of the user terminal UE provided by the node Nl-5 belonging to the blockchain network 100.
[0125] Otherwise, that is to say, when the identifier IdUE of the user terminal UE from the database BdS does not correspond to the identifier IdUE of the user terminal UE provided by the node Nl-5 belonging to the blockchain network 100, the establishment of the connection with the user terminal UE is interrupted.
[0126] In other implementation modes, the connection with the user terminal UE is established in the case where the identifier IdUE of the user terminal UE from the database BdS corresponds to the identifier IdUE of the user terminal UE provided by the node Nl-5 belonging to the blockchain network 100 and to the identifier IdUE of the user terminal EU reader included in the ConR connection request.
[0127] Otherwise, that is to say, when the identifier IdUE of the user terminal UE from the database BdS does not correspond to the identifier IdUE of the user terminal UE provided by the node Nl-5 belonging to the blockchain network 100 and to the identifier IdUE of the user terminal UE included in the connection request ConR, the establishment of the connection with the user terminal UE is interrupted.
[0128] Once the connection with the user terminal UE is established, the user terminal and the equipment belonging to the core network 102 implement in a conventional manner the steps of the attachment and key management procedure or AKA for “Attachment and Key Agreement” which follow the mutual authentication of the user terminal UE and the equipment belonging to the core network 102.
[0129] Thus, the user terminal UE and the equipment belonging to the core network 102 implement a procedure for negotiating encryption keys, such as an integrity key and an encryption key intended to be used in order to secure the data exchanges occurring between the user terminal UE and the core network. The negotiation of the encryption keys can be done by means of the Diffe-Hellman algorithm.
[0130] [Fig.4] represents a node N1-N5 belonging to a blockchain network capable of implementing certain steps of the solution previously described.
[0131] A node N1-N5 may comprise at least one hardware processor 401, a storage unit 402 corresponding to the STOR memory 12 of [Fig.l], a first interface 403, and at least one second network interface 404 and an Ethereum EVM virtual machine 10 which are connected to each other through a bus 405. Of course, the constituent elements of the node N1-N5 may be connected by means of a connection other than a bus.
[0132] The processor 401 controls the operations of the node N1-N5. The storage unit 402 stores at least one program for implementing the various methods that are the subject of the invention to be executed by the processor 401, and various data, such as parameters used for calculations performed by the processor 401, intermediate data of calculations performed by the processor 401, etc. The processor 401 may be formed by any known and suitable hardware or software, or by a combination of hardware and software. For example, the processor 401 may be formed by dedicated hardware such as a processing circuit, or by a programmable processing unit such as a central processing unit ("Central Processing Unit") which executes a program stored in a memory thereof.
[0133] The storage unit 402 may be formed by any suitable means capable of storing the program(s) and data in a computer-readable manner. Examples of storage unit 402 include media computer-readable non-transitory storage such as semiconductor memory devices, and magnetic, optical, or magneto-optical recording media loaded into a read-write unit.
[0134] Interface 403 provides an interface between node N1-N5 and another node N1-N5 of the blockchain network.
[0135] The network interface 404 provides a connection between the node N1-N5 and the equipment belonging to the RAN 101, or the equipment belonging to the core network 102 or even the database BdD.
[0136] [Fig.5] represents equipment belonging to the core network 102 capable of implementing certain steps of the authentication method of the user terminal UE previously described.
[0137] A piece of equipment belonging to the core network 102 may comprise at least one hardware processor 501, a storage unit 502, a first interface 503, and at least one second network interface 504 which are connected to each other through a bus 505. Of course, the constituent elements of the equipment belonging to the core network 102 may be connected by means of a connection other than a bus.
[0138] The processor 501 controls the operations of the equipment belonging to the core network 102. The storage unit 502 stores at least one program for implementing the various methods that are the subject of the invention to be executed by the processor 501, and various data, such as parameters used for calculations performed by the processor 501, intermediate data of calculations performed by the processor 501, etc. The processor 501 may be formed by any known and suitable hardware or software, or by a combination of hardware and software. For example, the processor 801 may be formed by dedicated hardware such as a processing circuit, or by a programmable processing unit such as a central processing unit ("Central Processing Unit") which executes a program stored in a memory thereof.
[0139] The storage unit 502 may be formed by any suitable means capable of storing the program(s) and data in a computer-readable manner. Examples of the storage unit 502 include non-transitory computer-readable storage media such as semiconductor memory devices, and magnetic, optical, or magneto-optical recording media loaded into a read-write unit.
[0140] The interface 503 provides an interface between the equipment belonging to the core network 102 and a node N1-N5 of the blockchain network 100.
[0141] The network interface 504 provides a connection between the equipment belonging to the core network 102 and the equipment belonging to the RAN 101, or the database BdD.
Claims
Claims
1. Method for generating an authentication token of a user terminal with a core network implemented by a node belonging to a blockchain network configured to execute a smart contract of said blockchain, said method comprising the following steps: • obtaining a registration request of the user terminal comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter, and an identifier of the core network with which the user terminal is intended to be authenticated, • decrypting the identification token using a public key of the user terminal, • generating the authentication token of the user terminal with the core network in the case where the identification token and the control parameter have the same value,• encryption of the authentication token using a public encryption key associated with the core network.,
2. Method for generating an authentication token of a user terminal according to claim 1 wherein the authentication token is generated by means of an identifier of the user terminal and at least one of the following data belonging to a group comprising: - a digest, or "hash", of the transaction, - a digest of an identifier of the transaction, - a digest of a block of the blockchain in which the transaction is stored, - a digest of an identifier of the block of the blockchain in which the transaction is stored, - a timestamp data of the block.
3. Method for generating an authentication token of a user terminal according to any one of claims 1 or 2 comprising a step of obtaining the public encryption key of the user terminal lizer stored in the blockchain by means of a user terminal identifier included in the user terminal registration request.
4. A method of generating an authentication token of a user terminal according to claim 3 wherein the identification token is generated using the identifier of the user terminal and a random number.
5. A method of generating an authentication token of a user terminal according to claim 4 wherein the control parameter is generated using the identifier of the user terminal and the random number.
6. A method of generating an authentication token of a user terminal according to any one of claims 4 or 5 wherein the random number is generated by equipment of an access network to which the user terminal is attached.
7. Method for authenticating a user terminal implemented by equipment belonging to a core network, said method comprising the following steps: • receiving a connection request sent by the user terminal comprising a first identifier of the user terminal and a first authentication token of the user terminal encrypted using a public encryption key associated with the core network, • obtaining, using the first identifier of the user terminal, a second authentication token of the user terminal encrypted using a public encryption key associated with the core network from a node belonging to a blockchain network configured to execute a smart contract of said blockchain, • decrypting the first authentication token and the second authentication token using a private key associated with the core network,• establishing a connection with the user terminal in the case where the first authentication token and the second authentication token have the same value.,
8. Authentication method according to claim 7 wherein, the ge- generation of the authentication token by the smart contract constituting a transaction stored in at least one block of the blockchain, the authentication token comprises a digest, or "hash", of the transaction, a digest of the block of the blockchain in which the transaction is stored, a second identifier of the user terminal and a timestamp data of the block.
9. Authentication method according to any one of claims 7 or 8 further comprising the following steps: • obtaining from a decentralized database, by means of the first identifier of the user terminal, data relating to the user terminal encrypted by means of a symmetric encryption key and the symmetric encryption key encrypted by means of the public encryption key associated with the core network, the data relating to the user terminal comprising at least a third identifier of the user terminal, • decrypting the symmetric encryption key by means of the private key associated with the core network, • decrypting the data relating to the user terminal by means of the symmetric encryption key, • establishing a connection with the user terminal in the case where the first identifier and the third identifier of the user terminal have the same value.
10. Authentication method according to claim 9 wherein the establishment of the connection with the user terminal is triggered in the case where the first identifier, the second identifier and the third identifier of the user terminal have the same value.
11. Authentication method according to any one of claims 9 or 10 in which the connection with the user terminal is intended to be established by means of data relating to the user terminal obtained from a decentralized database.
12. Node belonging to a blockchain network configured to execute a smart contract of said blockchain intended to generate an authentication token of a user terminal with a core network, the node comprising at least one processor configured to: • obtain a registration request from the user terminal comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter, and an identifier of the core network with which the user terminal is intended to be authenticated, • decrypt the identification token using a public key of the user terminal, • generate the user terminal authentication token with the core network in the case where the identification token and the control parameter have the same value, • encrypt the authentication token using a public encryption key associated with the core network.
13. Equipment belonging to a core network intended to authenticate a user terminal, said equipment comprising at least one processor configured to: • receive a connection request issued by the user terminal comprising a first identifier of the user terminal and a first authentication token of the user terminal encrypted using a public encryption key associated with the core network, • obtain, by means of the first identifier of the user terminal, a second authentication token of the user terminal encrypted by means of a public encryption key associated with the core network from a node belonging to a blockchain network configured to execute a smart contract of said blockchain, • decrypt a first authentication token and the second authentication token using a private key associated with the core network, • establish a connection with the user terminal in the case where the first authentication token and the second authentication token have the same value.
14. User terminal intended to authenticate itself to a core network, the user terminal comprising at least one processor configured to: • transmit a registration request comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter to a node belonging to a blockchain network configured to execute a smart contract of said blockchain intended to generate an authentication token of the user terminal with the core network, • receive, from the node belonging to a blockchain network, the authentication token of the user terminal with the core network encrypted using a public encryption key associated with the core network, • send, to a device of the core network, a connection request comprising an identifier of the user terminal and the encrypted authentication token, • receive, from the device of the core network, a message relating to the establishment of the connection.
15. Computer program comprising instructions for implementing a method for generating an authentication token of a user terminal with a core network according to any one of claims 1 to 6, when said program is executed by a computer.
16. Computer program comprising instructions for implementing a method of authenticating a user terminal according to any one of claims 7 to 11, when said program is executed by a computer.
Citation Information
Patent Citations
Method for oauth service through blockchain network, and terminal and server using the same
US20190306148A1
Securing communications for roaming user equipment (UE) using a native blockchain platform
US20190380031A1
Authentication of communication session participants using blockchain
US20230065364A1
User authentication using connection information provided by a blockchain network
WO2019086127A1