EP4541048A1 - Procédé de communication entre un premier équipement et un serveur distant, procédé de gestion des communications, premier équipement, serveur distant et programme d'ordinateur correspondants - Google Patents
Procédé de communication entre un premier équipement et un serveur distant, procédé de gestion des communications, premier équipement, serveur distant et programme d'ordinateur correspondantsInfo
- Publication number
- EP4541048A1 EP4541048A1 EP23732931.3A EP23732931A EP4541048A1 EP 4541048 A1 EP4541048 A1 EP 4541048A1 EP 23732931 A EP23732931 A EP 23732931A EP 4541048 A1 EP4541048 A1 EP 4541048A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- equipment
- mac address
- remote server
- communication
- interface
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/02—Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/606—Protecting data by securing the transmission between two devices or processes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/50—Address allocation
- H04L61/5038—Address allocation for local use, e.g. in LAN or USB networks, or in a controller area network [CAN]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
- H04W12/75—Temporary identity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2101/00—Indexing scheme associated with group H04L61/00
- H04L2101/60—Types of network addresses
- H04L2101/618—Details of network addresses
- H04L2101/622—Layer-2 addresses, e.g. medium access control [MAC] addresses
Definitions
- TITLE Method of communication between a first piece of equipment and a remote server, method of managing communications, first piece of equipment, remote server and corresponding computer program.
- the field of the invention is that of communications within at least one communication network, for example a computer network implementing the IP protocol.
- the invention relates to the management of at least one MAC address (in English “Media Access Control”) assigned to at least one interface of equipment connected to a communications network.
- MAC address in English “Media Access Control”
- the invention notably proposes a solution making it possible to contribute to the preservation of the confidentiality of communications.
- the QUIC protocol Error! Referral source not found. is a communication protocol based on the UDP protocol (in English “User Datagram Protocol”) of the transport layer. Compared to the use of the TCP protocol (in English “Transmission Control Protocol”), the QUIC protocol makes it possible in particular to reduce the latency times generally observed when establishing TCP connections.
- the QUIC protocol not only encrypts useful data, unlike the TLS protocol (in English “Transport Layer Security”), but also connection control information. Thus, traditional solutions for inserting application relays (“proxies” in English) are not directly reusable for communications established according to the QUIC protocol.
- QUIC connection control information sent in clear text is limited to the strict minimum. For example, a QUIC packet includes an unencrypted header, including one or more flags, one or more connection identifiers and a packet number.
- a transport identifier (also sometimes referred to as "transport address") being defined by a quadruplet ⁇ source IP address, source port number, destination IP address, destination port number ⁇ , but on at least one connection identifier, called CID (for "Connection IDentifier ”) or CONNECTIONJD.
- the QUIC specification defines two types of CID: Destination CID and Source CID.
- the QUIC protocol supports a connection migration mechanism which makes it possible to maintain an active QUIC connection in the event of modification of one of the addresses (or port numbers) of the equipment participating in the establishment and maintenance of the QUIC connection (including THE address changes made by NATs (for “Network Address Translation” in English) placed on a path taken by the data exchanged under a QUIC connection).
- a connection migration consists of moving from a transport identifier defined by a quadruplet ⁇ source address, source port, destination address, destination port ⁇ to another.
- a communication path is identified by a transport identifier defined by a quadruplet ⁇ source address, source port, destination address, destination port ⁇ .
- Modifying at least one parameter of this quadruple gives rise to a new communication path. It should be noted, however, that this definition does not require that the corresponding "physical" paths be in whole or in part disjoint (in other words, the modification of said at least one parameter does not mean that the physical paths are- i.e. the routes taken by the data differ).
- the equipment participating in the establishment and maintenance of the QUIC connection can validate a new address used for example by the QUIC equipment at the origin of the establishment of the connection using the frames PATH_CHALLENGE and PATH_RESPONSE exchanged between these devices to validate a connection migration. The same connection migration procedure is implemented in the event of announcement of a new address by the remote device.
- a first solution to try to limit the tracking of communications in the event of connection migration is based on the use of new connection identifiers for communications established on other paths, within the same QUIC connection.
- MAC addresses are identifiers assigned to network interfaces for communication needs. These identifiers are generally assigned by network card manufacturers. A MAC address is often considered unique and permanent (i.e. not modified over time), which makes it possible to track and identify equipment such as a terminal, even when it is in motion. . There is therefore a need for a new solution to improve the confidentiality of communications.
- the invention proposes a solution in the form of a method for managing communications of a first piece of equipment, implemented by a remote server, comprising: establishing a first secure connection between said first piece of equipment and said remote server , via a first communication interface of said first equipment, the transmission, using said first secure connection, of an instruction for managing at least one current MAC address associated with at least a second communication interface of the first equipment.
- the first and second communication interface of the first equipment can be the same interface or distinct interfaces.
- the first equipment is a terminal (fixed or mobile, such as a computer, a smartphone, etc.) comprising one or more communication interfaces, for example a WLAN (Wireless LAN) interface, an Ethernet interface, etc.
- WLAN Wireless LAN
- the first equipment and the remote server can be connected to the same network, for example an access network, or to separate networks.
- the first equipment is connected to a local network, such as a home network or a corporate intranet network.
- a network may possibly be a hierarchical network, that is to say a network within which one or more IP routers have been deployed.
- the first equipment can be connected to the remote server via an access router.
- the remote server may in particular be connected to the access network to which the terminal connects or to another network.
- IP connectivity can be provided via a wired network, or wireless (e.g. 5G), or both.
- the server can trigger a procedure for managing the current MAC address, by sending to the first equipment an instruction for managing this current MAC address.
- a management instruction belongs to the group comprising: a request for renewal of said at least one current MAC address, a request for extension of the period of validity of said at least one current MAC address.
- the proposed solution thus makes it possible, according to at least one embodiment, to avoid the tracking of communications thanks to the management of MAC addresses (for example, to the renewal of the address current MAC or the extension of its validity period), and consequently to contribute to the preservation of the confidentiality of data exchanged by users of such equipment or data characteristic of these users.
- Such a MAC address management procedure initiated by the server is for example called ADET procedure for “ADvancEd anti-Tracking system”.
- an extension of the validity period of said at least one current MAC address may prove more effective in certain situations and/or for certain services, or in anticipation of a possible renewal request. This makes it possible in particular to make the procedure more robust (for example by preventing the simultaneous renewal of the MAC addresses of all the active interfaces of a piece of equipment).
- this instruction for managing the current MAC address is transmitted using a secure connection, which makes it possible to improve the security of exchanges between the first equipment and the remote server.
- the first secure connection is based on a secure communication protocol, such as the QUIC protocol, MP-QUIC (“Multipath QUIC”), or the CoAP protocol (in English “Constrained Application Protocol”) when used in conjunction with the DTLS protocol (in English “Datagram Transport Layer Security”), etc.
- a secure communication protocol such as the QUIC protocol, MP-QUIC (“Multipath QUIC”), or the CoAP protocol (in English “Constrained Application Protocol”) when used in conjunction with the DTLS protocol (in English “Datagram Transport Layer Security”), etc.
- connection migration can be replaced by a function of adding / removing communication paths between the server and the first device.
- the proposed solution thus offers the advantage of using functions supported by a secure communication protocol.
- MAC_RENEW a request for renewal of at least one current MAC address is for example transmitted in a QUIC frame called here “MAC_RENEW”.
- a communication being established on a first communication path between the first equipment and the remote server and using said at least one current MAC address the instruction for managing said at least one current MAC address is transmitted following the detection of an event relating to said communication belonging to the group comprising: a duration of use of said at least one current MAC address, a duration of validity of said at least one current MAC address, or in other words a deadline for renewing said at least one current MAC address, detecting migration of the communication established on the first communication path towards at least a second communication path.
- the remote server can thus trigger the procedure for managing the current MAC address upon detection of an event relating to a communication using at least one current MAC address associated with an interface of the first equipment.
- the remote server can detect a long-term communication using said at least one current MAC address associated with at least a second interface of the first equipment, and ask the first equipment to renew the current MAC address(es) concerned.
- the remote server can thus control the lifespan of a MAC address used by a client.
- the MAC address renewal request can also be transmitted to the first device prior to migration.
- a QUIC notification can be sent by the remote server to the first device to inform it of the upcoming migration.
- Such communication can be established between the first equipment and the server, or the first equipment and a second equipment connected to the same network as the first equipment or to a separate network.
- a communication being established on a first communication path between the first equipment and the remote server and using said at least one current MAC address said remote server delays the transmission of data on the first path for a duration defined (for example of the order of a few milliseconds or a few seconds) or as long as the remote server has not received confirmation of association of at least one new MAC address to said at least one second interface of said first equipment for continue communication on the first communication path.
- Said defined duration may be configurable.
- the remote server does not use the first communication path during the renewal of at least one MAC address associated with at least one interface of the first equipment, and observes a time delay (hereinafter called “period of "pause") while storing for example data in a buffer.
- period of a time delay
- no useful data is transmitted during a given period, for example of the order of 100 ms.
- said remote server transmits data on at least a second path between the first equipment and the remote server for a defined duration (for example of the order of a few milliseconds or a few seconds, this duration being configurable) or as long as said remote server has not received association confirmation from at least one new MAC address to said at least one second interface of said first equipment to continue communication on the first communication path.
- the remote server does not use the first communication path during the renewal of at least one MAC address associated with at least one interface of the first equipment, and transmits the data on at least a second communication path (alternative path).
- the useful data can be transmitted on another available path during a given period, for example of the order of ls.
- the remote server can in particular send to the first equipment a request to extend the validity period of the MAC address associated with an interface of the first equipment used for communications with the remote server on the second path , so as to ensure that this MAC address is not modified for the defined period or as long as the remote server has not received confirmation of association of a new MAC address with the interface of the first equipment and used for communications with the server on the first path.
- the instruction for managing at least one current MAC address comprises at least one element belonging to the group comprising: one or more interface identifiers (making it possible to identify the interface(s) of the first equipment which must be associated with a new MAC address), one or more network path identifiers (making it possible to identify the current and/or previously used communication path(s) between said first equipment and the remote server).
- identifiers may be an address, an address identifier, etc. etc.
- the invention also relates to a method of communication between a first piece of equipment and a remote server, implemented by said first piece of equipment, comprising: establishing a first secure connection between said first piece of equipment and said remote server, via a first interface communication of said first equipment, receiving, using said first secure connection, an instruction for managing at least one current MAC address associated with at least one second communication interface of said first equipment, executing said instruction of management.
- the management of at least one MAC address of the first equipment is implemented upon request from the remote server.
- the server can thus trigger a procedure for managing at least one current MAC address associated with at least one interface of the first equipment, for example following the detection of an event relating to a communication using this address Current MAC.
- the proposed solution makes it possible in particular, according to at least one embodiment, to avoid the tracking of communications thanks to the management of MAC addresses, and consequently to contribute to the preservation of the confidentiality of data exchanged by users of such equipment or characteristic data of these users.
- the execution of said management instruction comprises the association of at least one new MAC address to said at least one second interface.
- At least one current MAC address can be renewed and replaced by a new MAC address.
- said at least one new MAC address is chosen so as not to be able to be correlated to said at least one current MAC address.
- the proposed solution thus offers a solution to help preserve the confidentiality of communications by avoiding exposing information which makes it possible to deduce that it is a migration of a communication established on a first communication path to a communication established on at least a second communication path.
- the association of at least one new MAC address with said at least one second interface implements a classic MAC address renewal technique, for example a random generation technique for MAC addresses ("randomization").
- association of at least one new MAC address with said at least one second interface implements a new technique called here MUSC (in English “Efficient MAC address Update for Service Continuity”), such as described in French patent application FR2205880 filed on 06/16/2022.
- MUSC in English “Efficient MAC address Update for Service Continuity”
- such a procedure can be implemented when said at least one current MAC address is used to communicate with or via at least one second piece of equipment located on a communication path between said first piece of equipment and said remote server, or an intermediate piece of equipment located on a communication path between said first equipment and said second equipment.
- such second equipment may be an access router which makes it possible to connect said first equipment to the remote server.
- the intermediate equipment may be another router located on the path between the first equipment and the second equipment.
- the first equipment implements: the establishment of a second secure connection between said first equipment and said second equipment, via a third communication interface of said first equipment, the transmission, using said second secure connection, of a message comprising at least one encrypted MAC address, associated or capable of being associated with said third interface and used to communicate with or via said second equipment or said intermediate equipment.
- first, second and third communication interface of the first equipment can be the same interface or distinct interfaces.
- the first equipment can declare to the second equipment the current MAC address which it uses to communicate with or via the second equipment, or at least one candidate MAC address which it wishes to use. to communicate with or via the second device.
- the encryption of at least one MAC address makes it possible to reinforce the confidentiality of the transmitted information.
- this embodiment makes it possible to communicate this or these MAC addresses to the second equipment when it is not directly connected to the first equipment (case of a hierarchical network for example).
- recipient equipment of said message to compare the source MAC address of the message (which can be transported in plain text in the message header) with the encrypted MAC address as declared in the message, to detect possible fraudulent manipulation of MAC addresses.
- the proposed solution thus makes it possible, according to at least one embodiment, to contribute to the preservation of the confidentiality of communications.
- the second secure connection relies on a secure communication protocol, such as QUIC protocol, CoAP protocol over DTLS, etc.
- a secure communication protocol such as QUIC protocol, CoAP protocol over DTLS, etc.
- the proposed solution thus offers the advantage of using functions supported by a secure communication protocol, and is not simply based on the use of MAC addresses.
- the use of a secure channel and the encryption of MAC addresses makes it possible in particular to obtain network access authorization on the basis of the MAC address even if access control is activated by equipment which is not not on the same link (i.e. located several IP hops away).
- the message corresponds for example to at least one frame belonging to the group comprising: a frame which describes the current MAC address that the first equipment uses to communicate with or via the second equipment, for example a QUIC frame called here "CURRENT_MAC_ADDRESS", a frame which describes a candidate MAC address that the first equipment plans to use to communicate with or via the second equipment, for example a QUIC frame called here “CANDIDATE_MAC_ADDRESS”, a frame which describes a list of MAC addresses that the first equipment plans to use to communicate with or via the second equipment, for example a QUIC frame called here “LIST_MAC_ADDRESS”.
- a frame which describes the current MAC address that the first equipment uses to communicate with or via the second equipment for example a QUIC frame called here "CURRENT_MAC_ADDRESS”
- a frame which describes a candidate MAC address that the first equipment plans to use to communicate with or via the second equipment for example a QUIC frame called here “CANDIDATE_MAC_ADDRES
- the proposed solution makes it possible in particular to offer continuity of service, even in the event of MAC address renewal.
- the proposed solution does not require explicit authentication or establishment of a security association between the first equipment (terminal for example) and the second equipment (access router for example) for each exchange of packets with equipment external to the network.
- the first equipment and the server can exchange messages to confirm that they are capable of implementing the invention, according to at least one embodiment.
- the exchange of such parameters can be implemented before the transmission, by the server, of the MAC address management instruction.
- the invention relates to a first equipment and a corresponding remote server.
- One embodiment of the invention also aims to protect one or more computer programs comprising instructions adapted to the implementation of at least one step of the methods according to at least one embodiment of the invention as described above, when this or these programs are executed by a processor, as well as at least one computer-readable information medium comprising instructions for at least one computer program as mentioned above.
- Figure 1 presents an example of network architecture
- Figure 2 illustrates the main steps implemented by a first piece of equipment and a remote server according to at least one embodiment of the invention
- Figure 3 illustrates the exchange of parameters to check the compatibility of the first equipment and the remote server according to one embodiment of the invention
- Figure 4 illustrates an example of network architecture implementing a MUSC procedure on one of the communication paths between the first equipment and the remote server
- Figure 5 shows examples of messages exchanged between a first piece of equipment, a first access router and a remote server when the MUSC procedure is implemented following receipt of a management instruction from the remote server
- Figure 6 illustrates an example of network architecture implementing a MUSC procedure on each of the available communication paths following receipt of a management instruction from the remote server
- Figure 7 presents examples of messages exchanged between the first equipment, the first access router, and the remote server, and between the first
- the general principle of the invention is based on the management, by a remote server, of at least one current MAC address associated with at least one communication interface of a first piece of equipment, so as to limit the risks of tracking the first piece of equipment. and thus contribute to the preservation of the confidentiality of communications.
- the first equipment and the remote server can be connected to the same network, for example to an access network, or to separate networks.
- the first equipment H 11 is a multi-interface terminal, which can use the same interface or distinct interfaces to connect to one or more access networks.
- the first equipment is connected to at least one access network, for example to a first access network NET. #1 121 and a second NET access network. #2 122.
- the remote server S 13 can be connected to an external network, for example the network of an operator with which the user of the first equipment has subscribed to an Internet service offer 131 (ISP, “Internet Service Provider” in English) or to another network managed by a third party, or directly to NET access networks.
- ISP Internet Service Provider
- the first equipment 11 can communicate with the remote server 13 via the first access router RI 1211 of the first access network NET. #1 121 and/or via a second access router R2 1221 of the second access network NET. #2,122.
- the first equipment 11 conventionally uses the same MAC address (for example @MAC1) to communicate with the server 13, whatever the communication path used (first communication path via of the first access router 1211 or second communication path via the second access router 1221), particularly when the same interface is used to connect to these access networks.
- the same MAC address is exposed on the different communication paths, and the communications established on these different paths can be correlated. Malicious equipment can therefore easily trace the communications emanating from the first equipment 11, even in the event of a change in the access network to which the first equipment connects.
- the proposed solution makes it possible to manage at least one MAC address associated with at least one interface of the first equipment 11, for example by modifying this MAC address in the event of migration of the communication from a first communication path to at least a second communication path.
- the same procedure can also be used in the event of maintaining communication on several communication paths (that is to say during simultaneous use of the resources associated with the different paths in the absence of migration of the communication). It is also possible to control the duration of use of a MAC address, for example depending on the service invoked, or to extend its validity period.
- Figure 2 illustrates the main steps implemented by a remote server and by a first piece of equipment, for example the server 13 and the first piece of equipment 11 of Figure 1, for the implementation of the methods according to at least one embodiment of the invention.
- a first secure connection between the first equipment and the remote server is established, via a first communication interface of the first equipment.
- the establishment of such a secure connection being classic, it is not described in more detail here.
- the server 13 can then transmit (22) to the first equipment 11, using the first secure connection, an instruction for managing at least one current MAC address associated with at least one second communication interface of the first equipment (the first and second communication interfaces which can be the same interface or distinct interfaces).
- Such a management instruction is for example of the type request for renewal of the current MAC address or request for extension of the validity period of the current MAC address.
- the server can trigger the sending of a management instruction for at least one MAC address when the duration of use of the current MAC address is greater than a defined duration, when a validity period of the the current MAC address is reached (corresponding to a deadline for the renewal of the current MAC address) and/or following the migration of a communication established on a first communication path towards at least a second communication path, etc.
- the first equipment 11 can thus receive (23) the management instruction of at least one current MAC address associated with at least one second communication interface of the first equipment, using the first secure connection.
- the first equipment can then execute (24) the corresponding management instruction, for example renewing the current MAC address @MAC1 and associate at least one new MAC address @MAC2 with the relevant interface of the first equipment.
- the first equipment can implement a classic procedure for associating at least one MAC address with at least one of its interfaces.
- the first equipment can implement a new procedure for associating at least one MAC address with at least one of its interfaces, called the MUSC procedure, as described in the patent application French FR2205880 cited above.
- Such a MUSC procedure can in particular be implemented between the first equipment and a second equipment located on a communication path between the first equipment and the server, for example the first access router 1211 and/or the second access router 1221 of Figure 1.
- the first secure connection between the server and the first equipment uses the QUIC protocol.
- the first secure connection may use the CoAP over DTLS protocol or any other protocol allowing the establishment of a secure connection.
- the proposed solution can also be applied to QUIC communications established over several paths by exploiting MP-QUIC resources. The exploitation of all or part of these different paths may be the subject of negotiation between the server and the first equipment.
- the first equipment can use a new QUIC transport parameter (as provided in section 7.4.2 of document RFC 9000, May 2021), called here “mac-update”, to signal to the server that it supports the MAC address management procedure initialized by the server (ADET procedure).
- the first equipment 11 implements the transmission 31 of a first parameter signaling to the server 13 that the first equipment 11 is able to modify its current MAC address or to extend its validity period, using the first secure connection.
- the server also supports ADET, it can respond using the new QUIC transport parameter "mac-update", also using the first secure connection.
- the server 13 implements the transmission 32 of a second parameter signaling to the first equipment 11 that the server 13 is capable of managing at least one MAC address associated with at least one interface of the first equipment.
- the server can then transmit to the first equipment a MAC address management instruction, for example a request to renew at least one of its current MAC addresses in a QUIC frame called here “MAC_RENEW” 33.
- Figure 4 illustrates an example of network architecture, according to which the first equipment 11 can communicate with the remote server 13 via the first access router RI 1211 of the first access network NET. #1,121.
- Figure 5 illustrates examples of messages exchanged between the first equipment 11, the first access router 1211 and the server 13 when the MUSC procedure is implemented following receipt of a management instruction from the remote server.
- a secure QUIC Connect connection. #1 is established between the first equipment 11 and the server 13.
- the secure QUIC Connect connection #1 established between the first equipment 11 and the server 13 via the first access router 1211 is characterized by connection identifiers CID (notably source CID).
- QUIC “mac-update” transport parameters can be exchanged between the first equipment 11 and the server 13 to verify that they support the MAC address management procedure (ADET procedure) according to a embodiment of the invention.
- Data D can in particular be exchanged between the first equipment 11 and the server 13 via the secure QUIC Connect connection. #1, through the first communication path via the first access router 1211.
- the server 13 detects that the first equipment 11 has established a long-term communication (for example of duration greater than a given threshold recommended for the current service) with a second equipment located on the first communication path (for example with the server 13 or with the first access router 1211), using a current MAC address @MAC1 associated with a communication interface of the first equipment to communicate with or via the second equipment.
- a long-term communication for example of duration greater than a given threshold recommended for the current service
- the server 13 can then trigger the MAC address management procedure so as to prevent the first equipment from permanently establishing communications based on the use of the same MAC address.
- the server 13 can send a request for renewal of the address @MAC1 used by the first equipment 11, so that the MAC address used for the transmission of packets on the first path is modified.
- the server 13 can for example send a MAC_RENEW frame to the first equipment 11 via the secure QUIC Connect connection. #1, and a MAC address negotiation cycle can then be triggered.
- a MUSC procedure can in particular be implemented between the first equipment 11 and the second equipment, to associate a new MAC address with the interface used by the first equipment to communicate with or via the second equipment.
- the second equipment is the first access router 1211.
- a secure QUIC Connect connection. #2 (2) is established between the first equipment 11 and the first access router 1211.
- a secure connection uses the QUIC protocol, the CoAP protocol over DTLS, etc.
- the first equipment 11 can then transmit a message to the first access router 1211, using the secure QUIC Connect connection. #2.
- a message includes at least one encrypted MAC address, associated or able to be associated with the interface considered of the first equipment, and used to communicate with or via the first access router 1211 or an intermediate equipment located on a communication path between the first equipment and the first access router 1211.
- the first access router 1211 can thus receive such a message, and validate the MAC address(es) received.
- Different types of messages can be sent from the first equipment 11 to the first access router 1211.
- the first equipment 11 can generate at least one new MAC address @MAC 2 and transmit this new address @MAC 2 encrypted in a message using the secure QUIC Connect connection. #2.
- the first access router 1211 can then validate the new @MAC 2 address and, if necessary, update the filtering rules that it maintains.
- the new address @MAC 2 becomes the current MAC address associated with the interface considered.
- a message corresponding to at least one QUIC frame which describes the current MAC address that the first equipment uses to communicate with or via the first access router 1211, called for example here "CURRENT_MAC_ADDRESS" can then be transmitted from the first equipment 11 to the first access router 1211.
- the insertion of the current MAC address in the new frame, and therefore its encryption linked to the use of the secure QUIC connection, allows the first access router 1211 to compare information transported in the encrypted part of the message (for example example the current MAC address) with information conveyed in clear in the QUIC connection (for example the source MAC address) and to detect possible manipulation of the information conveyed in clear.
- information transported in the encrypted part of the message for example example the current MAC address
- information conveyed in clear in the QUIC connection for example the source MAC address
- Inserting the current MAC address into the new frame also makes it possible to communicate the current MAC address to the first access router 1211 even if it is not directly connected to the first equipment (case of intermediate equipment of router type for example).
- the first equipment 11 can then use the address @MAC2 to communicate with the server 13 using the first secure QUIC Connect connection. #1 (53), via the first access router 1211.
- QUIC “mac-update” transport parameters can be exchanged between the first equipment 11 and the first access router 1211 to verify that they support the MUSC procedure according to one embodiment of the invention.
- the first device uses the new QUIC transport parameter “mac-update” to signal to the first access router 1211 that it supports the MUSC procedure. If the first access router 1211 also supports the MUSC procedure, it can respond using the new QUIC transport parameter “mac-update”.
- Figure 6 illustrates an example of network architecture, according to which the first equipment 11 can communicate with the remote server 13 via the first access router RI 1211 of the first access network NET. #1 121 and/or via the second access router R2 1221 of the second access network NET. #2,122.
- Figure 7 illustrates examples of messages exchanged between the first equipment 11, the first access router 1211 and the server 13, and between the first equipment 11, the second access router 1221 and the server 13, when the MUSC procedure is implemented for each of the communication paths between the first equipment and the remote server available following receipt of a management instruction from the remote server.
- a MUSC procedure can be implemented between the first equipment 11 and a second equipment located on a communication path between the first equipment 11 and the server 13.
- a first MUSC procedure can be implemented between the first equipment 11 and the first access router 1211
- a second MUSC procedure can be implemented between the first equipment 11 and the second access router 1221.
- MUSC procedures as there are communication paths between the first equipment 11 and the server 13 can be implemented.
- the first MUSC procedure implements the following steps.
- a secure QUIC Connect connection. #1 (71) is established between the first equipment 11 and the first access router 1211.
- a secure connection uses the QUIC protocol, or alternatively the CoAP protocol over DTLS, etc.
- QUIC “mac-update” transport parameters can possibly be exchanged between the first equipment 11 and the first access router 1211 to verify that they support the MUSC procedure according to one embodiment of the invention.
- the first equipment 11 can then transmit a message to the first access router 1211, using the secure QUIC Connect connection. #1.
- a message comprises at least one encrypted MAC address, associated or capable of being associated with the interface considered of the first equipment, and used to communicate with or via the first router of access 1211 or intermediate equipment located on a communication path between the first equipment and the first access router 1211.
- the first access router 1211 can thus receive such a message, and validate the MAC address(es) received.
- Different types of messages can be sent from the first equipment 11 to the first access router 1211.
- the message corresponds to a QUIC frame “CURRENT_MAC_ADDRESS” which describes the current MAC address that the first equipment uses to communicate with or via the first access router 121.
- CURRENT_MAC_ADDRESS Such a current MAC address is therefore now and already assigned to the interface used to contact the first access router 1211.
- the first equipment 11 can prepare the migration of MAC addresses by previously indicating to the first access router 1211 at least one MAC address that it plans to use, called a candidate MAC address.
- the message sent from the first equipment 11 to the first access router 1211, via the secure QUIC Connect connection. #1 corresponds to a QUIC frame, called for example here “LIST_MAC_ADDRESSES”, comprising at least one encrypted candidate MAC address that the first equipment plans to use to communicate with or via the first access router 1211 (for example a5: c7:ef:82:58:e9, el:44:5c:32:3c:72, ee:3c:50:18:7e:44).
- LIST_MAC_ADDRESSES a QUIC frame, called for example here “LIST_MAC_ADDRESSES”
- the first equipment 11 can check with the first access router 1211 that the candidate MAC address is available. This makes it possible in particular to avoid a conflict with the MAC addresses used by other equipment connected to the same network and avoids impacting the service access delay induced by a change of MAC address.
- the message sent by the first equipment 11 to the first router access 1211, via the secure connection QUIC Connect #1 corresponds to a QUIC frame, called for example here “CANDIDATE_MAC_ADDRESS”, comprising at least one encrypted candidate address.
- the first equipment implements a MUSC procedure to associate a MAC address with at least one of its interfaces and validate this MAC address.
- the first device can use a default MAC address, configured for example by a user of the first device or by the operating system.
- the first equipment 11 transmits to the first access router 1211 a message corresponding to a QUIC frame “CURRENT_MAC_ADDRESS” bearing the address @MAC1.
- a secure QUIC Connect connection. #2 (72) is also established between the first equipment 11 and the server 13 (before, during or after the establishment of the secure QUIC Connect connection. #1). Multiple login credentials can be used.
- the secure connection QUIC Connect #2 established between the first equipment 11 and the server 13 via the first access router 1211 is characterized by first (resp. second) identifiers of connection, in particular source CID, negotiated beforehand (Section 19.15 of RFC 9000) with the server 13.
- first (resp. second) identifiers of connection in particular source CID, negotiated beforehand (Section 19.15 of RFC 9000) with the server 13.
- QUIC “mac-update” transport parameters can be exchanged between the first equipment 11 and the server 13 to verify that they support the MAC address management procedure (ADET) according to a mode of carrying out the invention.
- ADAT MAC address management procedure
- Data D can in particular be exchanged between the first equipment 11 and the server 13 via the secure QUIC Connect connection. #2, by the first communication path via the first access router 1211.
- the server 13 detects the use of a new transport identifier (for example a new source IP address when the data packets coming from the first equipment 11 and destined for the server 13 arrive via at least a new path or when attempting to migrate a connection). For example, the server 13 detects that it is receiving data packets from different source addresses.
- the server 13 can trigger the MAC address management procedure according to one embodiment of the invention, so as to prevent the first equipment from always using the current MAC address @MAC1 to communicate with or via the second access router 1221.
- a MUSC procedure can in particular be implemented between the first equipment 11 and the second access router 1221, to associate a new MAC address with the interface used by the first equipment to communicate with or via the second access router 1221 .
- a secure QUIC Connect connection. #3 (73) is established between the first equipment 11 and the second access router 1221.
- a secure connection uses the QUIC protocol, or alternatively the CoAP protocol over DTLS, etc.
- the first equipment 11 can then use the @MAC2 address to communicate with the server 13 using the secure QUIC Connect connection. #2 (74), via the second access router 1221.
- a new login ID can be used during migration. This identifier can be exchanged beforehand according to the procedure described in Section 19.15 of RFC 9000.
- the secure QUIC Connect connection. #2 is therefore established on the two paths via the first access router 1211 and via the second access router 1221, and one and/or the other of the paths can be used to exchange data between the first equipment 11 and server 13.
- the remote server can, as a variant or in addition, send a request to extend the validity period of at least one current MAC address, for example the @MAC1 address used for communications on the first path.
- the @MAC1 address can thus be kept for communications via the first access router 1211, and the @MAC2 address can be used for communications via the second access router 1221.
- the MAC addresses used on alternative paths are not communicated to access routers located on other paths.
- the proposed solution thus makes it possible to negotiate different MAC addresses for the first equipment 11, depending on the access network to which it is attached, even if the same interface of the first equipment 11 would be used for communications with the different access networks.
- the first equipment 11 can communicate with the first access router 1211 via a first interface of the first equipment 11 using the MAC address @MAC1, and the first equipment 11 can communicate with the second access router 1221 via the first interface of the first equipment 11 using the MAC address @MAC2.
- the new MAC address(es) are chosen so as not to be able to be correlated with the current MAC address(es), so as to prevent the traceability of the first equipment.
- the first equipment uses a new MAC address which cannot be correlated with a MAC address previously used, for example during the last 24 hours.
- the first equipment 11 can in particular confirm the renewal of its MAC address, by transmitting a message via the secure connection established with the server 13 (QUIC Connect #1 according to Figure 5 or QUIC Connect #2 according to Figure 7).
- a message transmitted from the first equipment to the server is named here “MAC_RENEWED” and includes the new MAC address associated with the interface considered of the first equipment 11.
- a communication using the current MAC address @MAC1 being established on the first communication path via the first access router 1211 the remote server 13 delays the transmission of data on the first path for a period of time. defined duration or as long as the remote server has not received confirmation of association of at least one new MAC address to the first device to continue communication on the first path (for example as long as the remote server has not received MAC_RENEWED message).
- the server 13 can observe a "pause" period during the renewal of the MAC address of the first equipment 11 and associated with the first path, to avoid, or at the very least reduce, the risk of loss of packets while the MAC address is being modified by the first equipment 11 according to the indications received from the server 13.
- the server 13 does not send useful data on the first path for a short configurable duration, for example of the order of 100 ms.
- a communication using the current MAC address @MAC1 being established on the first communication path via the first access router 1211 the remote server 13 transmits data on at least one other path during a defined duration or as long as the remote server has not received association confirmation from at least one new MAC address to the first device to continue communication on the first path (for example until the remote server has received a MAC_RENEWED message).
- the server 13 can use another path during the renewal of the MAC address of the first equipment 11 associated with the first path, to avoid, or at least reduce, the risk of packet loss while the MAC address is being modified by the first equipment 11 according to the indications received from the server 13.
- the server 13 sends the useful data on at least one other available path (for example the second path via the second router access) for a short configurable duration, for example of the order of Is. It can also send duplicate data via the first path and at least one other available path, so as to ensure that the first equipment receives the useful data.
- the server can send a request to extend the validity period of the MAC address @MAC2 used for communications on the second path during the renewal of the MAC address @MAC1 used for communications on the first path.
- the first equipment can refuse the implementation of the ADET procedure, in particular if a similar management instruction has already been received (for example the same instruction has been received several times, an instruction similar management instruction has been received from another server, etc.) or conflicts with a previously received management instruction.
- a new error message can be transmitted by the first device to the server, for example by using a new QUIC frame called here “REJECT_MAC_RENEW”.
- the server 13 initiates the renewal of at least one MAC address of the first equipment. It is therefore the server which sends a QUIC “MAC_RENEW” frame to the first device. However, we consider that the first device cannot send a QUIC “MAC_RENEW” frame to the server. In other words, the first device does not initiate the renewal of at least one MAC address associated with one of its interfaces. If a “MAC_RENEW” type message is received by the server, the server can ignore it.
- a MUSC procedure for the association of MAC addresses on the interfaces of the first equipment for all of the paths available between the first equipment and the server.
- a procedure can be implemented on certain paths only.
- such a procedure can be implemented upon receipt of a MAC address renewal request sent by the remote server (reception of a QUIC MAC_RENEW frame by the first equipment).
- a new MAC address can be generated in a conventional manner for at least one interface of the first equipment or a path.
- the first equipment locally implements a procedure for generating MAC addresses which cannot be correlated with the MAC addresses used in the past (for example during the last 24 hours).
- the random generation of MAC addresses is implemented locally by the first equipment.
- the server may in particular ask the first equipment to extend the validity of at least one MAC address associated with at least one of its interfaces (which may be the one for which the address renewal is carried out or another interface, particularly in the event of short-term communication).
- the first equipment H (resp. the server S), according to one embodiment of the invention, comprises a memory 81 H (resp. 81s), a processing unit 82 H (resp. 82s), equipped for example with a programmable calculation machine or a dedicated calculation machine, for example a processor P, and controlled by the computer program 83 H (resp. 83s), implementing steps of the communication process (resp. of the process communications management) according to at least one embodiment of the invention.
- a memory 81 H resp. 81s
- a processing unit 82 H equipped for example with a programmable calculation machine or a dedicated calculation machine, for example a processor P
- the computer program 83 H resp. 83s
- the code instructions of the computer program 83 H are for example loaded into a RAM memory before being executed by the processor of the processing unit 82 H (respectively 82s).
- the processor of the processing unit 82 H of the first equipment implements steps of the communication method described above, according to the instructions of the computer program 83 H , to: establish a first secure connection between a first equipment and said server remote, via a first communication interface of said first equipment, transmit, using said first secure connection, an instruction for managing at least one current MAC address associated with at least a second communication interface of the first equipment.
- the processor of the processing unit 82s of the server implements steps of the communications management method described above, according to the instructions of the computer program 83s, to: establish a first secure connection between said first equipment and a remote server , via a first communication interface of said first equipment, receive, using said first secure connection, a management instruction for at least one current MAC address associated with at least one second communication interface of said first equipment, execute said management instruction.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- Bioethics (AREA)
- Computer Hardware Design (AREA)
- General Health & Medical Sciences (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- Small-Scale Networks (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Telephonic Communication Services (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR2205883A FR3136922A1 (fr) | 2022-06-16 | 2022-06-16 | Procédé de communication entre un premier équipement et un serveur distant, procédé de gestion des communications, premier équipement, serveur distant et programme d’ordinateur correspondants. |
| PCT/EP2023/066058 WO2023242318A1 (fr) | 2022-06-16 | 2023-06-15 | Procédé de communication entre un premier équipement et un serveur distant, procédé de gestion des communications, premier équipement, serveur distant et programme d'ordinateur correspondants. |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4541048A1 true EP4541048A1 (fr) | 2025-04-23 |
Family
ID=83505830
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP23732931.3A Pending EP4541048A1 (fr) | 2022-06-16 | 2023-06-15 | Procédé de communication entre un premier équipement et un serveur distant, procédé de gestion des communications, premier équipement, serveur distant et programme d'ordinateur correspondants |
Country Status (4)
| Country | Link |
|---|---|
| EP (1) | EP4541048A1 (fr) |
| CN (1) | CN119605206A (fr) |
| FR (1) | FR3136922A1 (fr) |
| WO (1) | WO2023242318A1 (fr) |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| FR2205880A5 (fr) | 1972-11-09 | 1974-05-31 | Coflexip | |
| CN104754560B (zh) * | 2013-12-30 | 2018-11-30 | 华为终端(东莞)有限公司 | 一种位置隐私保护方法、装置及系统 |
| JP6407598B2 (ja) * | 2014-07-18 | 2018-10-17 | セイコーソリューションズ株式会社 | 中継装置、中継方法、及び中継プログラム |
-
2022
- 2022-06-16 FR FR2205883A patent/FR3136922A1/fr not_active Withdrawn
-
2023
- 2023-06-15 EP EP23732931.3A patent/EP4541048A1/fr active Pending
- 2023-06-15 CN CN202380058893.2A patent/CN119605206A/zh active Pending
- 2023-06-15 WO PCT/EP2023/066058 patent/WO2023242318A1/fr not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| WO2023242318A1 (fr) | 2023-12-21 |
| CN119605206A (zh) | 2025-03-11 |
| FR3136922A1 (fr) | 2023-12-22 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3476095B1 (fr) | Procédé de communication udp via des chemins multiples entre deux terminaux | |
| FR3067550A1 (fr) | Procede de communication quic via des chemins multiples | |
| EP3739843A1 (fr) | Procédé de communication udp via des chemins multiples entre deux terminaux | |
| EP3556130B1 (fr) | Procédé de surveillance d'un réseau de télécommunications mis en oeuvre par un point d'accès | |
| WO2011151573A1 (fr) | Procede et dispositifs de communications securisees dans un reseau de telecommunications | |
| FR3096533A1 (fr) | Procédé de gestion d’une communication entre terminaux dans un réseau de communication, et dispositifs pour la mise en œuvre du procédé | |
| EP3643044A1 (fr) | Procédé d'activation de traitements appliqués à une session de données | |
| CA3087762A1 (fr) | Procede de configuration d'un systeme d'extension de couverture de communication sans-fil et un systeme d'extension de couverture de communication sans-fil mettant en oeuvre ledit procede | |
| FR3072238B1 (fr) | Dispositif et procede de transmission de donnees | |
| FR3096530A1 (fr) | Procédé de gestion d’au moins une communication d’un équipement terminal dans un réseau de communication, procédés de traitement, dispositifs, équipement terminal, équipement proxy et programmes d’ordinateur correspondants | |
| EP1142269B1 (fr) | Procede d'adressage et serveur de noms et d'adresses dans un reseau numerique | |
| EP3788762B1 (fr) | Procédé d'envoi d'une information et de réception d'une information pour la gestion de réputation d'une ressource ip | |
| WO2023242318A1 (fr) | Procédé de communication entre un premier équipement et un serveur distant, procédé de gestion des communications, premier équipement, serveur distant et programme d'ordinateur correspondants. | |
| FR2863798A1 (fr) | Procede et systeme de diffusion multicast vers un terminal nomade en fonction de la localisation. | |
| EP3235217B1 (fr) | Procédé d'échanges de données entre deux navigateurs internet, équipement de routage, terminal, programme d'ordinateur et support d'informations corespondants | |
| WO2020002853A1 (fr) | Procédés de gestion du trafic associé à un domaine client, serveur, nœud client et programme d'ordinateur correspondants | |
| FR3109255A1 (fr) | Procédé mis en œuvre par une entité intermédiaire pour gérer une communication entre deux dispositifs de communication | |
| FR3143150A1 (fr) | Procédé de gestion d’un ensemble d’adresses IP, procédé de collaboration et dispositifs configurés pour mettre en œuvre ces procédés. | |
| WO2009080971A1 (fr) | Procede de configuration d'un terminal d'utilisateur dans un reseau de telephonie ip | |
| EP4540971A1 (fr) | Procédé de communication entre deux équipements, premier équipement, deuxième équipement et programme d'ordinateur correspondants | |
| FR3157769A1 (fr) | Procédé d’accès à un service par un dispositif de communication via au moins un réseau de communication | |
| FR3154268A1 (fr) | Procédés de vérification, de gestion, de contrôle, d’exécution d’une vérification de l’accessibilité d’un équipement, équipement, serveur de contrôle, contrôleur réseau, entité relais et programme d’ordinateur correspondants. | |
| FR3153206A1 (fr) | Procédés, dispositifs et système de contrôle d’une communication dans un réseau | |
| FR3150670A1 (fr) | Procédés d’accès à un service, procédé de fourniture de services, procédé de contrôle, procédé de gestion, terminal, instance de service, contrôleur, nœud de bordure et programmes d’ordinateur correspondants. | |
| WO2024068722A1 (fr) | Procedes de resolution de nom, de communication, de traitement de messages et serveur, dispositif client et noeud relais correspondants |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20241210 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20260226 |