WO2025201931 - METHOD AND DEVICE FOR DETECTING AND IDENTIFYING CRYPTOGRAPHIC ALGORITHMS IN A COMMUNICATION NETWORK

National phase entry is expected:
Publication Number WO/2025/201931
Publication Date 02.10.2025
International Application No. PCT/EP2025/057151
International Filing Date 17.03.2025
Title **
[English] METHOD AND DEVICE FOR DETECTING AND IDENTIFYING CRYPTOGRAPHIC ALGORITHMS IN A COMMUNICATION NETWORK
[French] PROCÉDÉ ET DISPOSITIF DE DÉTECTION ET D'IDENTIFICATION D'ALGORITHMES CRYPTOGRAPHIQUES DANS UN RÉSEAU DE COMMUNICATION
Applicants **
ORANGE
Inventors
COMBES, Jean-Michel
FERREIRA, Loïc
Priority Data
FR2403153   28.03.2024   FR
Application details
Total Number of Claims/PCT *
Number of Independent Claims *
Number of Priorities *
Number of Multi-Dependent Claims *
Number of Drawings *
Pages for Publication *
Number of Pages with Drawings *
Pages of Specification *
*
Number of Office Actions *
*
International Searching Authority
*
Recordal of a Change of the Applicant's Name/Address
*
Type of Assignment
*
Applicant's Legal Status
*
*
*
*
*
*
Entry into National Phase under
*
Patent Delivery
*
译文

* The data is based on automatic recognition. Please verify and amend if necessary.

** IP-Coster compiles data from publicly available sources. If this data includes your personal information, you can contact us to request its removal.

Quotation for National Phase entry

Country StagesTotal
China Filing, Examination, Granting1909
EPO Filing, Examination, Granting8126
Japan Filing, Examination, Granting2031
South Korea Filing, Examination, Granting1819
USA Filing, Examination, Granting6540
MasterCard Visa
Total: 20,425
Contact Us
Abstract[English] The invention relates to a method for detecting a particular cryptographic algorithm used in a computer system, comprising steps of capturing data packets exchanged with a target machine in order to obtain initial measurements of time and data volume, calculating response delays by measuring the time elapsed between sending and receiving the captured data packets, determining a first time signature indicative of a cryptographic algorithm used to generate the captured packets on the basis of the calculated response delays and the exchanged data volumes, determining a level of correspondence between the first time signature determined and at least one second time signature determined beforehand for a particular cryptographic algorithm, and transmitting an alert comprising at least one identifier of a source apparatus and/or of a destination apparatus of the network flow when the level of correspondence is greater than a threshold.[French] L'invention concerne un procédé de détection d'un algorithme cryptographique particulier utilisé dans un système informatique, comprenant des étapes de capture de paquets de données échangés avec une machine cible pour obtenir des mesures initiales de temps et de volume de données, de calcul de délais de réponse en mesurant le temps écoulé entre l'envoi et la réception des paquets de données capturés, de détermination d'une première signature temporelle indicative d'un algorithme cryptographique utilisé pour générer les paquets capturés à partir des délais de réponse calculés et des volumes de données échangés, de détermination d'un niveau de correspondance entre la première signature temporelle déterminée et au moins une deuxième signature temporelle déterminée au préalable pour un algorithme cryptographique particulier, et de transmission d'une alerte comprenant au moins un identifiant d'un équipement à l'origine et/ou d'un équipement destinataire dudit flux réseau lorsque le niveau de correspondance est supérieur à un seuil.