WO2025201931 - METHOD AND DEVICE FOR DETECTING AND IDENTIFYING CRYPTOGRAPHIC ALGORITHMS IN A COMMUNICATION NETWORK
National phase entry is expected:
Publication Number
WO/2025/201931
Publication Date
02.10.2025
International Application No.
PCT/EP2025/057151
International Filing Date
17.03.2025
Title **
[English]
METHOD AND DEVICE FOR DETECTING AND IDENTIFYING CRYPTOGRAPHIC ALGORITHMS IN A COMMUNICATION NETWORK
[French]
PROCÉDÉ ET DISPOSITIF DE DÉTECTION ET D'IDENTIFICATION D'ALGORITHMES CRYPTOGRAPHIQUES DANS UN RÉSEAU DE COMMUNICATION
Applicants **
ORANGE
Inventors
COMBES, Jean-Michel
FERREIRA, Loïc
Priority Data
FR2403153
28.03.2024
FR
Application details
| Total Number of Claims/PCT | * |
| Number of Independent Claims | * |
| Number of Priorities | * |
| Number of Multi-Dependent Claims | * |
| Number of Drawings | * |
| Pages for Publication | * |
| Number of Pages with Drawings | * |
| Pages of Specification | * |
| * | |
| Number of Office Actions | * |
| * | |
International Searching Authority |
EPO
* |
| Recordal of a Change of the Applicant's Name/Address |
Change of Applicant's Name and Address
* |
| Type of Assignment |
The Standard Agent's Assignment
* |
| Applicant's Legal Status |
Legal Entity
* |
| * | |
| * | |
| * | |
| * | |
| * | |
| Entry into National Phase under |
Chapter I
* |
| Patent Delivery |
Send the Letters Patent by Courier
* |
| Translation |
|
* The data is based on automatic recognition. Please verify and amend if necessary.
** IP-Coster compiles data from publicly available sources. If this data includes your personal information, you can contact us to request its removal.
Quotation for National Phase entry
| Country | Stages | Total | |
|---|---|---|---|
| China | Filing, Examination, Granting | 1907 | |
| EPO | Filing, Examination, Granting | 8143 | |
| Japan | Filing, Examination, Granting | 2056 | |
| South Korea | Filing, Examination, Granting | 1798 | |
| USA | Filing, Examination, Granting | 6540 |

Total:
20,444
Contact Us
Abstract[English]
The invention relates to a method for detecting a particular cryptographic algorithm used in a computer system, comprising steps of capturing data packets exchanged with a target machine in order to obtain initial measurements of time and data volume, calculating response delays by measuring the time elapsed between sending and receiving the captured data packets, determining a first time signature indicative of a cryptographic algorithm used to generate the captured packets on the basis of the calculated response delays and the exchanged data volumes, determining a level of correspondence between the first time signature determined and at least one second time signature determined beforehand for a particular cryptographic algorithm, and transmitting an alert comprising at least one identifier of a source apparatus and/or of a destination apparatus of the network flow when the level of correspondence is greater than a threshold.[French]
L'invention concerne un procédé de détection d'un algorithme cryptographique particulier utilisé dans un système informatique, comprenant des étapes de capture de paquets de données échangés avec une machine cible pour obtenir des mesures initiales de temps et de volume de données, de calcul de délais de réponse en mesurant le temps écoulé entre l'envoi et la réception des paquets de données capturés, de détermination d'une première signature temporelle indicative d'un algorithme cryptographique utilisé pour générer les paquets capturés à partir des délais de réponse calculés et des volumes de données échangés, de détermination d'un niveau de correspondance entre la première signature temporelle déterminée et au moins une deuxième signature temporelle déterminée au préalable pour un algorithme cryptographique particulier, et de transmission d'une alerte comprenant au moins un identifiant d'un équipement à l'origine et/ou d'un équipement destinataire dudit flux réseau lorsque le niveau de correspondance est supérieur à un seuil.