IP Library › Granted Patent US 12,348,500
Granted Patent B2
US 12,348,500 · App. 18/007,963 · Granted Jul 1, 2025

Method for capturing a packet from an encrypted session

Inventors: Imed Allal (Chatillon, FR); Emile Stephan (Chatillon, FR); Gaël Fromentoux (Chatillon, FR); Arnaud Braud (Chatillon, FR)
Assignee: Orange
H04L63/0435H04L47/2475H04L47/35H04L63/0414H04L69/164
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,500
App. No.
18/007,963
Granted
Jul 1, 2025
Kind
B2
Abstract

A method for capturing a packet from an encrypted session established between a terminal unit and a data server. The packet includes a datum for determining a security key used for the encryption of the packet. The method is implemented by a device routing the packet between the terminal unit and the data server and includes: analysis of a plurality of packets transmitted by the terminal unit and destined for the server; identification of a cooperation packet from among the plurality of analyzed packets, the cooperation packet including the determining datum corresponding to a security key used for the encryption of packets transmitted by the terminal unit to the data server prior to the terminal unit sending the cooperation packet; and decryption of the received cooperation packet using a security key corresponding to the determining datum from the identified cooperation packet.

Claims (25)

1. A capturing method for capturing a packet from an encrypted session established between a terminal unit and a data server, said packet comprising a datum for determining a security key used for encrypting the packet, the method being implemented by a device routing the packet between the terminal unit and the data server and comprising:

analyzing the datum for determining the security key of a plurality of received packets transmitted by the terminal unit and destined for the server;

identifying a cooperation packet from among the plurality of transmitted packets, said cooperation packet comprising a value of the determining datum, distinct from a value of the data for determining the security keys of the other packets of the plurality of packets, said value of the determining datum of the cooperation packet corresponding to a security key used for encrypting packets transmitted by the terminal unit to the data server prior to the terminal unit sending said cooperation packet; and

decrypting the cooperation packet using a security key corresponding to the value of the determining datum of the identified cooperation packet.

2. The capturing method as claimed in claim 1 , wherein the determining datum is a binary phase element indicating a key change to be used by the terminal and the data server for encrypting and decrypting packets exchanged between the terminal unit and the data server.

3. The capturing method as claimed in claim 1 , wherein the cooperation packet is a packet of a secure data multiplexing protocol and the cooperation packet is identified from one or more of the following parameter(s):

phase bit;

value of a spin bit of a QUIC (Quick UDP Internet Communications) transport protocol packet; value of RR bits of the QUIC transport protocol packet;

connection identifier.

4. The capturing method as claimed in claim 1 , wherein the cooperation packet is identified after activating, in the device, detection of the packets for which the determining datum has a value that differs from the determining datum of a plurality of successive packets previously received from the terminal unit.

5. The capturing method as claimed in claim 1 , wherein the security key associated with the determining datum is transmitted by the terminal unit to the device after an end of the session between the terminal unit and the data server.

6. The capturing method as claimed in claim 1 , wherein the security key associated with the determining datum was used for securing an exchange of packets from a previous session between the terminal unit and the data server.

7. The capturing method as claimed in claim 1 , wherein the security key associated with the determining datum is a key negotiated between the terminal unit and the data server during a step of initializing the session.

8. The capturing method as claimed in claim 1 , wherein the cooperation packet is removed from the plurality of packets when routing said plurality of packets to the data server.

9. The capturing method as claimed in claim 1 , further comprising analyzing, as well as identifying a cooperation packet, and decrypting the cooperation packet as defined in claim 1 , from among the packets transmitted by the data server to the terminal unit.

10. A device for capturing a packet from an encrypted session established between a terminal unit and a data server, said packet comprising a datum for determining a security key used for encrypting the packet, the device comprising:

a processor; and

a non-transitory computer readable medium comprising instructions stored thereon which when executed by the processor configure the device to implement a method comprising:

analyzing the datum for determining the security key of a plurality of received packets transmitted by the terminal unit and destined for the server;

identifying a cooperation packet from among the plurality of transmitted packets, said cooperation packet comprising a value of the determining datum, distinct from a value of the data for determining the security keys of the other packets of the plurality of packets, said value of the determining datum of the cooperation packet corresponding to a security key used for encrypting packets transmitted by the terminal unit to the data server prior to the terminal unit sending said cooperation packet;

a decryption module, capable of decrypting the cooperation packet using a security key corresponding to the value of the determining datum of the identified cooperation packet.

11. A non-transitory computer readable medium comprising a computer program stored thereon comprising instructions for implementing a capturing method, when the program is executed by a processor of a device routing a packet between a terminal unit and a data server, the capturing method capturing the packet from an encrypted session established between the terminal unit and the data server, said packet comprising a datum for determining a security key used for encrypting the packet, the method comprising:

analyzing the datum for determining the security key of a plurality of received packets transmitted by the terminal unit and destined for the server;

identifying a cooperation packet from among the plurality of transmitted packets, said cooperation packet comprising a value of the determining datum, distinct from a value of the data for determining the security keys of the other packets of the plurality of packets, said value of the determining datum of the cooperation packet corresponding to a security key used for encrypting packets transmitted by the terminal unit to the data server prior to the terminal unit sending said cooperation packet; and

decrypting the cooperation packet using a security key corresponding to the value of the determining datum of the identified cooperation packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: ALLAL, IMED; STEPHAN, EMILE; FROMENTOUX, GAËL; BRAUD, ARNAUD
To: ORANGE
Reel/Frame 066393/0824 →
Priority Claims (1)
FR 2005863 · Jun 4, 2020 · national
Continuity (1)
Related Publication 20230247009A1 · Aug 3, 2023
References Cited (11)
US 10389690B2 · Nádas · 2019 [cited by examiner]
US 20050177506A1 · Rissanen · 2005 [cited by applicant]
US 20210273926A1 · Stephan et al. · 2021 [cited by applicant]
US 20230262004A1 · Allal · 2023 [cited by examiner]
FR 3081653A1 · 2019 [cited by applicant]
WO 2020043319A1 · 2020 [cited by applicant]
WO WO2021009554A1 · 2021 [cited by examiner]
E. Rescorla, Internet Engineering Task Force (IETF) Request for Comments: 8446: “The Transport Layer Security (TLS) Protocol Version 1.3”, Aug. 2018, obtained online from <https://www.rfc-editor.org/rfc/pdfrfc/rfc8446.t… [cited by examiner]
International Search Report dated Jul. 30, 2021 for corresponding International Application No. PCT/FR2021/050992, filed Jun. 1, 2021. [cited by applicant]
Written Opinion of the International Searching Authority dated Jul. 30, 2021 for corresponding International Application No. PCT/FR2021/050992, filed Jun. 1, 2021. [cited by applicant]
International Preliminary Report on Patentability and English translation of the Written Opinion dated Dec. 6, 2022, for corresponding International Application No. PCT/FR2021/050992, filed Jun. 1, 2021. [cited by applicant]