Method for generating a token for authenticating a user terminal with a core network based on the use of a blockchain and corresponding method for authenticating the user terminal

The blockchain-based authentication token generation method addresses security vulnerabilities in shared RAN environments by enabling secure user terminal registration with core networks, independent of RAN authentication, thus enhancing security and reducing operational complexity.

WO2025119852A1PCT designated stage expired Publication Date: 2025-06-12ORANGE SA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/084367
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-05
Filing Date
2024-12-02
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Current user terminal registration procedures in shared Radio Access Networks (RAN) are vulnerable to security threats due to the mutual authentication requirements between user terminals and core networks, which can be compromised in a shared RAN environment.

Method used

A method utilizing a blockchain-based system to generate and manage authentication tokens for user terminals, allowing secure registration with a core network without relying on the RAN for authentication, by using smart contracts and decentralized databases to ensure integrity and authenticity.

Benefits of technology

This solution enhances security and reduces operational complexity by eliminating the RAN's involvement in user terminal authentication, thereby mitigating security vulnerabilities in shared RAN environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024084367_12062025_PF_FP_ABST
    Figure EP2024084367_12062025_PF_FP_ABST
Patent Text Reader

Abstract

The solution of the present invention is based on using a blockchain structure to design a platform for authenticating a user terminal seeking to register with a core network operated by a telecommunications operator with which the user of the user terminal has subscribed to a service plan. More particularly, the present solution is based on delegating certain authentication operations from a user terminal to a third-party service interfacing the structure of the blockchain with at least one radio access network, or RAN, and a plurality of core networks, in order to guarantee the integrity and authenticity of the user terminal authentication process, in particular in a context of pooling the RAN among a plurality of entities which may or may not include the telecommunications operator with which the user of the user terminal has subscribed to a service plan.
Need to check novelty before this filing date? Find Prior Art

Description

Method for generating an authentication token for a user terminal on a core network based on the use of a blockchain and method for authenticating the corresponding user terminal

[0001] The present invention belongs to the general field of telecommunications, and in particular wireless communications implemented on radio-type networks such as mobile networks (e.g. 4G, 5G, B5G etc.), etc.

[0002] It relates more particularly to a method for generating an authentication token for a user terminal as well as a method for authenticating the user terminal to a communication network, such as a core network, by means of the authentication token, these two methods being based on a decentralized information storage technology of the blockchain type.

[0003] More specifically, the invention relates to mechanisms, implemented by a computer interfacing with at least one node of a blockchain network executing one or more smart contracts, leading on the one hand to obtaining the authentication token of the user terminal and on the other hand to the authentication of the user terminal with the communication network by means of this authentication token.

[0004] Radio Access Networks (RAN) are an essential component of telecommunications networks compliant with the fifth generation of radio communications standards or 5G as well as with earlier generations of radio communications standards such as 4G or 3G which correspond respectively to the fourth generation and third generation of radio communications standards.

[0005] In order to offer extensive and robust coverage, guaranteeing both access to the greatest number of people, even in the most remote geographical areas, as well as a quality of service best suited to the needs of their users, telecommunications operators are investing massively in the development and maintenance of the infrastructures constituting the RAN.

[0006] It is indeed important for a telecommunications operator to upgrade the components of its RANs to ensure that they are always able to meet the growing needs in terms of capacity and performance due to the increase in the number of user terminals and the growing demand for services requiring very high speeds.

[0007] Telecom operators are therefore facing financial challenges related to the need to constantly modernize and expand their RANs to remain competitive. Since RAN operation, maintenance, and upgrade costs represent a significant portion of a telecom operator's operational expenses, it is increasingly common for telecom operators to seek to pool their RAN.

[0008] RAN pooling is a practice that involves sharing all or part of the software and / or hardware infrastructure of these RANs between several players such as telecommunications operators, service providers, content providers, etc. This approach aims to optimize the use of resources, reduce costs and promote greater efficiency in the deployment and management of RANs.

[0009] Although RAN sharing offers economic benefits, it also leads to increased operational complexity. Beyond managing relationships between the different entities sharing a single RAN, there is the issue of registering user terminals with RAN equipment in order to be granted access to services provided by a telecommunications operator with whom the user has a service provision contract.

[0010] Currently, user terminal registration procedures rely on mutual authentication of the user terminal and the telecommunications operator's core network. This ensures that both parties are legitimate, with the user terminal proving its identity using a SIM certificate (Subscriber Identity Module) or equivalent, while the core network uses a certificate confirming its identity. However, the fact that the RAN through which the protocol exchanges between the user terminal and the core network are carried out is a shared RAN introduces a security vulnerability in this registration procedure.

[0011] There is therefore a need for a technique for registering a user terminal with a core network which does not have all or part of the drawbacks of the prior art, and which can be implemented in a context of sharing a RAN between several stakeholders with varied interests.

[0012] The present invention aims to remedy all or part of the drawbacks of the prior art, in particular those set out above, by proposing a solution which allows the registration of a user terminal with a core network operated by an entity separate from that operating the RAN through which the protocol exchanges relating to the user terminal registration procedure are transmitted.

[0013] To this end, and according to a first aspect, the invention relates to a method for generating an authentication token for a user terminal with a core network implemented by a node belonging to a blockchain network configured to execute a smart contract of said blockchain, said method comprising the following steps: obtaining a registration request for the user terminal comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter, and an identifier of the core network with which the user terminal is intended to be authenticated, decrypting the identification token using a public key of the user terminal, generating the authentication token for the user terminal with the core network in the case where the identification token and the control parameter have the same value,encryption of the authentication token using a public encryption key associated with the core network.,

[0014] Blockchain is a technology for storing and transmitting information that is transparent, secure, and operates without a central control body. More precisely, a blockchain is a distributed database that contains the history of all exchanges between its users since its creation: information sent by users and exchanges within the database are verified and grouped at regular time intervals into blocks, thus forming a chain. The whole system is secured by cryptography.

[0015] More specifically, transactions between users of the blockchain network are grouped into blocks. Each block is validated by the network's nodes using cryptographic techniques that depend on the type of blockchain used. Once the block is validated, it is timestamped and added to the blockchain, which is accessible to all users. The transaction is then visible to all nodes in the network. Once added to the blockchain, a block cannot be modified or deleted, ensuring the authenticity and security of the network.

[0016] There are public blockchains, open to all, and private, or consortium, blockchains, whose access and use are limited to a certain number of actors defined in advance.

[0017] Early blockchains found applications in digital currency, such as Bitcoin, which is an example of programmable currency. However, the decentralized nature of blockchain, coupled with its security and transparency, suggests applications far beyond monetary ones.

[0018] Blockchain infrastructures have recently been enriched with smart contracts, which can be defined as programs that automatically execute the terms and conditions of a contract, without requiring human intervention. In other words, a smart contract is a compiled computer program that includes a set of characteristics allowing it to automatically and autonomously execute at least some of the specific clauses of the contract it supports.

[0019] Using a blockchain, a smart contract, and decentralized databases to generate an authentication token eliminates the RAN's involvement in the process of registering a user terminal with a core network. Thus, even if the RAN is not operated by the telecommunications operator managing the core network, this has no impact on the registration process since all exchanges are carried out via the blockchain.

[0020] In particular embodiments of the method for generating an authentication token, the authentication token is recorded in the blockchain.

[0021] Such a step of registration in the blockchain makes the authentication token accessible to all users of the latter.

[0022] In particular embodiments of the method for generating an authentication token, the authentication token is generated by means of an identifier of the user terminal and at least one of the following data belonging to a group comprising: a digest, or "hash", of the transaction, a digest of an identifier of the transaction, a digest of a block of the blockchain in which the transaction is stored, a digest of an identifier of the block of the blockchain in which the transaction is stored, a timestamp data of the block.

[0023] Such an authentication token generated using all or part of this data has a high level of security. It is therefore difficult for a third party to usurp this authentication token.

[0024] In particular embodiments of the method for generating a token, the latter comprises a step of obtaining the public encryption key of the user terminal stored in the blockchain by means of an identifier of the user terminal included in the registration request of the user terminal.

[0025] In particular embodiments of the method for generating a token, the identification token is generated using the identifier of the user terminal and a random number.

[0026] Using a random number helps reduce the risk of authentication token spoofing or registration request reuse by a malicious third party.

[0027] In particular embodiments of the method for generating a token, the control parameter is generated using the identifier of the user terminal and the random number.

[0028] In particular embodiments of the method for generating a token, the registration request from the user terminal further comprises data relating to the type of service required, and / or data relating to the type of registration required.

[0029] For example, such additional data may be an identifier of a slice of the communications network, a required throughput value, a latency value to be respected, etc.

[0030] In particular embodiments of the method for generating a token, the random number is generated by equipment of an access network to which the user terminal is attached.

[0031] In particular embodiments of the method for generating a token, the identifier of the core network with which the user terminal is intended to be authenticated is provided by the equipment of the access network to which the user terminal is attached.

[0032] In particular modes of implementation of the method for generating a token, the identifier of the core network with which the user terminal is intended to be authenticated is stored in the blockchain.

[0033] According to another aspect, the invention relates to a method for authenticating a user terminal implemented by equipment belonging to a core network, said method comprising the following steps:receiving a connection request sent by the user terminal comprising a first identifier of the user terminal and a first authentication token of the user terminal encrypted using a public encryption key associated with the core network,obtaining, using the first identifier of the user terminal, a second authentication token of the user terminal encrypted using a public encryption key associated with the core network from a node belonging to a blockchain network configured to execute a smart contract of said blockchain,decrypting the first authentication token and the second authentication token using a private key associated with the core network,establishing a connection with the user terminal in the case where the first authentication token and the second authentication token have the same value.,

[0034] In particular embodiments of the authentication method, the generation of the authentication token by the smart contract constituting a transaction stored in at least one block of the blockchain, the authentication token comprises a digest, or "hash", of the transaction, a digest of the block of the blockchain in which the transaction is stored, a second identifier of the user terminal and a timestamp data of the block. [claim 8]

[0035] In particular embodiments of the authentication method, the latter further comprises the following steps:obtaining from a decentralized database, by means of the first identifier of the user terminal, data relating to the user terminal encrypted by means of a symmetric encryption key and the symmetric encryption key encrypted by means of the public encryption key associated with the core network, the data relating to the user terminal comprising at least a third identifier of the user terminal,decryption of the symmetric encryption key by means of the private key associated with the core network,decryption of the data relating to the user terminal by means of the symmetric encryption key,establishment of a connection with the user terminal in the case where the first identifier and the third identifier of the user terminal have the same value.

[0036] In particular modes of implementation of the authentication method, the establishment of the connection with the user terminal is triggered in the case where the first identifier, the second identifier and the third identifier of the user terminal have the same value.

[0037] In particular embodiments of the authentication method, the connection with the user terminal is intended to be established by means of data relating to the user terminal obtained from a decentralized database.

[0038] In particular modes of implementation of the authentication method, the authentication of the user terminal is stored in the blockchain.

[0039] According to another aspect, the invention relates to a node belonging to a blockchain network configured to execute a smart contract of said blockchain intended to generate an authentication token of a user terminal with a core network, the node comprising at least one processor configured to:obtain a registration request from the user terminal comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter, and an identifier of the core network with which the user terminal is intended to be authenticated,decrypt the identification token using a public key of the user terminal,generate the authentication token of the user terminal with the core network in the case where the identification token and the control parameter have the same value,encrypt the authentication token using a public encryption key associated with the core network, save the authentication token in the blockchain.,

[0040] According to another aspect, the invention also relates to equipment belonging to a core network intended to authenticate a user terminal, said equipment comprising at least one processor configured to:receive a connection request sent by the user terminal comprising a first identifier of the user terminal and a first authentication token of the user terminal encrypted by means of a public encryption key associated with the core network,obtain, by means of the first identifier of the user terminal, a second authentication token of the user terminal encrypted by means of a public encryption key associated with the core network from a node belonging to a blockchain network configured to execute a smart contract of said blockchain,decrypt a first authentication token and the second authentication token by means of a private key associated with the core network,establish a connection with the user terminal in case the first authentication token and the second authentication token have the same value.,

[0041] Finally, the invention also relates to a user terminal intended to authenticate itself to a core network, the user terminal comprising at least one processor configured to:transmit a registration request comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter to a node belonging to a blockchain network configured to execute a smart contract of said blockchain intended to generate an authentication token of the user terminal to the core network,receive, from the node belonging to a blockchain network, the authentication token of the user terminal to the core network encrypted using a public encryption key associated with the core network,transmit, to a device of the core network,a connection request including a user terminal identifier and the encrypted authentication token,receive, from the core network equipment, a message relating to the establishment of the connection.,

[0042] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate an exemplary embodiment thereof without any limiting character. In the figures:

[0043] larepresents a blockchain-based user terminal authentication system in which the methods of generating a user terminal authentication token and authenticating the user terminal according to the invention are implemented;

[0044] illustrates, in the form of a flowchart, the main steps of a method for generating an authentication token for a user terminal with a core network implemented by a node Ni belonging to a blockchain network according to an exemplary implementation of the invention;

[0045] illustrates, in the form of a flowchart, an example of a method for authenticating a user terminal implemented by equipment belonging to a core network according to an example of implementation of the invention;

[0046] represents a node belonging to a blockchain network capable of implementing certain steps of the methods for generating an authentication token of a user terminal and for authenticating the user terminal according to the invention;

[0047] represents equipment belonging to the core network capable of implementing certain steps of the user terminal authentication method according to the invention.

[0048] The present invention is based on the use of a blockchain structure to design a platform for authenticating a user terminal wishing to register with a core network operated by a telecommunications operator with which the user of the user terminal has subscribed to a service offer. More particularly, the present solution is based on the delegation of certain authentication operations of a user terminal to a third-party service interfacing the blockchain structure with at least one radio access network, or RAN, and a plurality of core networks, in order to guarantee the integrity and authenticity of the authentication process of the user terminals, in particular in a context of pooling of the RAN between a plurality of actors among which may or may not be the telecommunications operator with which the user of the user terminal has subscribed to a service offer.

[0049] Such a platform corresponds to a blockchain-based user terminal authentication system described with reference to the.

[0050] Such a system may comprise a blockchain network 100, also referred to hereinafter as the blockchain network 100, comprising a plurality of nodes N1 to N5 interconnected to each other. The structure of node N1 is illustrated in more detail in this document for the benefit of the reader. Each node N2 to N5 has an architecture similar to that of node N1, although this has not been detailed, for the sake of simplification, in the document. In this document, the term node refers exclusively to nodes N1-N5 belonging to the blockchain network 100.

[0051] It is noted that the term node can correspond to a software component as well as to a hardware component or a set of hardware and software components, a software component itself corresponding to one or more computer programs or sub-programs or more generally to any element of a program capable of implementing a function or a set of functions.

[0052] More generally, a node Ni comprises a random access memory (for example a RAM memory), a processing unit equipped for example with a processor, and driven by a computer program, representative of the code instructions of one or more smart contracts SC 11, SC UE , SC 102, stored in a read-only memory (for example, a ROM or a hard disk). When the Ni node is initialized, the code instructions of the computer program are, for example, loaded into the RAM before being executed by the processor of the processing unit.

[0053] Thus, in some embodiments, node N1 may further comprise:

[0054] - an Ethereum EVM 10 virtual machine, which is the execution environment for smart contracts in Ethereum. Remember that Ethereum is a decentralized exchange protocol that allows users to create smart contracts using a Turing-complete language. Other decentralized exchange protocols can be used, such as Polkadot, Solana, or Cardano;

[0055] - a STOR 12 data storage area;

[0056] - the bytecode of smart contracts SC 11, SC UE, SC 102 , i.e. the deterministic codes executable on the blockchain network 100, whose variables can be stored on the network 100, and whose functions can be called.

[0057] The backend of a user terminal's authentication platform is thus decentralized, and resides in the SC 11, SC smart contracts UE , SC 102 , implementing a panel of functions necessary for the authentication of a user terminal.

[0058] The users of the platform are, for example, equipment 101 belonging to the RAN, such as a base station or gNodeB, and equipment 102 belonging to a core network such as equipment performing an access and mobility management function or AMF for "Access and Mobility Management". These equipment 101 and 102 can interact with the platform via their interface, or "frontend" according to the English terminology. API requests (for "Application Programming Interface") allow interaction between the equipment 101, 102 on the one hand, and the smart contracts SC 11, SC UE , SC 102 , deployed on the blockchain 100 network on the other hand.

[0059] The equipment belonging to the core network 102 may comprise a transmission / reception module RX / TX 1020, configured to transmit requests to the platform and to obtain an authentication token from a user terminal. Equipment 102 may comprise in particular one or more processors, configured to execute program code instructions to authenticate a user terminal, in particular compliant with the programming languages ​​HTML (for “HyperText Markup Language”), and JS (for Java Script).

[0060] The equipment belonging to the RAN 101 comprises a transmission / reception module RX / TX 1010, configured to transmit requests for registration of user terminals to the platform. Such equipment belonging to the RAN 101 comprises in particular one or more processors, configured to execute program code instructions for the transmission of such data, in particular compliant with the programming languages ​​HTML (for “HyperText Markup Language”), and JS (for Java Script).

[0061] The listed and validated transactions between the devices belonging to the RAN 101 and the devices belonging to a core network 102 can be stored in the form of blocks in the nodes N1 to N5 of the blockchain 100. Consensus rules can help to limit malicious nodes, and to identify invalidated transactions. Cryptographic rules can help to ensure pseudo-anonymity of transactions and users, and the authenticity of authentication tokens generated in accordance with the solution of the present invention.

[0062] Laillustrates only one particular way, among several possible ones, of producing a node Ni so that it performs the steps of the methods for generating an authentication token and for authenticating the user terminal UE detailed below, in relation to figures 2 and 3 (in any one of the different embodiments, or in a combination of these embodiments). Indeed, these steps can be performed indifferently on a reprogrammable computing machine (a computer, a processor or a microcontroller) executing a program comprising a sequence of instructions, or on a dedicated computing machine (for example a set of logic gates such as an FPGA or an ASIC, or any other hardware module).

[0063] In the case where the node Ni is produced with a reprogrammable computing machine, the corresponding programs (i.e. the sequences of instructions) may be stored in a removable storage medium (such as for example a floppy disk, a CD-ROM or a DVD-ROM) or not, this storage medium being partially or totally readable by a computer or a processor.

[0064] Illustrates, in the form of a flowchart, the main steps of a method for generating an authentication token for a user terminal with a core network implemented by a node Ni belonging to a blockchain network 100 according to an exemplary implementation of the invention.

[0065] As illustrated by the, the method for generating an authentication token comprises a first step E1 during which a user terminal UE (not shown in the figures) attached to the equipment belonging to the RAN 101 transmits a request for registration of the user terminal RQT to the latter.

[0066] Such an RQT registration request including at least one IdTok identification token UE encrypted using a private encryption key KPriv UE of the EU user terminal and a PCheck control parameter UE . The use of such a private encryption key KPriv UE allows the authenticity of the UE user terminal that issued the registration request to be verified.

[0067] In other implementations, the RQT registration request may also include a random number Rand, an identifier Id UEof the EU user terminal or additional data such as an identifier of a slice of the communications network, a required throughput value, a latency value to be respected, etc.

[0068] As a reminder, network slicing is a key concept in the development of 5G telecommunications networks, playing a vital role in supporting the diversity of services and applications offered by 5G. A network slice is essentially an end-to-end virtualized network, providing specific and customized service capabilities to meet the requirements of a particular use case or application.

[0069] Generally speaking, the IdTok identification token UE of the user terminal UE is obtained by encrypting, using the private encryption key KPriv UE, a pair consisting of the identifier Id UE of the user terminal UE and the random number Rand. In other implementations, the IdTok identification token UE of the user terminal UE is obtained by encrypting, using the private encryption key KPriv UE , a digest or “hash” of the pair consisting of the identifier Id UE of the user terminal UE and the random number Rand.

[0070] The use of a random number in the generation of the IdTok identification token UE of the UE user terminal reduces the risk that a malicious third party can reuse the RQT registration request. This random number Rand can be generated by the UE user terminal itself or by the equipment belonging to the RAN 101. In this second case, the random number Rand is transmitted by the equipment belonging to the RAN 101 at the request of the UE user terminal.

[0071] Similarly, the PCheck control parameter UE corresponds to the pair consisting of the identifier Id UE of the user terminal UE and the random number Rand or a digest thereof.

[0072] In a step E2, the equipment belonging to the RAN 101 transmits the RQT registration request received in step E1 to a node N1-5 belonging to the blockchain network 100.

[0073] In other implementations, prior to transmitting the registration request RQT to a node N1-5, the equipment belonging to the RAN 101 selects a core network with which the user terminal UE wishes to register. The equipment belonging to the RAN 101 makes this selection, for example, on the basis of information included in the registration request RQT, such as a core network identifier IdCore, or on the basis of information made available to it by parties other than the user terminal UE.

[0074] Thus, the equipment belonging to the RAN 101 can contact a node N1-5 executing a smart contract whose function is to store a list of core network identifiers IdCore with which the user terminal can register. Such a smart contract is updated periodically by equipment belonging to these different core networks. In order to select the core network with which the user terminal will register, the equipment belonging to the RAN 101 uses data associated with the identifier IdCore of each core network stored in the smart contract in order to determine which, among all of these core networks, best meets the needs of the user terminal UE in terms of, for example, quality of service, throughput, latency, etc.

[0075] For example, the core network identifier IdCore points to the equipment belonging to the core network 102. It may be a network address, such as an IP address associated with this equipment belonging to the core network 102.

[0076] Thus, at the end of step E2, the node N1-5 has all or part of the following data, provided by the equipment belonging to the RAN 101: the IdTok identification token UE of the UE user terminal, of the PCheck control parameter UE , the additional data and the identifier of the selected core network IdCore. Thus, indirectly, the node N1-5 has the identifier Id UE of the user terminal UE and the random number Rand.

[0077] The reception of the registration request RQT by the node N1-5 triggers the execution of the smart contract SC 11 in a step E3. The smart contract SC 11 has the function of generating an authentication token AuthTok UE-102enabling the user terminal UE to authenticate itself with the core network via the equipment belonging to the core network 102 in order to be able to access one or more services provided by the telecommunications operator managing the core network. The smart contract SC 11 can, for the same user terminal UE, generate a plurality of authentication tokens, each authentication token generated corresponding to a core network with which the user terminal UE can register without it being necessary for the user terminal UE to be equipped with several SIM cards (for "Subscriber Identification Module" or module identifying the user in French).

[0078] In a step E4, the node N1-5 contacts another node N1-5 also belonging to the blockchain network 100 and executing the smart contract SC UE in order to obtain the public encryption key KPub UE of the EU user terminal. The SC smart contractUE is a smart contract that, when executed, provides a CID UE pointing to a section of a distributed database BdD in which data relating to the user terminal UE are stored. The nature of this data relating to the user terminal UE will be discussed in more detail later in this document. Such a database BdD may be, for example, an IPFS database for “InterPlanetary File System” or interplanetary file system in French.

[0079] IPFS is a distributed peer-to-peer file system that does not rely on centralized servers. This system allows a set of computing devices to be connected to a single file system. In particular, IPFS provides a block file storage model that can be addressed using hyperlinks.

[0080] Node N1-5 running smart contract SC 11 addresses node N1-5 running smart contract SC UE using the identifier Id UE of the user terminal UE included in the RQT registration request.

[0081] In other implementations, both smart contracts SC 11 and SC UE are executed by the same node N1-5.

[0082] Once the SC smart contract UE was executed, the CID identifier UE is transmitted to node N1-5 executing smart contract SC 11 in step E5.

[0083] Using the CID identifier UE , the node N1-5 executing the smart contract SC 11 addresses the database BdD in order to obtain all or part of the data relating to the user terminal UE that it contains, and more particularly the public encryption key KPub UE of the user terminal UE, in a step E6.

[0084] The BdD database includes a lot of D data UE relating to the user terminal UE which are all encrypted except for the public encryption key KPub UE of the EU user terminal. More specifically, the data D UE relating to the user terminal UE are encrypted using a symmetric encryption key KSym known to the core network. This symmetric encryption key KSym is then encrypted using a public encryption key KPub 102 of the equipment belonging to the core network 102. This limits the risks of fraudulent use of data relating to the user terminal UE.

[0085] This encrypted version of the symmetric encryption key KSym is stored in the database BdD with the encrypted version of the data D UE relating to the user terminal UE and the public encryption key KPub UE of the EU user terminal.

[0086] In other implementation modes, the database BdD stores, for a given user terminal UE, as many encrypted versions of the data D UE relating to the user terminal UE, and as many encrypted versions of a symmetric encryption key KSym, as there are core networks with which the user terminal UE can register.

[0087] The BdD database thus queried transmits the public encryption key KPub UE from the user terminal UE to the node N1-5 executing the smart contract SC 11 in a step E7. In other implementation modes, the database BdD transmits to the node N1-5 executing the smart contract SC 11 all the data concerning the user terminal that it contains.

[0088] Once in possession of the KPub public encryption key UEof the user terminal UE, the node N1-5 running the smart contract SC 11 proceeds to decrypt the identification token IdTok UE of the user terminal UE in a step E8.

[0089] At the end of step E8, the node N1-5 executing the smart contract SC 11 has the decrypted identification token IdTok UE , which, as a reminder, can be the pair consisting of the identifier Id UE of the user terminal UE and the random number Rand or the digest of this pair.

[0090] In a step E9, the node N1-5 executing the smart contract SC 11 compares the decrypted identification token IdTok UE with the PCheck control parameter UE .

[0091] If the value of the decrypted ID token IdTok UE corresponds to the value of the PCheck control parameter UEthen the node executing the smart contract SC 11 executes step E10. Otherwise, that is, when the value of the decrypted identification token IdTok UE does not match the value of the PCheck control parameter UE , this means that a possible fraudulent use of the registration request is at work. The execution of the SC 11 smart contract is then interrupted.

[0092] Step E10 corresponds to the generation of the AuthTok authentication token UE-102 of the user terminal to the core network by the node N1-5 executing the smart contract SC 11.

[0093] In order to be able to generate the AuthTok authentication token UE-102 of the user terminal UE to the core network, the node N1-5 executing the smart contract SC 11 contacts, in a step E11, another node N1-5 also belonging to the blockchain network 100 and executing the smart contract SC 102in order to obtain the public encryption key KPub 102 of the equipment belonging to the core network 102. The SC smart contract 102 is a smart contract that, when executed, provides the public encryption key KPub 102 of the equipment belonging to the core network 102 .

[0094] Node N1-5 running smart contract SC 11 addresses node N1-5 running smart contract SC UE by means of the IdCore identifier of the equipment belonging to the core network 102 which it received from the equipment belonging to the RAN 101 during step E2.

[0095] In other implementations, both smart contracts SC 11 and SC 102 are executed by the same node N1-5.

[0096] Once the SC smart contract 102 was executed, the public encryption key KPub 102of the equipment belonging to the core network 102 is transmitted to the node N1-5 executing the smart contract SC 11 in a step E12.

[0097] Steps E11 and E12 can be implemented by node N1-5 executing smart contract SC 11 at any time between steps E3 and E9 or concomitantly with one of these two steps E3 or E9.

[0098] Back to step E10, node N1-5 running smart contract SC 11 generates the authentication token AuthTok UE-102 of the user terminal to the core network. Such an AuthTok authentication token UE-102 is obtained by encrypting, using the public encryption key KPub 102 of the equipment belonging to the core network 102, the identifier Id UE of the EU user terminal and at least one of the following data:

[0099] - a summary of a transaction carried out within the blockchain network 100, this transaction comprising all of the exchanges and actions carried out during steps E3 to E12,

[0100] - an identifier of the transaction carried out within the blockchain network 100 or the digest of this identifier,

[0101] - a digest of a block B constituting the blockchain in which the transaction is memorized / stored,

[0102] - an identifier of the block B constituting the blockchain in which the transaction is stored or a digest of this identifier, and

[0103] - a TS timestamp data B from block B.

[0104] For example, the AuthTok authentication token UE-102 can be obtained by encrypting, using the public encryption key KPub 102 of the equipment belonging to the core network 102, the identifier Id UEof the user terminal UE, the digest of the transaction carried out within the blockchain network 100, the digest of the block B constituting the chain of blocks in which the transaction is memorized / stored, and the timestamp data TS B from block B.

[0105] Once the AuthTok authentication token UE-102 of the user terminal to the generated core network, it is then stored in the blockchain network 100 in a step E11. It is thus accessible to any stakeholder in the blockchain network 100.

[0106] In other implementations, the AuthTok authentication token UE-102 from the user terminal to the core network is transmitted, via the equipment belonging to the RAN 101, to the user terminal UE.

[0107] Illustrates, in the form of a flowchart, an example of a method for authenticating a user terminal implemented by equipment belonging to a core network 102.

[0108] As illustrated by the, the method for authenticating a user terminal implemented by equipment belonging to a core network 102 comprises a first step G1 during which a user terminal UE (not shown in the figures) attached to the equipment belonging to the RAN 101 transmits a ConR connection request sent by the user terminal UE. Such a ConR connection request comprises the identifier Id UE of the UE user terminal and a first value of the AuthTok authentication token UE-102 from the user terminal to the core network.

[0109] In a step G2, the equipment belonging to the core network 102 obtains from the blockchain network 100 a second value of the authentication token AuthTok UE-102 of the user terminal to the core network using the identifier Id UE of the UE user terminal. This second value of the AuthTok authentication token UE-102of the user terminal from the core network can be obtained from a node N1-5 belonging to the blockchain network 100 executing a smart contract whose function is to provide this second value of the AuthTok authentication token UE-102 from the user terminal to the core network.

[0110] At the end of step G2, the equipment belonging to the core network 102 is in possession of the two values ​​of the authentication token AuthTok UE-102 of the user terminal to the core network, that provided by the user terminal UE and that, reliable and which therefore serves as a control value, provided by a node N1-5 belonging to the blockchain network 100.

[0111] The equipment belonging to the core network 102 then proceeds to decrypt the first value of the AuthTok authentication token. UE-102 of the user terminal to the core network and the second value of the AuthTok authentication token UE-102from the user terminal to the core network using a private encryption key KPriv 102 of the equipment belonging to the core network 102 in a step G3.

[0112] Once the two values ​​of the AuthTok authentication token UE-102 of the user terminal to the core network, the equipment belonging to the core network 102 compares one by one the values ​​of the digest of a transaction carried out within the blockchain network 100, of the digest of block B of the chain of blocks in which the transaction is memorized / stored, of the identifier Id UE of the user terminal UE, and of the timestamp data TS B of block B included in the two AuthTok authentication tokens UE-102 of the user terminal to the core network in possession of the equipment belonging to the core network 102 during a step G4.

[0113] If the set of values ​​of the digest of a transaction carried out within the blockchain network 100, of the digest of block B of the blockchain in which the transaction is memorized / stored, of the identifier Id UE of the user terminal UE, and of the timestamp data TS B of block B included in the two AuthTok authentication tokens UE-102 of the user terminal to the core network correspond, the equipment belonging to the core network 102 then executes step G5.

[0114] Otherwise, that is to say, when at least one of the values ​​of the digest of a transaction carried out within the blockchain network 100, of the digest of the block B of the chain of blocks in which the transaction is memorized / stored, of the identifier Id UE of the user terminal UE, and of the timestamp data TS B of block B included in the AuthTok authentication token UE-102of the user terminal to the core network provided by the user terminal UE does not match the corresponding value included in the AuthTok authentication token UE-102 of the user terminal to the core network provided by node N1-5, this means that a possible fraudulent use of the ConR connection request is at work. The execution of the authentication process is then interrupted.

[0115] Returning to step G5, the equipment belonging to the core network 102 contacts a node N1-5 belonging to the blockchain network 100 and executing the smart contract SC UE in order to obtain the CID identifier UE pointing to the section of the distributed database BdD in which data relating to the user terminal UE is stored.

[0116] Once the SC smart contract UE was executed, the CID identifier UEis transmitted to the equipment belonging to the core network 102 in a step G6.

[0117] Using the CID identifier UE , the equipment belonging to the core network 102 addresses the database BdD in order to obtain all or part of the data relating to the user terminal UE that it contains in a step G7.

[0118] As discussed earlier in this document, the BdD database includes many D data UE relating to the EU user terminal which are all encrypted except for the public encryption key KPub UE of the EU user terminal. More specifically, the data D UE relating to the user terminal UE are encrypted using the symmetric encryption key KSym known to the core network. This symmetric encryption key KSym is then encrypted using a public encryption key KPub 102 of the equipment belonging to the core network 102.

[0119] This encrypted version of the symmetric encryption key KSym is stored in the database BdD with the encrypted version of the data D UE relating to the user terminal UE and the public encryption key KPub UE of the EU user terminal.

[0120] The database BdD thus queried transmits all the data concerning the user terminal that it contains to the equipment belonging to the core network 102 during a step G8.

[0121] Upon receipt of the data relating to the user terminal UE from the database BdD, the equipment belonging to the core network 102 proceeds to decrypt the symmetric encryption key KSym using its private encryption key KPriv 102 in a G9 step.

[0122] Then, once in possession of the symmetric encryption key KSym, the equipment belonging to the core network 102 proceeds to decrypt the data D UE relating to the user terminal UE by means of the latter in a step G10.

[0123] The equipment belonging to the core network 102 then establishes, in a step G11, a connection with the user terminal UE by means of the data D UE relating to the EU user terminal.

[0124] In other implementations, the connection with the user terminal UE is established in the case where the identifier Id UE of the user terminal UE from the BdS database corresponds to the identifier Id UE of the user terminal UE provided by the node N1-5 belonging to the blockchain network 100.

[0125] Otherwise, that is, when the identifier Id UEof the UE user terminal from the BdS database does not correspond to the identifier Id UE of the user terminal UE provided by the node N1-5 belonging to the blockchain network 100, the establishment of the connection with the user terminal UE is interrupted.

[0126] In other implementations, the connection with the user terminal UE is established in the case where the identifier Id UE of the user terminal UE from the BdS database corresponds to the identifier Id UE of the user terminal UE provided by the node N1-5 belonging to the blockchain network 100 and to the identifier Id UE of the user terminal UE included in the ConR connection request.

[0127] Otherwise, that is, when the identifier Id UE of the UE user terminal from the BdS database does not correspond to the identifier Id UEof the user terminal UE provided by the node N1-5 belonging to the blockchain network 100 and to the identifier Id UE of the user terminal UE included in the connection request ConR, the establishment of the connection with the user terminal UE is interrupted.

[0128] Once the connection with the user terminal UE is established, the user terminal and the equipment belonging to the core network 102 conventionally implement the steps of the attachment and key management procedure or AKA for “Attachment and Key Agreement” which follow the mutual authentication of the user terminal UE and the equipment belonging to the core network 102.

[0129] Thus, the user terminal UE and the equipment belonging to the core network 102 implement a procedure for negotiating encryption keys, such as an integrity key and an encryption key intended to be used to secure the data exchanges occurring between the user terminal UE and the core network. The negotiation of the encryption keys can be done using the Diffe-Hellman algorithm.

[0130] Larepresents a node N1-N5 belonging to a blockchain network capable of implementing certain steps of the solution previously described.

[0131] A node N1-N5 may comprise at least one hardware processor 401, a storage unit 402 corresponding to the STOR memory 12 of the, a first interface 403, and at least one second network interface 404 and an Ethereum EVM virtual machine 10 which are connected to each other through a bus 405. Of course, the constituent elements of the node N1-N5 may be connected by means of a connection other than a bus.

[0132] The processor 401 controls the operations of the node N1-N5. The storage unit 402 stores at least one program for implementing the various methods that are the subject of the invention to be executed by the processor 401, and various data, such as parameters used for calculations performed by the processor 401, intermediate data of calculations performed by the processor 401, etc. The processor 401 may be formed by any known and suitable hardware or software, or by a combination of hardware and software. For example, the processor 401 may be formed by dedicated hardware such as a processing circuit, or by a programmable processing unit such as a central processing unit (“Central Processing Unit”) which executes a program stored in a memory thereof.

[0133] The storage unit 402 may be formed by any suitable means capable of storing the program(s) and data in a computer-readable manner. Examples of the storage unit 402 include non-transitory computer-readable storage media such as semiconductor memory devices, and magnetic, optical, or magneto-optical recording media loaded into a read-write unit.

[0134] Interface 403 provides an interface between node N1-N5 and another node N1-N5 in the blockchain network.

[0135] The network interface 404 provides a connection between the node N1-N5 and the equipment belonging to the RAN 101, or the equipment belonging to the core network 102 or the database BdD.

[0136] La represents a piece of equipment belonging to the core network 102 capable of implementing certain steps of the authentication method of the user terminal UE previously described.

[0137] A piece of equipment belonging to the core network 102 may comprise at least one hardware processor 501, a storage unit 502, a first interface 503, and at least one second network interface 504 which are connected to each other via a bus 505. Of course, the constituent elements of the equipment belonging to the core network 102 may be connected by means of a connection other than a bus.

[0138] The processor 501 controls the operations of the equipment belonging to the core network 102. The storage unit 502 stores at least one program for implementing the various methods that are the subject of the invention to be executed by the processor 501, and various data, such as parameters used for calculations performed by the processor 501, intermediate data of calculations performed by the processor 501, etc. The processor 501 may be formed by any known and suitable hardware or software, or by a combination of hardware and software. For example, the processor 801 may be formed by dedicated hardware such as a processing circuit, or by a programmable processing unit such as a central processing unit ("Central Processing Unit") which executes a program stored in a memory thereof.

[0139] The storage unit 502 may be formed by any suitable means capable of storing the program(s) and data in a computer-readable manner. Examples of the storage unit 502 include non-transitory computer-readable storage media such as semiconductor memory devices, and magnetic, optical, or magneto-optical recording media loaded into a read-write unit.

[0140] Interface 503 provides an interface between the equipment belonging to the core network 102 and a node N1-N5 of the blockchain network 100.

[0141] The network interface 504 provides a connection between the equipment belonging to the core network 102 and the equipment belonging to the RAN 101, or the database BdD.

Claims

Method for generating an authentication token of a user terminal with a core network implemented by a node belonging to a blockchain network configured to execute a smart contract of said blockchain, said method comprising the following steps: obtaining a registration request of the user terminal comprising at least one identification token encrypted by means of a private encryption key of the user terminal and a control parameter, and an identifier of the core network with which the user terminal is intended to be authenticated, decryption of the identification token by means of a public key of the user terminal, generation of the authentication token of the user terminal with the core network in the case where the identification token and the control parameter have the same value, encryption of the authentication token by means of a public encryption key associated with the core network. Method for generating an authentication token for a user terminal according to claim 1, in which the authentication token is generated using an identifier of the user terminal and at least one of the following data belonging to a group comprising: a digest, or "hash", of the transaction, a digest of an identifier of the transaction, a digest of a block of the blockchain in which the transaction is stored, a digest of an identifier of the block of the blockchain in which the transaction is stored, a timestamp data of the block. Method for generating an authentication token for a user terminal according to any one of claims 1 or 2 comprising a step of obtaining the public encryption key of the user terminal stored in the blockchain by means of an identifier of the user terminal included in the registration request of the user terminal. A method for generating an authentication token of a user terminal according to claim 3 wherein the identification token is generated using the identifier of the user terminal and a random number. A method for generating an authentication token of a user terminal according to claim 4 wherein the control parameter is generated using the identifier of the user terminal and the random number. Method for generating an authentication token of a user terminal according to any one of claims 4 or 5 in which the random number is generated by equipment of an access network to which the user terminal is attached. Method for authenticating a user terminal implemented by equipment belonging to a core network, said method comprising the following steps:receiving a connection request sent by the user terminal comprising a first identifier of the user terminal and a first authentication token of the user terminal encrypted using a public encryption key associated with the core network,obtaining, using the first identifier of the user terminal, a second authentication token of the user terminal encrypted using a public encryption key associated with the core network from a node belonging to a blockchain network configured to execute a smart contract of said blockchain,decrypting the first authentication token and the second authentication token using a private key associated with the core network,establishing a connection with the user terminal in the case where the first authentication token and the second authentication token have the same value., Authentication method according to claim 7 wherein, the generation of the authentication token by the smart contract constituting a transaction stored in at least one block of the blockchain, the authentication token comprises a digest, or "hash", of the transaction, a digest of the block of the blockchain in which the transaction is stored, a second identifier of the user terminal and a timestamp data of the block. Authentication method according to any one of claims 7 or 8 further comprising the following steps:obtaining from a decentralized database, by means of the first identifier of the user terminal, data relating to the user terminal encrypted by means of a symmetric encryption key and the symmetric encryption key encrypted by means of the public encryption key associated with the core network, the data relating to the user terminal comprising at least a third identifier of the user terminal,decrypting the symmetric encryption key by means of the private key associated with the core network,decrypting the data relating to the user terminal by means of the symmetric encryption key,establishing a connection with the user terminal in the case where the first identifier and the third identifier of the user terminal have the same value. Authentication method according to claim 9 wherein the establishment of the connection with the user terminal is triggered in the case where the first identifier, the second identifier and the third identifier of the user terminal have the same value. Authentication method according to any one of claims 9 or 10 in which the connection with the user terminal is intended to be established by means of data relating to the user terminal obtained from a decentralized database. Node belonging to a blockchain network configured to execute a smart contract of said blockchain intended to generate an authentication token of a user terminal with a core network, the node comprising at least one processor configured to:obtain a registration request from the user terminal comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter, and an identifier of the core network with which the user terminal is intended to be authenticated,decrypt the identification token using a public key of the user terminal,generate the authentication token of the user terminal with the core network in the case where the identification token and the control parameter have the same value,encrypt the authentication token using a public encryption key associated with the core network. Equipment belonging to a core network intended to authenticate a user terminal, said equipment comprising at least one processor configured to:receive a connection request sent by the user terminal comprising a first identifier of the user terminal and a first authentication token of the user terminal encrypted using a public encryption key associated with the core network,obtain, using the first identifier of the user terminal, a second authentication token of the user terminal encrypted using a public encryption key associated with the core network from a node belonging to a blockchain network configured to execute a smart contract of said blockchain,decrypt a first authentication token and the second authentication token using a private key associated with the core network,establish a connection with the user terminal in case the first authentication token and the second authentication token have the same value., A user terminal intended to authenticate itself to a core network, the user terminal comprising at least one processor configured to:transmit a registration request comprising at least one identification token encrypted using a private encryption key of the user terminal and a control parameter to a node belonging to a blockchain network configured to execute a smart contract of said blockchain intended to generate an authentication token of the user terminal to the core network,receive, from the node belonging to a blockchain network, the authentication token of the user terminal to the core network encrypted using a public encryption key associated with the core network,send, to a device of the core network, a connection request comprising an identifier of the user terminal and the encrypted authentication token,receive,from the core network equipment, a message relating to the establishment of the connection., Computer program comprising instructions for implementing a method for generating an authentication token for a user terminal with a core network according to any one of claims 1 to 6, when said program is executed by a computer. Computer program comprising instructions for implementing a method of authenticating a user terminal according to any one of claims 7 to 11, when said program is executed by a computer.

Citation Information

Patent Citations

  • Method for oauth service through blockchain network, and terminal and server using the same

    US20190306148A1

  • Securing communications for roaming user equipment (UE) using a native blockchain platform

    US20190380031A1

  • Authentication of communication session participants using blockchain

    US20230065364A1

  • User authentication using connection information provided by a blockchain network

    WO2019086127A1