Method for administering a profile for access to a communication network

    公开(公告)号:US20230016837A1

    公开(公告)日:2023-01-19

    申请号:US17786199

    申请日:2020-12-17

    申请人: Orange

    IPC分类号: H04L9/40

    摘要: A method for administering a profile for access to a communication network by using a security module. The security module receives a request to perform an administrative action relating to an access profile originating from an administration entity. The request includes a certificate from the administration entity. The security module verifies that the certificate received is legitimate and that it carries information indicating that the entity is authorised to request the action and, if so, sends an authorisation to perform the action in conjunction with the administration entity. Otherwise, the security module rejects the request.

    Method of registering a mobile terminal in a mobile communication network

    公开(公告)号:US10887754B2

    公开(公告)日:2021-01-05

    申请号:US16091799

    申请日:2017-04-03

    申请人: ORANGE

    摘要: A method of registering a mobile terminal in a mobile communication network via a base station, an access link between the base station and the core of the network being switched from a normal mode of operation to a degraded mode of operation. The method is implemented by a local mobility management entity and includes: receiving an attachment request, retransmitted by the base station and originating from the mobile terminal, the request including an identifier of the mobile terminal, dispatching, to an agent mobility management item, a request for security information specific to the mobile terminal, the request including the identifier of the mobile terminal, receiving a response to the request for security information, the response including security information specific to the mobile terminal, the security information originating from a server of subscribers of the network, and authenticating the terminal by using the security information received.

    Method for obtaining a profile for access to a communication network by a secondary terminal via a main terminal

    公开(公告)号:US11425117B2

    公开(公告)日:2022-08-23

    申请号:US16636185

    申请日:2018-07-26

    申请人: ORANGE

    IPC分类号: H04L9/40 H04W12/06

    摘要: A method for obtaining a profile for access to a communication network by a secondary terminal via a main terminal. The main terminal includes a security element having an authentication key, the authentication key being used by the network and by the main terminal to generate at least one session master key specific to the main terminal. The secondary terminal: provides its identifier to the main terminal; receives from the main terminal a temporary key specific to the secondary terminal, a temporary identifier of the secondary terminal, and an identifier of the network for access to the network. The temporary key is based on the temporary identifier of the secondary terminal and the session master key of the main terminal. The temporary key, the temporary identifier, the identifier of the secondary terminal, and the identifier of the access network are included in an profile for access to the network.

    Method for Determining a Key for Securing Communication Between a User Apparatus and an Application Server

    公开(公告)号:US20200344603A1

    公开(公告)日:2020-10-29

    申请号:US16962329

    申请日:2019-01-11

    申请人: ORANGE

    发明人: Todor Gamishev

    IPC分类号: H04W12/04 H04W12/06

    摘要: A method for determining a key for securing communication between a user apparatus and an application server. An authentication server of a mobile communication network and the user apparatus generate a secret master key during an authentication procedure. The user apparatus sends the authentication server a request for a key to communicate with the application server and receives a random variable. The authentication server and the user apparatus calculate the requested key by using a key derivation function applied to at least the random variable, a user identifier and an application server identifier using the master key.

    Method for determining a key for securing communication between a user apparatus and an application server

    公开(公告)号:US11895487B2

    公开(公告)日:2024-02-06

    申请号:US16962329

    申请日:2019-01-11

    申请人: ORANGE

    发明人: Todor Gamishev

    摘要: A method for determining a key for securing communication between a user apparatus and an application server. An authentication server of a mobile communication network and the user apparatus generate a secret master key during an authentication procedure. The user apparatus sends the authentication server a request for a key to communicate with the application server and receives a random variable. The authentication server and the user apparatus calculate the requested key by using a key derivation function applied to at least the random variable, a user identifier and an application server identifier using the master key.

    METHOD FOR OBTAINING A COMMAND RELATING TO A NETWORK ACCESS PROFILE OF AN EUICC SECURITY MODULE

    公开(公告)号:US20230044937A1

    公开(公告)日:2023-02-09

    申请号:US17786959

    申请日:2020-12-04

    申请人: Orange

    IPC分类号: H04W12/02 H04W8/20

    摘要: A method for obtaining a command relating to a network access profile of an eUICC security module incorporated into a communication device and associated with a physical identifier. The communication terminal: obtains the physical identifier and an anonymous identifier of the security module is calculated from the physical identifier and a random parameter; transmits a request to obtain the command, via an “operator server”, to a “preparation server”, the request to obtain including the anonymous identifier of the security module; obtains the random parameter and calculates the anonymous identifier from the physical identifier of the security module and the random parameter; and sends, to a “discovery server”, a request to obtain information intended to obtain the command, this request to obtain information including the anonymous identifier, in order to obtain, in response, from the discovery server, an address of the preparation server.

    METHOD FOR MUTUAL AUTHENTICATION BETWEEN USER EQUIPMENT AND A COMMUNICATION NETWORK

    公开(公告)号:US20190246272A1

    公开(公告)日:2019-08-08

    申请号:US16339599

    申请日:2017-10-02

    申请人: ORANGE

    摘要: A method for mutual authentication between user equipment and a communications network. The network includes a mobility management entity and a home subscriber server. The method, implemented by the user equipment, includes: receiving an authentication challenge having an token based on a first index and a first authentication message calculated by the home subscriber server and based on a first sequence number; checking that a condition of a set is true, the set including: the first sequence number is the same as a second sequence number stored in the user equipment, and the first sequence number is the same as a preceding value of the second sequence number and the first index is higher than a second index stored in the client equipment; and calculating and sending, when a condition is true, an authentication result and an authentication message, based on the preceding value of the second sequence number.

    Method for protecting a network access profile against cloning

    公开(公告)号:US20230370247A1

    公开(公告)日:2023-11-16

    申请号:US18003583

    申请日:2021-06-16

    申请人: Orange

    IPC分类号: H04L9/08 H04L9/40

    CPC分类号: H04L9/0819 H04L63/102

    摘要: A method for protecting a network access profile against cloning. A first mobile equipment includes a first security module havng the network access profile. A second mobile equipment is designed to receive the network access profile and includes a second security module. The first and second security modules are designed to establish a logic communication channel with each other. The method is implemented by the first security module and includes: generating a secret key; using the secret key to encrypt a data packet associated with the network access profile; sending the encrypted packet to the second security module through the logic communication channel; receiving, from the second security module, an acknowledgement of a correct receipt of the encrypted data packet; deleting the data packet associated with the network access profile; and then sending the secret key to the second security module through the logic communication channel.

    Method for mutual authentication between user equipment and a communication network

    公开(公告)号:US11159940B2

    公开(公告)日:2021-10-26

    申请号:US16339599

    申请日:2017-10-02

    申请人: ORANGE

    摘要: A method for mutual authentication between user equipment and a communications network. The network includes a mobility management entity and a home subscriber server. The method, implemented by the user equipment, includes: receiving an authentication challenge having an token based on a first index and a first authentication message calculated by the home subscriber server and based on a first sequence number; checking that a condition of a set is true, the set including: the first sequence number is the same as a second sequence number stored in the user equipment, and the first sequence number is the same as a preceding value of the second sequence number and the first index is higher than a second index stored in the client equipment; and calculating and sending, when a condition is true, an authentication result and an authentication message, based on the preceding value of the second sequence number.

    METHOD FOR OBTAINING A PROFILE FOR ACCESS TO A COMMUNICATION NETWORK BY A SECONDARY TERMINAL VIA A MAIN TERMINAL

    公开(公告)号:US20200267141A1

    公开(公告)日:2020-08-20

    申请号:US16636185

    申请日:2018-07-26

    申请人: ORANGE

    IPC分类号: H04L29/06 H04W12/06

    摘要: A method for obtaining a profile for access to a communication network by a secondary terminal via a main terminal. The main terminal includes a security element having an authentication key, the authentication key being used by the network and by the main terminal to generate at least one session master key specific to the main terminal. The secondary terminal: provides its identifier to the main terminal; receives from the main terminal a temporary key specific to the secondary terminal, a temporary identifier of the secondary terminal, and an identifier of the network for access to the network. The temporary key is based on the temporary identifier of the secondary terminal and the session master key of the main terminal. The temporary key, the temporary identifier, the identifier of the secondary terminal, and the identifier of the access network are included in an profile for access to the network.