PQC Adaptation for 6G AKA Procedures

By introducing post-quantum cryptography into communication networks, generating pre-shared keys and using the PQC key generation function, the security of authentication and key negotiation processes is enhanced, solving the problem of network security in communication networks under the threat of quantum computing, and realizing quantum-secure authentication and key negotiation.

CN122269279APending Publication Date: 2026-06-23NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2025-12-19
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Existing communication network authentication and key agreement (AKA) processes lack effective security enhancement mechanisms in the face of quantum computing threats, making it difficult to ensure high security and reliability between communication devices and networks.

Method used

The introduction of post-quantum cryptography (PQC) technology enhances the authentication and key negotiation process by generating a pre-shared post-quantum key (PPK) and a PQC-based key generation function. This includes generating public and private keys, deriving the shared key, and using PQC bitmaps for secure communication in authentication and security mode commands.

Benefits of technology

It provides resistance to quantum computing attacks, enhances the security and reliability of communication networks, and ensures the quantum security of authentication and key negotiation processes between communication devices and networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122269279A_ABST
    Figure CN122269279A_ABST
Patent Text Reader

Abstract

The present disclosure relates to post-quantum cryptography (PQC) enhancements for authentication and key agreement (AKA) procedures used in communication networks, in particular a PQC adaptation for 6G AKA procedures. Aspects of the present disclosure include: the use of a pre-shared post-quantum key (PPK), or a PPK selected from a list of PPKs, or the use of a post-quantum cryptography (PQC) key generation function to derive a home network public key (pk) and private key (sk) to define a PQC-based pk and a PQC-based sk for an authentication procedure between a user equipment and a network entity. Aspects of the present disclosure also include the use of a PQC-based pk and a PQC-based sk for the generation of a shared PQC-based key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to communication networks, and more specifically to enhancements to post-quantum cryptography (PQC) for authentication and key negotiation (AKA) processes used in communication networks. Background Technology

[0002] Mobile telecommunications networks or cellular networks (often referred to herein as communication networks) enable communication between two or more communication devices, provide communication devices with access to data networks, deliver services provided by third-party applications to communication devices, or provide communication devices with services supplied by the communication network.

[0003] Communication networks and equipment can operate according to cellular technologies (also known as radio access technologies), such as GSM, UMTS, LTE, LTE-A, and NR. Cellular technologies are standardized by various standards organizations, such as the 3rd Generation Partnership Project (3GPP) or ETSI (European Telecommunications Standards Institute). 3GPP is currently developing standards for fifth-generation cellular technologies (commonly referred to as 5G or NR standards) and sixth-generation cellular technologies (commonly referred to as 6G standards). Communication networks operating according to 5G or NR standards are generally referred to as 5G networks, and communication networks operating according to 6G standards are generally referred to as 6G networks.

[0004] Communication networks (e.g., 5G or 6G networks) include access networks (e.g., radio access networks) that can wirelessly communicate with one or more communication devices by sharing the available resources (e.g., bandwidth, transmit power, etc.) of the access network. Communication networks can also establish reliable and secure connections between communication devices and the core network of the communication network via the access networks. Communication networks (e.g., 5G or 6G networks) can provide communication devices with enhanced mobile broadband services (e.g., telephony, video, data, and short message services), ultra-reliable low-latency communication services (e.g., XR services), or massive machine-type communication services.

[0005] The Authentication and Key Agreement (AKA) process is a security mechanism used within a communication network (e.g., a 5G or 6G network). On one hand, the AKA process enables mutual authentication between a User Equipment (UE) and the core network of the communication network; and on the other hand, it provides key materials that can be used between the UE and the serving network in subsequent security processes.

[0006] Enhancement of the AKA process is desirable. Summary of the Invention

[0007] This disclosure relates to post-quantum cryptography (PQC) enhancements for authentication and key negotiation (AKA) processes used in communication networks.

[0008] In a first aspect of this disclosure, an apparatus is provided comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: acquire a pre-shared post-quantum key (PPK); initiate registration with a home network, the registration indicating the use of the PPK; receive an authentication challenge from a network entity, the authentication challenge including an authentication token (AUTN PPK) and a PPK indication, wherein the AUTN PPK is derived in part using the PPK; and verify the authentication token in part using the PPK.

[0009] In a second aspect of this disclosure, an apparatus is provided comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: acquire a list of pre-shared post-quantum keys (PPKs); initiate registration with a home network, the registration indicating the use of the PPK; receive an authentication challenge from a network entity, the authentication challenge including an authentication token (AUTN PPK) and a PPK indication identifying a PPK selected from the list of PPKs, wherein the AUTN PPK is derived in part using the selected PPK; and verify the authentication token in part using the selected PPK.

[0010] In a third aspect of this disclosure, an apparatus is provided, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: acquire a pre-shared post-quantum key (PPK); initiate registration with a home network, the registration indicating the use of the PPK; receive an authentication challenge from a network entity, the authentication challenge including an authentication token (AUTN PPK) and a PPK indication; verify the authentication token; and compute an enhanced response indicating successful verification. ),in It is partially exported using this PPK; and the enhanced response is sent to network entities ( ).

[0011] In a fourth aspect of this disclosure, an apparatus is provided, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: acquire a list of pre-shared post-quantum keys (PPKs); initiate registration with a home network, the registration indicating the use of the PPK; receive an authentication challenge from a network entity, the authentication challenge including an authentication token (AUTN PPK) and a PPK indication identifying a PPK selected from the list of PPKs; verify the authentication token; and compute an enhanced response indicating successful verification. ),in It is partially exported using the selected PPK; and the enhanced response is sent to the network entity. )

[0012] In a fifth aspect of this disclosure, an apparatus is provided comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: generate a home network public key (pk) and a private key (sk) derived using a post-quantum cryptography (PQC) key generation function to define a PQC-based pk and a PQC-based sk; initiate registration to the home network using the PQC-based pk; receive an authentication challenge from a network entity, the authentication challenge including an authentication token having ciphertext (an AUTN having ciphertext (ct)), wherein the AUTN having ct includes ct, and the AUTN having ct is derived in part using the PQC-based pk; and verify the authentication token in part using the PQC-based sk.

[0013] In a sixth aspect of this disclosure, an apparatus is provided, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: generate a home network public key (pk) and a private key (sk) derived using a post-quantum cryptography (PQC) key generation function to define a PQC-based pk and a PQC-based sk; prepare a PQC bitmap indicating one or more network entities supporting PQC; initiate registration with the home network using the PQC-based pk and including the PQC bitmap; receive a security mode command message (SMC) from a network entity, the SMC including ciphertext (ct) and a PQC indication, the SMC defining a PQC SMC; generate a shared key (pqc_ss) using ct and sk; derive a value (pqc_ct) by concatenating pqc_ss with ct; and derive a shared PQC key associated with the network entity by concatenating pqc_ct with a non-PQC key of the network entity.

[0014] In a seventh aspect of this disclosure, an apparatus is provided, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: generate a home network public key (pk) and a private key (sk) derived using a post-quantum cryptography (PQC) key generation function to define a PQC-based pk and a PQC-based sk; prepare a PQC bitmap indicating one or more network entities supporting PQC; initiate registration with the home network using the PQC-based pk and including the PQC bitmap; and receive a Non-Access Stratum (NAS) Security Mode Command Message (SMC) from an Access and Mobility Management Function (AMF), the SMC including ciphertext (ct) and a PQC indication, the SMC defining the PQC. SMC; Generate a shared key (pqc_ss) using ct and sk; Derive the value (pqc_ct) by concatenating pqc_ss with the ct; and Derive the AMF PQC key (KAMF_PQC) by concatenating pqc_ct with the AMF non-PQC key (KAMF).

[0015] In an eighth aspect of this disclosure, an apparatus is provided, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: generate a home network public key (pk) and a private key (sk) derived using a post-quantum cryptography (PQC) key generation function to define a PQC-based pk and a PQC-based sk; prepare a PQC bitmap indicating one or more network entities supporting PQC; initiate registration with the home network using the PQC-based pk and including the PQC bitmap; and receive an access stratum (AS) security mode command message (SMC) from a base station (gNB) of a radio access network (RAN), the SMC including ciphertext (ct) and a PQC indication, the SMC defining the PQC. SMC; Generate a shared key (pqc_ss) using ct and sk; Derive the value (pqc_ct) by concatenating pqc_ss with the ct; Generate a shared key (pqc_ss) using ct and sk; Derive the value (pqc_ct) by concatenating pqc_ss with the ct; and Derive the gNB PQC key (KgNB_PQC) by concatenating pqc_ct with the gNB non-PQC key (KgNB).

[0016] According to an aspect of this disclosure, an apparatus includes at least one processor and at least one memory storing instructions. When executed by the at least one processor, the instructions cause the apparatus to perform any of the methods and aspects described above.

[0017] According to an aspect of this disclosure, a processor-readable medium storage instruction, when executed by at least one processor of the device, causes the device to perform any of the methods and aspects described above.

[0018] The subject matter of the independent claims is provided for some aspects. Other aspects are defined in the dependent claims.

[0019] The foregoing summary provides a basic understanding of some aspects of this disclosure. This summary is not a broad overview of the disclosure and is not intended to limit its scope. Other aspects and features of this disclosure will become apparent to those skilled in the art from the following description of exemplary embodiments taken in conjunction with the accompanying drawings. Attached Figure Description

[0020] Some exemplary embodiments will now be described with reference to the accompanying drawings.

[0021] Figure 1 This is a schematic representation of a communication system according to an example implementation;

[0022] Figure 2 The user equipment and network entities of a communication system according to an example implementation are shown;

[0023] Figures 3A-3B It is a message sequence and operation diagram used in the existing authentication and key negotiation (AKA) process;

[0024] Figures 4A-4B It is a message sequence and operation diagram of an AKA process using a post-quantum pre-shared key (PPK) according to a first example implementation;

[0025] Figures 5A-5B It is a message sequence and operation diagram for an AKA process using PPK according to the second example embodiment;

[0026] Figures 6A-6B It is a message sequence and operation diagram for an AKA process without PPK, according to an example implementation;

[0027] Figure 7 An example embodiment is shown for use in Figures 4A-4B or Figures 5A-5B The construction of the authentication vector (AV) used in the AKA process;

[0028] Figures 8A-8B It is a message sequence and operation diagram for an AKA process using post-quantum cryptography (PQC) according to the first example implementation;

[0029] Figure 9 It shows the use of in Figures 8A-8BThe construction of the authentication token (AUTN) used in the AKA process;

[0030] Figures 10A-10B It is a message sequence and operation diagram for an AKA process using PQC according to the second example embodiment;

[0031] Figure 11A-11B It is a message sequence and operation diagram for an AKA process using PQC according to a third example implementation;

[0032] Figure 12A-12B It is a message sequence and operation diagram for an AKA process using PQC according to the fourth example implementation;

[0033] Figure 13 An example embodiment is shown for use in Figures 10A-10B PQC bitmap used in the AKA process of 11A-11B or 12A-12B;

[0034] Figure 14 An example embodiment is shown for use in Figures 10A-10B The construction of the encryption key (KAMF_PQC) used in the AKA process of 11A-11B;

[0035] Figure 15 An example embodiment of a method for... is shown. Figure 12A-11B The construction of the encryption key (KGNB_PQC) used in the AKA process. Detailed Implementation

[0036] The subject matter is described herein with reference to the accompanying drawings, in which exemplary embodiments are illustrated. However, many different exemplary embodiments may be used, and therefore this description should not be construed as limiting it to the embodiments set forth herein. Rather, these exemplary embodiments are provided to make this application exhaustive. Wherever possible, the same reference numerals are used in the drawings and the following description to refer to the same elements. Separate blocks or shown separation of logical elements in the illustrated systems and devices do not necessarily require physical separation of such logical elements, as communication between such logical elements can be achieved through message passing, function calls, shared memory space, etc., without any such physical separation. Therefore, logical elements do not need to be implemented on physically or logically separate platforms, although such logical elements are shown separately herein for ease of explanation. Different devices may have different designs such that while some devices implement some logical elements in hardware, other devices may implement these logical elements in a programmable processor using code obtained from a machine-readable medium. Finally, unless explicitly stated otherwise or implied by the context, elements referred to in the singular can be plural, and vice versa.

[0037] References to "one embodiment," "implementation," "exemplary embodiment," etc., in this disclosure indicate that the described embodiment may include a specific feature, structure, or characteristic, but not every embodiment necessarily includes that specific feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same embodiment. Additionally, when a specific feature, structure, or characteristic is described in connection with an embodiment, those skilled in the art will recognize that, whether explicitly described or not, in conjunction with other embodiments, influencing such feature, structure, or characteristic is within their knowledge.

[0038] As used herein, “send to,” “send toward,” “receive from,” “communicate with” (and variations thereof) include communication that may or may not involve one or more intermediate devices or nodes. The term “acquire” (and variations thereof) includes an initial acquisition or a subsequent acquisition. The term “connection” can refer to a physical connection or a logical connection.

[0039] Before describing illustrative embodiments, a general description of the communication system will follow. Figure 1 It is described in the context of.

[0040] refer to Figure 1 User equipment (UE) 100 is shown, which communicates via core network 108 with an application server (not shown) of a third-party application function (not shown) hosted on data network 102. This communication system includes a radio access network 106 (e.g., Next Generation Radio Access Network (NG-RAN)) and a core network 108 (e.g., a 5G core network (5GC)), which operates based on fifth-generation radio access technology, such as that described in the 3rd Generation Partnership Project (3GPP) standard for new radios. Core network 108 includes various network entities 110 (generally referred to as network functions), which will be described in more detail below.

[0041] User equipment 100 can be any device capable of transmitting and receiving wireless signals. Non-limiting examples of user equipment include mobile stations (MS), mobile devices (such as mobile phones or so-called "smartphones"), computers provided with wireless interface cards or other wireless interface facilities (e.g., USB dongles), personal data assistants (PDAs) or tablets provided with wireless communication capabilities, machine-type communication (MTC) devices, and Internet of Things (IoT) type communication devices, or any combination thereof.

[0042] Radio access network 106 includes one or more radio access network (RAN) nodes (also referred to as base stations). A RAN node can provide one or more cells. For example, a cell can be a macro cell, micro cell, femtocell, or picocell. A cell defines the coverage area or service area of ​​a RAN node. For example, a RAN node can be a Node B (NodeB or NB), an evolved Node B (eNodeB or eNB), a next-generation Node B (gNodeB or gNB), a remote radio unit (RRU), a remote radio head (RRH), a relay, integrated access and backhaul (IAB) node, or a low-power node.

[0043] The core network 108 has a service-based architecture. The network functions 110 of the core network include: Access and Mobility Management Function (AMF), Authentication Server Function (AUSF), Network Exposure Function (NEF), Network Repository Function (NRF), Network Slice Selection Function (NSSF), Policy Control Function (PCF), Session Management Function (SMF), User Plane Function (UPF), Unified Data Management (UDM), and Network Data Analysis Function (NWDAF).

[0044] AMF handles UE 100's access, authorization, and authentication, and manages UE 100's mobility when the UE moves between different radio access networks, cells, or locations.

[0045] The AUSF performs authentication and security-related functions to ensure secure and authenticated communication between the UE and the core network (CN). In 5G or 6G AKA processes, the AUSF acts as an intermediate node between the AMF and the UDM.

[0046] The UDM performs the authentication process, stores and manages user data (including subscriber profiles, authentication credentials, and authorization policies), and implements security mechanisms to protect user data and communication network (e.g., core network 108) resources from unauthorized attacks and vulnerabilities. The UDM is also responsible for managing the registration of network functions serving UE 100.

[0047] Figure 2This is a block diagram illustrating user equipment and network entities of core network 108 according to an illustrative embodiment. More specifically, system 200 shown in the figure includes user equipment (UE) 100 and multiple network entities 110-1, ..., 110-N. For example, in the illustrative embodiment, network entities 110-1, ..., 110-N may include AMF, AUSF, and UDM. It should be understood that UE 100 and network entities 110-1, ..., 110-N, including AMF, AUSF, and UDM, are configured to interact to perform secure operations, including authentication and key agreement (AKA) procedures that enable mutual authentication between UE 100 and core network 108 of the communication system; and provide key materials that can be used between the UE and the serving network to establish secure communication channels and ensure data confidentiality and integrity.

[0048] User equipment 100 includes a processor 212 coupled to memory 216 and an interface circuitry 210. The processor 212 of user equipment 100 includes a processing module 214, which is at least partially implemented as software executable by the processor. The processing module 214 performs the security operations described herein in conjunction with the accompanying drawings and exemplary embodiments. The memory 216 of user equipment 100 includes a storage module 218 that stores instructions and data generated or otherwise used during security operations.

[0049] although Figure 2 Not shown, but the UE includes a mobile device (ME) and a USIM. Both the ME and the USIM can be considered as including a processor 212 coupled to memory 216 and an interface circuit system 210, as generally described with respect to the UE.

[0050] Each network entity (referred to herein individually or collectively as 110) includes a processor 222 (226-1, ..., 226-N) coupled to a memory 226 (226-1, ..., 226-N), and an interface circuitry system 220 (220-1, ..., 220-N). Each processor 222 in each network entity 110 includes a processing module 224 (224-1, ..., 224-N), which may at least partially be implemented in the form of software executable by the processor 222. The processing module 224 performs the security operations described herein in conjunction with the accompanying drawings and exemplary embodiments. Each memory 226 in each network entity 110 includes a storage module 228 (228-1, ..., 228-N) storing instructions and / or data generated or otherwise used during security operations.

[0051] For example, processors 212 and 222 may include microprocessors, such as central processing units (CPUs), application-specific integrated circuits (ASICs), digital signal processors (DSPs), or other types of processing devices, as well as portions or combinations of such elements.

[0052] Memory 216 and 226 can be used to store one or more software programs that are executed by corresponding processor 212 and 222 to implement at least a portion of the functions described herein. For example, security operations and other functions as described herein in conjunction with the accompanying drawings and exemplary embodiments can be easily implemented using software code executed by processor 212 and 222.

[0053] Memory 216 and 226 can be considered as examples of what is more generally referred to herein as a computer program product, or still more generally as a processor-readable storage medium having executable program code embodied therein. Other examples of processor-readable storage media may include magnetic disks or other types of magnetic or optical media in any combination. Illustrative embodiments may include articles of manufacture comprising such computer program products or other processor-readable storage media.

[0054] Additionally, memories 216 and 226 may more specifically include, for example, electronic random access memory (RAM), such as static RAM (SRAM), dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memory, such as flash memory, magnetic RAM (MRAM), phase-change RAM (PC-RAM), or ferroelectric RAM (FRAM). The term "memory" as used herein is intended to be interpreted broadly, and may also include, for example, read-only memory (ROM), disk storage, or other types of storage devices, and portions or combinations thereof.

[0055] Interface circuit systems 210 and 220 illustratively include transceivers or other communication hardware or firmware that allow associated system components to communicate with each other.

[0056] from Figure 2It is evident that user equipment 100 and multiple network entities 110 are configured to interact via their respective interface circuit systems 210 and 220 for secure operation. This communication involves each participant sending data to one or more other participants and / or receiving data from one or more other participants. The term "data" as used herein is intended to be interpreted broadly to encompass any type of information that can be sent between participants, including but not limited to identification data, key pairs, key indicators, tokens, keys, security management messages, registration request / response messages and data, request / response messages, authentication request / response messages and data, metadata, control data, audio, video, multimedia, consent data, other messages, etc.

[0057] It should be understood that Figure 2 The specific component arrangements shown are merely examples, and various alternative configurations can be used in other embodiments. For example, any given network element / function can be configured to include additional or alternative components and support other communication protocols.

[0058] Figures 3A-3B This document illustrates the message sequence and operation diagram of an existing 5G AKA procedure, such as that described in 3GPP TS 33.501 (v18.2.0), which is incorporated herein by reference as if it were fully included.

[0059] The UE initiates the registration process.

[0060] At operation 301, the UE performs SUPI to SUCI hiding. The SUPI (Subscription Permanent Identifier) ​​is a globally unique 5G identifier assigned to each subscriber in the 5G system 100. The SUCI (Subscription Hidden Identifier) ​​contains the hidden Subscription Permanent Identifier (SUPI). The SUCI includes the SUPI type, the Home Network Identifier (HN-ID) identifying the subscriber's home network, the Routing Indicator (RID) assigned to the subscriber by the home network operator and supplied in the Universal Subscriber Identifier Module (USIM) of the UE 106, the Protection Scheme Identifier, the Home Network Public Key Identifier, and the scheme output (containing the ECC temporary public key, ciphertext value, and MAC tag value).

[0061] At operation 302, the UE sends a registration request to the AMF. The AMF includes a Security Anchor Function (SEAF) that supports authentication. The UE includes either a SUCI or a 5G Globally Unique Temporary Identifier (5G-GUTI) in the registration request.

[0062] At Operation 303, SEAF sends an authentication request to AUSF to initiate authentication. The authentication request includes SUCI or SUPI, and the service network name (SN-Name).

[0063] At Operation 304, upon receiving an authentication request, AUSF checks whether the requesting SEAF in the service network is authorized to use the service network name (SN-Name) in the authentication request by comparing the service network name with the expected service network name. If authorized, AUSF sends an authentication acquisition request to the home network's UDM. The authentication acquisition request includes SUCI or SUPI, and the service network name.

[0064] At operation 305, upon receiving an authentication acquisition request, the UDM identifies the SUPI (if received) or invokes the Subscription Identifier De-hiding Function (SIDF), which de-hides the SUPI from the SUCI (if received). The UDM (or the UDM's Authentication Credential Repository and Processing Function (ARPF)) selects or picks the authentication method for primary authentication based on this SUPI.

[0065] Belonging network computing AKA challenge.

[0066] At operation 306, the UDM uses cryptographic functions (f1, f2, f3, f4, f5) to compute the Message Authentication Code (MAC), Expected Response (XRES), Cipher Key (CK), Integrity Key (IK), and Anonymity Key (AK). The inputs include the Long-Term Key (K), a newly generated Random Number (RAND), the Authentication and Key Management Field (AMF), and a newly generated Sequence Number (SQN) (created through an incrementally stored non-time-based SQN, or a time-based SQN generated from a partially time-based SQN). The UDM derives K using the Key Derivation Function (KDF). AUSF The key, and calculate the expected enhanced response to the challenge ( K AUSF The key is derived according to KDF, where the inputs include the concatenation of CK and IK (CK||IK), the service network name (SNN), the sequence number of the home network (SQN), and the "XOR" of the anonymous key AK. The KDF is derived, with inputs including RAND, XRES, CK||IK, and SNN. Then, the UDM creates a structure containing RAND, an authentication token (AUTN), and... and K AUSF 5G Home Environment Authentication Vector (5G HEAV).

[0067] At operation 307, UDM sends an authentication acquisition response to AUSF with 5G HE AV, SUPI, and Authentication and Key Management (AKMA) instructions for the application.

[0068] At operation 308, AUSF utilizes the received SUCI or SUPI temporary storage to enhance the expected response. Then, AUSF uses RAND with cascaded inputs and The SHA-256 algorithm is expected to enhance the response ( ) Calculate hash expected to enhance response ( ).

[0069] At operation 309, AUSF from K AUSF Key generation K SEAF The key is prepared, and a 5G service environment authentication vector (5GSE AV) is constructed. 5G SE AV includes RAND, AUTN, and the expected hash response (...). ).

[0070] At operation 310, AUSF sends an authentication response to SEAF, including 5G SE AV.

[0071] At operation 311, SEAF storage .

[0072] At operation 312, SEAF sends an authentication request to the UE. This authentication request includes RAND, AUTN, Next Generation Key Set Identifier (ngKSI), and Inter-Architecture Anti-Bidding (ABBA) parameters.

[0073] The network is certified by the UE.

[0074] The UE consists of a Mobile Equipment (ME) and a USIM. The ME receives the Authentication Token (AUTN) and Random Challenge (RAND) from the authentication request and forwards them to the USIM. At operation 313, the USIM verifies the integrity of the Authentication Token (AUTN) by retrieving the MAC from the Authentication Token, calculating the XMAC using the cryptographic function corresponding to that used by the UDM, and verifying the integrity of the AUTN if MAC = XMAC. The USIM also verifies that the received SQN of the home network (referred to as SQNHN) is within the correct range, and if so, replaces it with the SQN in the USIM (referred to as SQNMS). If the AUTN integrity is verified, the USIM calculates the Response (RES).

[0075] USIM also calculates CK and IK, and returns the response (RES), CK key, and IK key to ME. ME then calculates based on RES. Calculate K AUSF The key, and according to K AUSF Key computation K SEAF Key. KAUSF The key is derived according to KDF, where the input includes a concatenation of CK and IK (CK||IK), the service network name (SNN), and an XOR of the sequence number (SQN) and the anonymous key AK. Enhanced Response It is derived from KDF, where the inputs include RAND, RES, CK||IK, and SNN.

[0076] At operation 314, the UE sends the following to the SEAF: The authentication response.

[0077] The UE is authenticated by the serving network.

[0078] At operation 315, SEAF uses the SHA-256 hash algorithm based on the received response. To calculate the enhanced response The hash, and will With the expected enhanced hash value The comparison is performed. If the comparison values ​​are equal, SEAF considers the authentication successful from the perspective of the service network.

[0079] At operation 316, SEAF sends a message to AUSF including... The authentication request.

[0080] The UE is authenticated by its home network.

[0081] At operation 317, AUSF will receive... With storage Compare. If and If they are equal, AUSF considers the authentication successful from the perspective of the home network.

[0082] At operation 318a, AUSF sends an authentication response to SEAF to notify SEAF of the authentication result. If authentication is successful, SUPI and K... SEAF The key is included in the authentication response. At Operation 318b, AUSF also informs the UDM of the authentication result (including SUPI, authentication timestamp, authentication type, and service network name) in the authentication result confirmation request message.

[0083] At operation 319, SEAF utilizes the received K SEAF IMSI and ABBA parameters generate K AMF The key. SEAF shares the generated K with AMF. AMF and ngKSI.

[0084] Authentication results are stored.

[0085] At operation 320, the UDM stores the authentication status of the UE.

[0086] At operation 321, UDM sends an authentication result confirmation response message to AUSF.

[0087] This disclosure relates to post-quantum cryptography (PQC) enhancements for authentication and key negotiation (AKA) processes used in communication networks. In some examples, a post-quantum pre-shared key (PPK) is mixed with a symmetric key to enable a known AKA process (such as regarding...). Figures 3A-3B The aforementioned provides an additional layer of quantum security. In other examples, purely post-quantum asymmetric algorithms are introduced, for example, for the 6G AKA process, to further enhance quantum security.

[0088] refer to Figures 4A-4B This describes an example of AKA using PPK.

[0089] The UE initiates the registration process.

[0090] At Operation 400, the pre-shared post-quantum key (PPK) is supplied to the USIM and UDM and can be referenced by SUPI. The UE decides to request the use of the PPK for the main authentication process.

[0091] At operation 401, the UE performs SUPI to SUCI hiding.

[0092] At operation 402, the UE sends a registration request to the AMF. The registration request includes a SUCI or a 5G Globally Unique Temporary Identifier (5G-GUTI), as well as instructions for using the PPK.

[0093] At Operation 403, SEAF sends an authentication request to AUSF to initiate authentication. The authentication request includes SUCI or SUPI, the service network name (SN-Name), and instructions for using the PPK.

[0094] At Operation 404, if the serving network is authorized, AUSF sends an authentication request to the home network's UDM. The authentication request includes SUCI or SUPI, the serving network name, and an instruction for using the PPK.

[0095] At operation 405, if the SUCI is received, the UDM calls the SIDF and executes the SUCI to SUPI for de-hiding. The UDM selects the authentication method (5GAKA, EAP-AKA, or EAP-TLS) for primary authentication based on the SUPI and provides the AUSF with the input for invoking that authentication method.

[0096] Belonging network computing AKA challenge.

[0097] At operation 406, UDM decided to use PPK for the AKA challenge. (Reference) Figure 7 There are two options for using PPK for the AKA challenge.

[0098] exist Figure 7 In option 1, PPK is concatenated with the long-term key K to obtain K||PPK. UDM uses encryption functions (f1, f2, f3, f4, f5) to compute the Message Authentication Code (MAC), Expected Response (XRES), Cipher Key (CK), Integrity Key (IK), and Anonymity Key (AK). The inputs include K||PPK, a newly generated random number (RAND), the Authentication and Key Management field AMF, and a newly generated Sequence Number (SQN) (created through an incrementally stored non-time-based SQN, or a time-based SQN generated from a partially time-based SQN). UDM uses the Key Derivation Function (KDF) to derive K. AUSF The key, and calculate the expected enhanced response to the challenge ( K AUSF The key is derived according to KDF, where the input includes a concatenation of CK and IK (CK||IK). The KDF is derived, with inputs including RAND, XRES, and CK||IK. In option 1, UDM derives the post-quantum pre-shared key authentication token (AUTN PPK) based on SQN, AK, AMF, and MAC. UDM then creates a PPK containing RAND, the authentication token (AUTN), and the expected response (…). ), and K AUSF The 6G Home Authentication Vector (6G HE PPK AV). The symbols “AUTN PPK” and “6G HE PPK AV” are used to represent the AUTN and AV partially derived using the PPK.

[0099] exist Figure 7 In option 2, PPK is concatenated with CK and IK to obtain CK||IK||PPK. UDM uses cryptographic functions (f1, f2, f3, f4, f5) to compute MAC, XRES, CK, IK, and AK, where the inputs include K, RAND, AMF, and SQN. UDM uses a key derivation function (KDF) to derive K. AUSF and K AUSF It is derived from KDF, where the inputs include a cascade of CK, IK, and PPK (CK||IK||PPK). The KDF is derived, with inputs including RAND, XRES, and CK||IK||PPK. In option 2, the UDM derives the authentication token (AUTN) based on SQN, AK, AMF, and MAC. The UDM then creates a structure containing RAND, the authentication token (AUTN), and the expected enhanced response (…). ), and K AUSF 6G Home Environment Authentication Vector (6G HE PPK AV).

[0100] In option 1, both AUTN PPK and 6G HE PPK AV are affected by the PPK, meaning they are derived partially using the PPK. AUTN PPK is affected by the PPK because at least the AK and MAC are derived based on an encryption function that includes K||PPK as input. 6G HE PPK AV is affected by the PPK because it is derived partially from AUTN PPK and also from... Both are exported, and both are affected by PPK. In option 2, the 6G HE PPK AV is affected by PPK, meaning it is partially exported using PPK because it is partially based on... And according to K AUSF Both are exported, and both include CK||IK||PPK as input.

[0101] At operation 407, the UDM sends an authentication acquisition response to the AUSF with a 6G HE PPK AV, SUPI, and an Authentication and Key Management (AKMA) instruction for the application, as well as an instruction for using an AKA challenge with a PPK.

[0102] At operation 408, AUSF utilizes the received SUCI or SUPI temporary storage to enhance the expected response. Then, AUSF uses cascaded input RAND and The SHA-256 algorithm, according to the expected enhanced response ( To compute the expected enhanced response of the hash () ).

[0103] At operation 409, AUSF, according to K SEAF Key generation K SEAF The key is prepared, and a quantum pre-shared key authentication vector (6G SE PPK AV) is prepared for the 6G service environment. The 6G SE PPK AV includes a random challenge (RAND), an authentication token (AUTN), and a hash expected response (...). ).

[0104] At operation 410, AUSF sends an authentication response to SEAF, which includes a 6G SE PPK AV and instructions for using the PPK for the AKA challenge.

[0105] At operation 411, SEAF storage .

[0106] At operation 412, SEAF sends an authentication request to the UE. This authentication request includes RAND, AUTN PPK (also known as a challenge with PPK), and PPK indication, as well as the Next Generation Key Set Identifier (ngKSI) and Inter-Architecture Anti-Bidding (ABBA) parameters.

[0107] The network is certified by the UE.

[0108] The UE includes a mobile device (ME) and a USIM. The ME receives an authentication token (AUTN PPK, e.g., in the authentication request). Figure 7 Option 1; or AUTN, for example, Figure 7 Option 2 is shown), Random Challenge (RAND), and PPK instructions, and forward them to USIM.

[0109] At operation 413, USIM verifies the integrity of the authentication token (e.g., AUTN PPK (Option 1) or AUTN (Option 2)) by retrieving the MAC from the authentication token; it retrieves the PPK based on the PPK indication, calculates the expected MAC (XMAC) (using an encryption function with inputs corresponding to Option 1 or Option 2, corresponding to Option 1 or Option 2 used by the UDM), and if MAC = XMAC, verifies the integrity of the AUTN PPK (Option 1) or the integrity of the AUTN (Option 2). If the AUTN PPK (Option 1) or the integrity of the AUTN (Option 2) is verified, USIM calculates the response (RES).

[0110] USIM also calculates CK and IK, and returns the response (RES), CK key, and IK key to ME. ME then calculates based on RES. Calculate K AUSF The key, and according to K AUSF Key computation K SEAF Key. In option 1, the PPK is used in part to verify the AUTN PPK and also to calculate the response (RES), K. AUSF ,as well as In option 2, PPK is used in part to calculate K. AUSF and .

[0111] In one embodiment, similar to Figure 7In option 1, K AUSF The KDF is derived where the inputs include a cascade of CK and IK (CK||IK) (with CK and IK being affected by K||PPK); and It is derived from KDF, where the inputs include RAND, XRES, and CK||IK. In another embodiment, it is similar to... Figure 7 In option 2, K AUSF It is derived from KDF, where the inputs include a cascade of CK, IK, and PPK (CK||IK||PPK). It is derived from KDF, where the inputs include RAND, XRES, and CK||IK||PPK.

[0112] At operation 414, the UE sends the following to the SEAF: The authentication response.

[0113] The UE is authenticated by the serving network.

[0114] At operation 415, SEAF adjusts the response received. Calculate using the SHA-256 hash algorithm and will Compared with the expected hash value The comparison is performed. If the comparison values ​​are equal, SEAF considers the authentication successful from the perspective of the service network.

[0115] At operation 416, SEAF sends a message to AUSF including... The authentication request.

[0116] The UE is authenticated by its home network.

[0117] At operation 417, AUSF will receive... With storage Compare. If and If they are equal, AUSF considers the authentication successful from the perspective of the home network.

[0118] At operation 418a, AUSF sends an authentication response to SEAF to notify SEAF of the authentication result. If authentication is successful, SUPI and K... SEAF The key is included in the authentication response. At Operation 18b, AUSF also informs the UDM of the authentication result (including SUPI, authentication timestamp, authentication type, and service network name) in the authentication result confirmation request message.

[0119] At operation 419, SEAF utilizes the received K SEAFThe KAMF key is generated using the IMSI and ABBA parameters. SEAF and AMF share the generated KAMF and ngKSI.

[0120] Authentication results are stored.

[0121] At operation 420, the UDM stores the authentication status of the UE.

[0122] At operation 421, UDM sends an authentication result confirmation response message to AUSF.

[0123] Now for reference Figures 5A-5B This describes another example of AKA using PPK.

[0124] The UE initiates the registration process.

[0125] At Operation 500, a list of pre-shared post-quantum keys (PPKs) is provided in the USIM and UDM and can be referenced by SUPI. The UE decides to request the use of the PPKs for the main authentication process.

[0126] At operation 501, the UE performs SUPI to SUCI hiding.

[0127] At operation 502, the UE sends a registration request to the AMF. The registration request includes a SUCI or a 5G Globally Unique Temporary Identifier (5G-GUTI), as well as instructions for using the PPK.

[0128] At Operation 503, SEAF sends an authentication request to AUSF to initiate authentication. The authentication request includes SUCI or SUPI, the service network name (SN-Name), and an instruction for using the PPK.

[0129] At Operation 504, if the serving network is authorized, AUSF sends an authentication request to the home network's UDM. The authentication request includes SUCI or SUPI, the serving network name, and an instruction for using the PPK.

[0130] At operation 505, if the SUCI is received, the UDM calls the SIDF and executes the SUCI to SUPI for de-hiding. The UDM selects the authentication method (5GAKA, EAP-AKA, or EAP-TLS) for primary authentication based on the SUPI and provides the AUSF with the input for calling the authentication method.

[0131] Belonging network computing AKA challenge.

[0132] At operation 506, UDM decides to use PPK for the AKA challenge. UDM selects a PPK from the PPK list based on the PPK ID and retrieves the associated PPK value.

[0133] exist Figure 7 In option 1, the selected PPK is concatenated with the long-term key K to obtain K||PPK. UDM uses encryption functions (f1, f2, f3, f4, f5) to calculate the Message Authentication Code (MAC), Expected Response (XRES), Cipher Key (CK), Integrity Key (IK), and Anonymity Key (AK). The inputs include K||PPK, a newly generated random number (RAND), the authentication and key management field AMF, and a newly generated sequence number (SQN) (created through an incrementally stored non-time-based SQN, or a time-based SQN generated from a partially time-based SQN). UDM uses the Key Derivation Function (KDF) to derive K. AUSF The key, and calculate the expected enhanced response to the challenge ( K AUSF The key is derived according to KDF, where the input includes a concatenation of CK and IK (CK||IK). The KDF is derived, with inputs including RAND, XRES, and CK||IK. In option 1, UDM derives the post-quantum pre-shared key authentication token (AUTN PPK) based on SQN, AK, AMF, and MAC. UDM then creates a PPK containing RAND, the authentication token (AUTN), and the expected response (…). ), and K AUSF 6G Home Authentication Vector (6G HEPPK AV).

[0134] exist Figure 7 In option 2, PPK is concatenated with CK and IK to obtain CK||IK||PPK. UDM uses cryptographic functions (f1, f2, f3, f4, f5) to compute MAC, XRES, CK, IK, and AK, where the inputs include K, RAND, AMF, and SQN. UDM uses a key derivation function (KDF) to derive K. AUSF and K AUSF It is derived from KDF, where the inputs include a cascade of CK, IK, and PPK (CK||IK||PPK). The KDF is derived, with inputs including RAND, XRES, and CK||IK||PPK. In option 2, the UDM derives the authentication token (AUTN) based on SQN, AK, AMF, and MAC. The UDM then creates a structure containing RAND, the authentication token (AUTN), and the expected enhanced response (…). ), and K AUSF 6G Home Environment Authentication Vector (6G HE PPKAV).

[0135] In option 1, both AUTN PPK and 6G HE PPK AV are affected by the selected PPK, meaning they are derived partially using the selected PPK. AUTN PPK is affected by the selected PPK because at least the AK and MAC are derived based on an encryption function that includes the K||PPK as input. 6G HE PPK AV is affected by the selected PPK because it is derived partially from AUTN PPK and based on... The exported data is affected by the selected PPK. In option 2, the 6G HE PPK AV is affected by the selected PPK, meaning it is exported partially using the selected PPK, as it is partially based on... And according to K AUSF The exported data includes CK||IK||PPK as input.

[0136] At operation 507, the UDM sends an authentication acquisition response to the AUSF containing a 6G HE PPK AV, SUPI, and an Authentication and Key Management (AKMA) instruction for the application, as well as an instruction to use a PPK (where the PPK is identified by a PPK ID) for an AKA challenge.

[0137] At operation 508, AUSF utilizes the received SUCI or SUPI temporary storage to enhance the expected response. Then, AUSF uses cascaded input RAND and The SHA-256 algorithm is used to enhance the response as expected. ) Calculate hash expected to enhance response ( ).

[0138] At operation 509, AUSF, according to K SEAF Key generation K SEAF The key is prepared, and the 5G service environment authentication vector (5GSE AV) is also prepared. The 5G SE AV includes the authentication token (AUTN), the expected hash response (...). ), and random challenges (RAND).

[0139] At operation 510, AUSF sends an authentication response to SEAF, which includes a 6G SE AV and an instruction to use a PPK (identified by a PPK ID) for the AKA challenge.

[0140] At operation 511, SEAF storage .

[0141] At operation 512, SEAF sends an authentication request to the UE. This authentication request includes RAND, AUTN PPK (also known as a challenge with PPK), and PPK indication (where the PPK is identified by the PPK ID), as well as the next-generation key set identifier (ngKSI) and inter-architecture anti-bid (ABBA) parameters.

[0142] The network is certified by the UE.

[0143] The UE includes a mobile device (ME) and a USIM. The ME receives an authentication token (AUTN PPK, e.g., in the authentication request). Figure 7 Option 1; or AUTN, for example, Figure 7 The system takes Option 2), a Random Challenge (RAND), and a PPK instruction, and forwards them to the USIM. At Operation 513, the USIM verifies the integrity of the authentication token (e.g., AUTN PPK (Option 1) or AUTN (Option 2)) by retrieving the MAC from the authentication token; based on the PPK instruction, it retrieves the selected PPK from the list of PPKs, calculates the expected MAC (XMAC) (using a cryptographic function where the input corresponds to Option 1 or Option 2, and corresponds to Option 1 or Option 2 used by the UDM), and if MAC = XMAC, it verifies the integrity of the AUTN PPK (Option 1) or the integrity of the AUTN (Option 2). If the AUTN PPK or the integrity of the AUTN is verified, the USIM calculates the response (RES).

[0144] USIM also calculates CK and IK, and returns the response (RES), CK key, and IK key to ME. ME then calculates based on RES. Calculate K AUSF The key, and according to K AUSF Key computation K SEAF Key. In option 1, the selected PPK is used in part to verify the AUTN PPK and also to calculate the response (RES), K. AUSF ,as well as In option 2, the selected PPK is used in part to calculate K. AUSF and .

[0145] In one embodiment, similar to Figure 7 In option 1, K AUSF The KDF is derived, where the inputs include a cascade of CK and IK (CK||IK) (where CK and IK are affected by K||PPK); and It is derived from KDF, where the inputs include RAND, XRES, and CK||IK. In another embodiment, it is similar to... Figure 7 In option 2, K AUSF It is derived from KDF, where the inputs include a cascade of CK, IK, and PPK (CK||IK||PPK). It is derived from KDF, where the inputs include RAND, XRES, and CK||IK||PPK.

[0146] At operation 514, the UE sends the following to the SEAF: The authentication response.

[0147] The UE is authenticated by the serving network.

[0148] At operation 515, SEAF uses the SHA-256 hash algorithm based on the received response. calculate and will Compared with the expected hash value The comparison is performed. If the comparison values ​​are equal, SEAF considers the authentication successful from the perspective of the service network.

[0149] At operation 516, SEAF sends a message to AUSF including... The authentication request.

[0150] UE is authenticated by its home network

[0151] At operation 517, AUSF will receive... With storage Compare. If and If they are equal, AUSF considers the authentication successful from the perspective of the home network.

[0152] At operation 518a, AUSF sends an authentication response to SEAF to notify SEAF of the authentication result. If authentication is successful, SUPI and K... SEAF The key is included in the authentication response. At Operation 518b, AUSF also informs the UDM of the authentication result (including SUPI, authentication timestamp, authentication type, and service network name) in the authentication result confirmation request message.

[0153] At operation 519, SEAF utilizes the received K SEAF The KAMF key is generated using the IMSI and ABBA parameters. SEAF and AMF share the generated KAMF and ngKSI.

[0154] Authentication results are stored.

[0155] At operation 520, the UDM stores the authentication status of the UE.

[0156] At operation 521, UDM sends an authentication result confirmation response message to AUSF.

[0157] Now for reference Figures 6A-6B This describes an example of an AKA with a PPK requested by the UE but not used by the UDM. For simplicity, only the first 6 operations will be described.

[0158] The UE initiates the registration process.

[0159] At Operation 600, the pre-shared post-quantum key (PPK) is supplied in the USIM and UDM and can be referenced by SUPI. The UE decides to request the use of the PPK for the main authentication process.

[0160] At operation 601, the UE performs SUPI to SUCI hiding.

[0161] At operation 602, the UE sends a registration request to the AMF. This registration request includes either a SUCI or a 5G Globally Unique Temporary Identifier (5G-GUTI), as well as instructions for using the PPK.

[0162] At Operation 603, SEAF sends an authentication request to AUSF to initiate authentication. The authentication request includes SUCI or SUPI, the service network name (SN-Name), and instructions for using the PPK.

[0163] At Operation 604, if the serving network is authorized, AUSF sends an authentication request to the home network's UDM. This authentication request includes SUCI or SUPI, the serving network name, and an instruction for using the PPK.

[0164] At operation 605, if the SUCI is received, the UDM calls the SIDF and executes the SUCI to SUPI for de-hiding. The UDM selects the authentication method for primary authentication based on the SUPI.

[0165] At operation 606, UDM decides not to use PPK for the AKA challenge. Instead, UDM generates authentication vectors without PPK, such as those related to... Figures 3A-3B The described steps are the same as described above. Figures 3A-3B The steps are repeated, except for the “600” series of figure labels.

[0166] Now for reference Figures 8A-8B It describes an example of using pure post-quantum cryptography (PQC), for example, in the 6G AKA process, to further enhance quantum security.

[0167] The UE initiates the registration process.

[0168] At Operation 800, the UE uses the PQC kemkeyGen function to generate the post-quantum cryptography (PQC) home network public key (pk) and private key (sk).

[0169] At operation 801, the UE performs SUPI to SUCI hiding.

[0170] At operation 802, the UE sends a registration request to the AMF. The registration request includes the SUCI or 5G Globally Unique Temporary Identifier (5G-GUTI) and the PQC public key (pk).

[0171] At operation 803, SEAF sends an authentication request to AUSF to initiate authentication. The authentication request includes SUCI or SUPI, the service network name (SN-Name), and the PQC public key (pk).

[0172] At Operation 804, if the serving network is authorized, AUSF sends an authentication request to the home network's UDM. The authentication request includes SUCI or SUPI, the serving network name, and the PQC public key (pk).

[0173] At operation 805, if the SUCI is received, the UDM calls the SIDF and executes the SUCI to SUPI for de-hiding. The UDM selects the authentication method (5GAKA, EAP-AKA, or EAP-TLS) for primary authentication based on the SUPI and provides the AUSF with the input for invoking that authentication method.

[0174] Belonging network computing PQC AKA challenge.

[0175] At operation 806, UDM decides to use PQC for the AKA challenge. UDM uses the PQCkemEncaps function with the public key (pk) to generate a shared key (pqc_ss) and ciphertext (ct). For IND-CCA2, pqc_ss is concatenated with ct to form pqc_ct. IND-CCA2 (Instintinguishability under Adaptive Chosen Ciphertext Attack) is an advanced security concept for cryptographic schemes that should be understood by those skilled in the art. UDM concatenates pqc_ct with a long-term key (k) for the AKA challenge.

[0176] refer to Figure 9UDM uses encryption functions (f1, f2, f3, f4, f5) to compute the Message Authentication Code (MAC), Expected Response (XRES), Cipher Key (CK), Integrity Key (IK), and Anonymity Key (AK). The inputs include a long-term key (K) concatenated with pqc_ct, RAND, AMF, and SQN. Note that the symbols f1K, f2K, etc., refer to the corresponding encryption functions (f1, f2, f3, f4, f5) where the input is concatenated with k (e.g., in an illustrative example, f3K(RAND) refers to the encryption function f3, where the input is RAND and the long-term key K concatenated with pqc_ct to obtain the output CK).

[0177] UDM uses a key derivation function (KDF) to derive the key. AUSF The key, whose inputs include a concatenation of the CK and IK cryptographic keys CK (CK||IK), the integrity key IK, SNN, and an "XOR" of SQN and AK. UDM also calculates the expected enhanced response based on KDF ( The inputs include RAND, XRES, SNN, and CK||IK. UDM derives the authentication token (AUTN) based on SQN, AK, ct, AMF, and MAC. UDM then creates a token containing RAND, AUTN, and K AUSF 6G Home Environment Authentication Vector (6G HE AV).

[0178] For convenience, "AUTN with ct" and "6G HE AV with ct" are used to refer to AUTN and 6G HE AV that are partially derived using ct. AUTN with ct is derived using ct, at least because it is calculated partly based on ct and partly based on AK and MAC, which are derived according to an encryption function including K||pqc_ct as input. 6G HE AV with ct is derived partially using ct, at least because it is calculated partly based on AUTN with ct and partly based on... Calculated, and Influenced by K||pqc_ct.

[0179] At operation 807, UDM sends an authentication acquisition response to AUSF, which includes: a 6GHE AV with ct, SUPI, an authentication and key management (AKMA) instruction for the application, and ciphertext (ct).

[0180] At operation 808, AUSF utilizes the received SUCI or SUPI temporary storage to enhance the expected response. Then, AUSF uses cascaded input RAND and The SHA-256 algorithm is used to enhance the response as expected. ) Calculate hash expected to enhance response ( ).

[0181] At operation 809, AUSF generates K based on KDF. SEAF Key, where the input includes K AUSF And SNN, and prepare 6G service environment authentication vector (6G SE AV with ct). 6G SE AV includes random challenge (RAND), authentication token (AUTN with ct), and hash expectation enhanced response ( ).

[0182] At operation 810, AUSF sends an authentication response to SEAF, including a 6G SE AV and a ct.

[0183] At operation 811, SEAF storage .

[0184] At operation 812, SEAF sends an authentication request to the UE. This authentication request includes RAND, AUTN with ct, Next Generation Key Set Identifier (ngKSI), and Inter-Architecture Anti-Bidding (ABBA) parameters.

[0185] The network is certified by the UE.

[0186] The UE includes the mobile device (ME) and the USIM. The ME receives the AUTN and RAND with ct in the authentication request and forwards them to the USIM.

[0187] At operation 813, USIM retrieves the MAC, SQN, and ct from the authentication token (e.g., AUTN with ct), and verifies the authentication token by first generating a shared key (pqc_ss) using the PQC kemdecaps function with ciphertext (ct) and private key (sk). For IND-CCA2, pqc_ss is concatenated with ct to form pqc_ct. UDM concatenates pqc_ct with a long key (k) for the AKA challenge. USIM then computes the expected MAC (XMAC) using the cryptographic function f1, where the inputs include SQN, RAND, AMF, and the long key (k) concatenated with pqc_ct, corresponding to the one used by UDM (see [link to cryptographic function]). Figure 9The USIM then compares the MAC and XMAC. If MAC = XMAC and the SQN is within the correct range, integrity is verified and the AUTN with ct is accepted. If the AUTN with ct is accepted, the USIM calculates the response (RES). The USIM also calculates CK and IK and returns the response (RES), CK, and IK to the ME. The ME then calculates the response based on RES. Calculate K AUSF The key, and according to K AUSF Key computation K SEAF The key is generated similarly to that in the UDM.

[0188] At operation 814, the UE sends the following to the SEAF: The authentication response.

[0189] The UE is authenticated by the serving network.

[0190] At operation 815, SEAF uses the SHA-256 hash algorithm based on the received response. To calculate and will Compared with the expected hash value The comparison is performed. If the comparison values ​​are equal, SEAF considers the authentication successful from the perspective of the service network.

[0191] At operation 816, SEAF sends a message to AUSF including... The authentication request.

[0192] The UE is authenticated by its home network.

[0193] At operation 817, AUSF will receive... With storage Compare. If and If they are equal, AUSF considers the authentication successful from the perspective of the home network.

[0194] At operation 818a, AUSF sends an authentication response to SEAF to notify SEAF of the authentication result. If authentication is successful, SUPI and K... SEAF The key is included in the authentication response. At Operation 818b, AUSF also informs the UDM of the authentication result (including SUPI, authentication timestamp, authentication type, and service network name) in the authentication result confirmation request message.

[0195] At operation 819, SEAF utilizes the received K SEAF The KAMF key is generated using the IMSI and ABBA parameters. SEAF and AMF share the generated KAMF and ngKSI.

[0196] Authentication results are stored.

[0197] At operation 820, the UDM stores the authentication status of the UE.

[0198] At operation 821, UDM sends an authentication result confirmation response message to AUSF.

[0199] Now for reference Figures 10A-10B The paper describes a second example of using pure post-quantum cryptography (PQC), for example, for the 6GAKA process, to further enhance quantum security.

[0200] The UE initiates the registration process.

[0201] At operation 1000, the UE uses the PQC kemkeyGen function to generate the post-quantum cryptography (PQC) KEM home network public key HN(pk) and private key (sk).

[0202] At operation 1001, the UE performs a SUPI to SUCI hide and prepares the PQC bitmap. An example PQC bitmap is shown below. Figure 13 It is shown. In Figure 13 In the example, the bits are set for entities that support PQC. As shown in the figure, the bits for 3GPP AN and SN are set to "1", indicating that AN and SN support PQC; and the bits for non-3GPP AN, SM NF, LMF NF, SMS NF, and HN are set to "0", indicating that these entities do not support PQC. For entities that support PQC, AS SMC and NAS SMC will operate independently, and a PQC shared key is generated and concatenated with the NAS key and AS key.

[0203] At operation 1002, the UE sends a registration request to the AMF. The registration request includes a SUCI or a 5G globally unique temporary identifier (5G-GUTI), a PQC public key (pk), and a PQC bitmap.

[0204] At operation 1003, SEAF sends an authentication request to AUSF to initiate authentication. The authentication request includes SUCI or SUPI, the service network name (SN-Name), the PQC public key (pk), and the PQC bitmap.

[0205] At operation 1004, if the serving network is authorized, AUSF will send an authentication request to the home network's UDM. This authentication request includes SUCI or SUPI, the serving network name, the PQC public key (pk), and the PQC bitmap.

[0206] At operation 1005, if the SUCI is received, the UDM calls the SIDF and executes the SUCI to SUPI for de-hiding. The UDM selects the authentication method (5GAKA, EAP-AKA, or EAP-TLS) for primary authentication based on the SUPI and provides the AUSF with the input for invoking that authentication method.

[0207] Belonging network computing PQC AKA challenge.

[0208] At operation 1006, UDM performs normal AV generation, such as regarding... Figures 3A-3B The difference is that it exports a 6G HE AV including a PQC bitmap.

[0209] At operation 1007, UDM sends an authentication acquisition response to AUSF containing a 6G HE AV, SUPI, Authentication and Key Management for Application (AKMA) instruction, PQC public key (pk), and PQC bitmap.

[0210] Operations 1008 to 1015 are not shown because they are identical to the normal AKA challenge process (without PQC), such as regarding Figures 3A-3B As described in operations 308 to 315.

[0211] At operation 1016, SEAF sends a message to AUSF including... The authentication request.

[0212] The UE is authenticated by its home network.

[0213] At operation 1017, AUSF will receive... With storage Compare. If and If they are equal, AUSF considers the authentication successful from the perspective of the home network.

[0214] At operation 1018a, AUSF sends an authentication response to SEAF to notify SEAF of the authentication result. If authentication is successful, SUPI and K... SEAF The key, along with the PQC public key (pk) and PQC bitmap, is included in the authentication response. At operation 1018b, AUSF also notifies the UDM of the authentication result (including SUPI, authentication timestamp, authentication type, and service network name) in the authentication result confirmation request message.

[0215] At operation 1019, SEAF utilizes the received K... SEAF The KAMF key is generated using the IMSI and ABBA parameters. SEAF and AMF share the generated KAMF and ngKSI.

[0216] Authentication results are stored.

[0217] At operation 1020, the UDM stores the authentication status of the UE.

[0218] At operation 1021, UDM sends an authentication result confirmation response message to AUSF.

[0219] At operation 1022, the AMF uses the `kemEncaps` function with the public key (pk) to generate a shared key (pqc_ss) and ciphertext (ct). For IND_CCA2, pqc_ss is concatenated with ct to form pqc_ct, and this value is concatenated with KAMF to generate a NAS key, such as... Figure 14 As shown in the diagram. Note that the same process can be used for AS or RAN keys with PQC, for example, RAN keys with PQC are generated in... Figure 15 The NAS SMC operates between the AMF and the UE, and the AS SMC operates between the RAN and the UE.

[0220] At operation 1023, the AMF sends a Non-Access Stratum (NAS) Security Mode Command (SMC) message to the UE with a set of PQC flags (i.e., PQC indications). Therefore, the UE knows this is a PQC SMC. The NAS SMC includes ct.

[0221] At operation 1024, USIM uses the Kemdecaps function with ct and sk to generate a shared key (pqc_ss). Then, as... Figure 14 As shown, pqc_ss is concatenated with ct to form pqc_ct, and this value (pqc_ct) is concatenated with the AMF non-PQC key (KAMF) to derive the AMFPQC key (KAMF_PQC).

[0222] Now for reference Figure 11A-11B It describes a fourth example of using pure post-quantum cryptography (PQC), for example, for the 6GAKA process, to further enhance quantum security.

[0223] The UE initiates the registration process.

[0224] At operation 1100, the UE uses the PQC kemkeyGen function to generate the post-quantum cryptography (PQC) KEM service network public key SN(pk) and private key (sk).

[0225] At operation 1101, the UE performs SUPI to SUCI hiding and prepares the Non-Access Stratum (NAS) PQC bitmap. An example PQC bitmap is shown below. Figure 13 The location is shown. Figure 13In the example, the bits are set for entities that support PQC. As shown in the figure, the bits for 3GPP AN and Serving Network (SN) are set to "1", indicating that the AN and SN support PQC; and the bits for non-3GPPAN, SMNF, LMFNF, SMSNF, and HN are set to "0", indicating that those entities do not support PQC. For entities that support PQC, AS SMC and NAS SMC will operate independently, and a PQC shared key is generated and concatenated with the NAS key and AS key.

[0226] At operation 1102a, the UE sends a registration request to the AMF. The registration request includes a SUCI or a 5G globally unique temporary identifier (5G-GUTI), a PQC public key (pk), and a NAS PQC bitmap. At operation 1102b, the AMF stores the PQC public key (pk) and the NAS PQC bitmap.

[0227] At operation 1103, SEAF sends an authentication request to AUSF to initiate authentication. The authentication request includes SUCI or SUPI, and the service network name (SN-Name).

[0228] At operation 1104, if the serving network is authorized, AUSF sends an authentication request to the home network's UDM. The authentication request includes SUCI or SUPI, and the serving network name.

[0229] At operation 1105, if the SUCI is received, the UDM calls the SIDF and executes the SUCI to SUPI for de-hiding. The UDM selects the authentication method (5GAKA, EAP-AKA, or EAP-TLS) for primary authentication based on the SUPI and provides the AUSF with the input for invoking that authentication method.

[0230] Belonging network computing PQC AKA challenge.

[0231] At operation 1106, UDM performs normal AV generation, such as regarding... Figures 3A-3B The difference is that it exports 6G HE AV.

[0232] At operation 1107, UDM sends an authentication acquisition response to AUSF with 6G HE AV, SUPI, and Authentication and Key Management for Application (AKMA) instructions.

[0233] Operations 1108 to 1115 are not shown because they are the same as normal AKA challenge procedures (without PQC), as described with respect to operations 308 to 315 in Figure 3.

[0234] At operation 1116, SEAF sends a message to AUSF including... The authentication request.

[0235] The UE is authenticated by its home network.

[0236] At operation 1117, AUSF will receive... With storage Compare. If and If they are equal, AUSF considers the authentication successful from the perspective of the home network.

[0237] At operation 1118a, AUSF sends an authentication response to SEAF to notify SEAF of the authentication result. If authentication is successful, SUPI and K... SEAF The key is included in the authentication response. At Operation 1118b, AUSF also informs the UDM of the authentication result (including SUPI, authentication timestamp, authentication type, and service network name) in the authentication result confirmation request message.

[0238] At operation 1119, SEAF utilizes the received K SEAF The KAMF key is generated using the IMSI and ABBA parameters. SEAF and AMF share the generated KAMF and ngKSI.

[0239] Authentication results are stored.

[0240] At operation 1120, the UDM stores the authentication status of the UE.

[0241] At operation 1121, UDM sends an authentication result confirmation response message to AUSF.

[0242] At operation 1122, the AMF uses the `kemEncaps` function with the public key (pk) to generate a shared key (pqc_ss) and ciphertext (ct). For IND_CCA2, pqc_ss is concatenated with ct to form pqc_ct, and this value is concatenated with KAMF to generate a NAS key, such as... Figure 14 As shown in the diagram. Note that the same process can be used for AS or RAN keys with PQC, for example, RAN keys with PQC are generated in... Figure 15 It is shown in the middle.

[0243] At operation 1123, the AMF sends a NAS SMC message with the PQC flag set to the UE. Therefore, the UE knows this is a PQCSMC. The NAS SMC includes ct.

[0244] At operation 1124, USIM uses the Kemdecaps function with ct and sk to generate a shared key (pqc_ss). Then, as... Figure 14 As shown, pqc_ss is concatenated with ct to form pqc_ct, and this value (pqc_ct) is concatenated with the AMF non-PQC key (KAMF) to derive the AMF PQC key (KAMF_PQC).

[0245] Now for reference Figure 12A-12B It describes a fourth example of using pure post-quantum cryptography (PQC), for example, for the 6GAKA process, to further enhance quantum security.

[0246] The UE initiates the registration process.

[0247] At operation 1200, the UE uses the PQC kemkeyGen function to generate the post-quantum cryptography (PQC) KEM access network public key AN(pk) and private key (sk).

[0248] At operation 1201, the UE performs SUPI to SUCI hiding and prepares the Access Layer (AS) PQC bitmap. An example PQC bitmap is shown below. Figure 13 The location is shown. Figure 13 In the example, the bits are set for entities that support PQC. As shown in the figure, the bits for 3GPP AN and Serving Network (SN) are set to "1", indicating that the AN and SN support PQC; and the bits for non-3GPP AN, SMNF, LMFNF, SMSNF, and HN are set to "0", indicating that those entities do not support PQC. For entities that support PQC, ASSMC and NAS SMC will operate independently, and a PQC shared key is generated and concatenated with the NAS key and AS key.

[0249] At operation 1202a, the UE sends a registration request to the AMF. The registration request includes a SUCI or a 5G globally unique temporary identifier (5G-GUTI), a PQC public key (pk), and an AS PQC bitmap. At operation 1202b, the AMF stores the PQC public key (pk) and the AS PQC bitmap.

[0250] At operation 1203, SEAF sends an authentication request to AUSF to initiate authentication. The authentication request includes SUCI or SUPI, and the service network name (SN-Name).

[0251] At operation 1204, if the serving network is authorized, AUSF sends an authentication request to the home network's UDM. The authentication request includes SUCI or SUPI, and the serving network name.

[0252] At operation 1205, if the SUCI is received, the UDM calls the SIDF and executes the SUCI to SUPI for de-hiding. The UDM selects the authentication method (5GAKA, EAP-AKA, or EAP-TLS) for primary authentication based on the SUPI and provides the AUSF with the input for invoking that authentication method.

[0253] Belonging network computing PQC AKA challenge.

[0254] At operation 1206, UDM performs normal AV generation, such as regarding... Figures 3A-3B The difference is that it exports 6G HE AV.

[0255] At operation 1207, UDM sends an authentication acquisition response to AUSF with 6G HE AV, SUPI, and Authentication and Key Management for Application (AKMA) instructions.

[0256] Operations 1208 to 1215 are not shown because they are identical to the normal AKA challenge process (without PQC), such as regarding Figures 3A-3B As described in operations 308 to 315.

[0257] At operation 1216, SEAF sends a message to AUSF including... The authentication request.

[0258] The UE is authenticated by its home network.

[0259] At operation 1217, AUSF will receive... With storage Compare. If and If they are equal, AUSF considers the authentication successful from the perspective of the home network.

[0260] At operation 1218a, AUSF sends an authentication response to SEAF to notify SEAF of the authentication result. If authentication is successful, SUPI and K... SEAF The key is included in the authentication response. At Operation 1218b, AUSF also informs the UDM of the authentication result (including SUPI, authentication timestamp, authentication type, and service network name) in the authentication result confirmation request message.

[0261] At operation 1219, SEAF utilizes the received K SEAF IMSI and ABBA parameters generate K AMF The key. SEAF shares the generated K with AMF. AMF and ngKSI.

[0262] Authentication results are stored.

[0263] At operation 1220, the UDM stores the authentication status of the UE.

[0264] At operation 1221, UDM sends an authentication result confirmation response message to AUSF.

[0265] At operation 1222, NAS SMC certification was successful.

[0266] At operation 1223, the AMF and gNB perform the initial context establishment process, in which the AMF sends a bitmap and pk to the gNB.

[0267] At operations 1224 and 1225, the gNB will generate the PQC shared key. Then at operation 1226, as follows... Figure 15 As shown, the gNB key (KgNB) is concatenated with the pqc_ct key to derive the gNB PQC key (KgNB_PQC), which is used to generate NAS encryption and integrity keys.

[0268] At operation 1227, the gNB sends an Access Stratum (AS) Security Mode Command (SMC) message to the UE with a set of PQC flags (i.e., PQC indications). Therefore, the UE knows it is a PQC SMC. The AS SMC includes ct.

[0269] At operation 1228, USIM uses the Kemdecaps function with ct and sk to generate a shared key (pqc_ss). Then, as... Figure 15 As shown, pqc_ss is concatenated with ct to form pqc_ct, and this value (pqc_ct) is concatenated with the gNB non-PQC key (KgNB) to derive the gNB PQC key (KgNB_PQC).

[0270] The embodiments and aspects disclosed herein are examples of this disclosure and may be embodied in various forms. For example, although some embodiments herein are described as separate embodiments, each embodiment herein may be combined with one or more embodiments in other embodiments herein. The specific structural and functional details disclosed herein should not be construed as limiting, but rather serve as the basis for the claims and as a representative basis for teaching those skilled in the art to adopt this disclosure in various ways in virtually any suitably detailed structure. The same reference numerals may refer to similar or identical elements in the description of the drawings.

[0271] In various embodiments, "first message" and "second message," as well as any subsequent message, can refer to any message that is sent or received in sequence, and are not necessarily limited to any particular message.

[0272] The phrases “in one embodiment,” “in an embodiment,” “in various embodiments,” “in some embodiments,” or “in other embodiments” can each refer to one or more of the same or different embodiments according to this disclosure. The phrase form “A or B” means “(A), (B), or (A and B).” The phrase form “at least one of A, B, or C” means “(A); (B); (C); (A and B); (A and C); (B and C); or (A, B, and C).”

[0273] Any method, program, algorithm, or code described herein can be converted into or represented in a programming language or computer program. As used herein, the terms "programming language" and "computer program" each include any language used to specify instructions to a computer, and include (but are not limited to) the following languages ​​and their derivatives: assembly language, Basic language, batch files, BCPL, C language, C++, Delphi, Fortran, Java, JavaScript, machine code, operating system command languages, Pascal, Perl, PL1, Python, scripting languages, Visual Basic, the meta-language that specifies the program itself, and all first-, second-, third-, fourth-, fifth-, or other generational computer languages. Additionally, databases and other data schemas, and any other meta-languages, are also included. There is no distinction between interpreted languages, compiled languages, or languages ​​that use both compilation and interpretation methods. There is also no distinction between compiled and source versions of a program. Therefore, where a program's programming language can exist in more than one state (such as source, compiled, object, or linked), a reference to the program refers to a reference to all of these states. References to a program may contain actual instructions and / or the intent of those instructions.

[0274] While aspects of this disclosure have been shown in the accompanying drawings, this disclosure is not intended to be limited thereto, but rather to cover the widest scope that will be permitted in the art, and the specification should be interpreted in the same manner. Therefore, the foregoing description should not be construed as restrictive, but merely as exemplary illustration of particular aspects. Other modifications within the scope and spirit of the appended claims will be apparent to those skilled in the art.

Claims

1. A device for communication, comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the device to at least: Generate the home network public key (pk) and private key (sk) derived using the post-quantum cryptography PQC key generation function to define PQC-based pk and PQC-based sk; Prepare a PQC bitmap, which indicates one or more network entities that support PQC; Using the PQC-based pk and including the PQC bitmap, initiate registration with the home network; Receive a Security Mode Command Message (SMC) from a network entity. The SMC includes ciphertext (ct) and a PQC indication. The SMC defines a PQC SMC. Use the ct and the sk to generate a shared key (pqc_ss); By concatenating pqc_ss with ct, the value (pqc_ct) is derived; and By concatenating pqc_ct with the non-PQC key of the network entity, a shared PQC key associated with the network entity is derived.

2. The apparatus of claim 1, wherein the Security Mode Command Message (SMC) includes a Non-Access Stratum (NAS) Security Mode Command Message (NAS SMC), and the network entity includes an Access and Mobility Management Function (AMF).

3. The apparatus of claim 2, wherein the shared PQC key comprises: The AMF PQC key (KAMF_PQC) is derived by concatenating pqc_ct with the AMF non-PQC key (KAMF).

4. The apparatus of claim 1, wherein the security mode command message SMC includes an access layer AS security mode command message AS SMC, and the network entity includes a base station gNB of a radio access network RAN.

5. The apparatus of claim 4, wherein the shared PQC key comprises: The gNB PQC key (KgNB_PQC) is derived by concatenating pqc_ct with the gNB non-PQC key (KgNB).

6. A method performed by a user equipment (UE), the method comprising: Generate the home network public key (pk) and private key (sk) derived using the post-quantum cryptography PQC key generation function, and define pk and sk based on PQC. Prepare a PQC bitmap, which indicates one or more network entities that support PQC; Using the PQC-based pk and including the PQC bitmap, initiate registration with the home network; Receive a Security Mode Command Message (SMC) from a network entity. The SMC includes ciphertext (ct) and a PQC indication. The SMC defines a PQC SMC. Use the ct and the sk to generate a shared key (pqc_ss); By concatenating pqc_ss with ct, the value (pqc_ct) is derived; and By concatenating pqc_ct with the non-PQC key of the network entity, a shared PQC key associated with the network entity is derived.

7. The method of claim 6, wherein the Security Mode Command Message (SMC) includes a Non-Access Stratum (NAS) Security Mode Command Message (NAS SMC), and the network entity includes an Access and Mobility Management Function (AMF).

8. The method of claim 7, wherein the shared PQC key comprises: The AMF PQC key (KAMF_PQC) is derived by concatenating pqc_ct with the AMF non-PQC key (KAMF).

9. The method of claim 6, wherein the Security Mode Command Message (SMC) includes an Access Layer Security Mode Command Message (AS SMC), and the network entity includes a Radio Access Network (RAN) base station (gNB).

10. The method of claim 9, wherein the shared PQC key comprises: The gNB PQC key (KgNB_PQC) is derived by concatenating pqc_ct with the gNB non-PQC key (KgNB).

11. A device for communication, comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the device to at least: Generate the home network public key (pk) and private key (sk) derived using the post-quantum cryptography PQC key generation function to define PQC-based pk and PQC-based sk; Prepare a PQC bitmap, which indicates one or more network entities that support PQC; Using the PQC-based pk and including the PQC bitmap, initiate registration with the home network; Receive a Non-Access Layer NAS Security Mode Command Message (SMC) from the AMF. The NAS SMC includes ciphertext (ct) and a PQC indication. The SMC defines a PQC SMC. Use the ct and the sk to generate a shared key (pqc_ss); By concatenating pqc_ss with ct, the value (pqc_ct) is derived; and The AMF PQC key (KAMF_PQC) is derived by concatenating pqc_ct with the AMF non-PQC key (KAMF).

12. A method performed by a user equipment (UE), comprising: Generate the home network public key (pk) and private key (sk) derived using the post-quantum cryptography PQC key generation function, and define pk and sk based on PQC. Prepare a PQC bitmap, which indicates one or more network entities that support PQC; Using the PQC-based pk and including the PQC bitmap, initiate registration with the home network; Receive a Non-Access Layer NAS Security Mode Command Message (SMC) from the AMF. The NAS SMC includes ciphertext (ct) and a PQC indication. The SMC defines a PQC SMC. Use the ct and the sk to generate a shared key (pqc_ss); By concatenating pqc_ss with ct, the value (pqc_ct) is derived; and The AMF PQC key (KAMF_PQC) is derived by concatenating pqc_ct with the AMF non-PQC key (KAMF).

13. A communication apparatus, comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the device to at least: Generate the home network public key (pk) and private key (sk) derived using the post-quantum cryptography PQC key generation function to define PQC-based pk and PQC-based sk; Prepare a PQC bitmap, which indicates one or more network entities that support PQC; Using the PQC-based public key (pk) and including the PQC bitmap, initiate a registration with the home network; The Access Layer Security Mode Command Message (SMC) is received from the base station gNB of the Radio Access Network (RAN). The AS SMC includes ciphertext (ct) and PQC indication, and the SMC defines the PQC SMC. Use the ct and the sk to generate a shared key (pqc_ss); By concatenating pqc_ss with ct, the value (pqc_ct) is derived; and The Gnb PQC key (KgNB_PQC) is derived by concatenating pqc_ct with the gNB non-PQC key (KgNB).

14. A method performed by a user equipment (UE), the method comprising: Generate the home network public key (pk) and private key (sk) derived using the post-quantum cryptography PQC key generation function, and define pk and sk based on PQC. Prepare a PQC bitmap, which indicates one or more network entities that support PQC; Using the PQC-based public key (pk) and including the PQC bitmap, initiate a registration with the home network; The Access Layer Security Mode Command Message (SMC) is received from the base station gNB of the Radio Access Network (RAN). The AS SMC includes ciphertext (ct) and PQC indication, and the SMC defines the PQC SMC. Use the ct and the sk to generate a shared key (pqc_ss); By concatenating pqc_ss with ct, the value (pqc_ct) is derived; and The Gnb PQC key (KgNB_PQC) is derived by concatenating pqc_ct with the gNB non-PQC key (KgNB).