Hybrid post-quantum cryptography-based forward secrecy supporting communication device and method
Patent Information
- Application Number
- KR1020250032876
- Authority / Receiving Office
- KR · KR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2026-09-22
Smart Images

Figure PAT00003_ABST
Abstract
Description
Technology Field
[0001] The present invention relates to user authentication and secure communication technology in a mobile communication system, and more specifically, to a hybrid quantum-resistant cryptography-based forward secretion supporting communication device and method that applies post-quantum cryptography (PQC) secure against quantum computer-based attacks to enhance the protection of user identification information and authentication processes, and guarantees forward secretion through the continuous updating of a session key. Background Technology
[0003] In 5G systems, 5G-AKA and EAP-AKA are protocols used for mutual authentication and key exchange between user devices (UEs) and the 5G core network. While protocols at this stage are highly important for operating a stable network environment and protecting user privacy through data encryption, recent research indicates that the 5G-AKA protocol is vulnerable to Linkability Attacks that threaten user privacy and anonymity, and it lacks support for forward secrecy, which is a strong confidentiality for encrypted data transmitted over the network. Furthermore, the emergence of quantum computing poses a serious threat to traditional encryption algorithms that form the basis of existing authentication systems. Quantum algorithms, such as Shor's algorithm, can efficiently destroy widely used encryption methods like RSA and ECC, leading to vulnerabilities in existing authentication protocols and systems.
[0004] Accordingly, the first standard document on quantum-resistant cryptography (PQC) was released by NIST (National Institute of Standards and Technology) on August 17, 2024. However, the verification period for the security of the algorithm is shorter compared to traditional cryptography, and in particular, software implementation vulnerabilities have not been verified over a sufficient period of time. Consequently, there is a growing need for a protocol that can guarantee both short-term and long-term security by combining traditional encryption methods, whose security has been proven over a long period, with PQC.
[0005] Korean Registered Patent No. 10-2662935 relates to an apparatus and method for providing a service for authentication using quantum-resistant cryptography, comprising: a message management unit that receives a message based on the RADIUS (remote authentication dial in user service) protocol from a client device, analyzes the message, and stores authentication request information in a work queue; a quantum-resistant cryptography process processing unit that generates and manages quantum-resistant cryptography processing threads in parallel, and generates a key pair through a quantum-resistant cryptography algorithm pre-configured in the quantum-resistant cryptography processing thread or requested by the client device upon receiving a request for key pair generation; and an asynchronous work thread module that generates and allocates an asynchronous work thread module in parallel for each authentication request information stored in the work queue, communicates with the client device through the asynchronous work thread module to identify the client device, and upon receiving a client public key generated by the quantum-resistant cryptography algorithm from the client device, requests the quantum-resistant cryptography process processing unit to generate a key pair, and receives a response message from the quantum-resistant cryptography process processing unit that includes a server public key among the key pairs. It includes a work thread management unit that transmits to the above client device, generates a master session key using the client public key and the server private key among the key pair in conjunction with the quantum-resistant cryptography process processing unit, and uses it for communication with the client device. Prior art literature
[0007] Korean Registered Patent No. 10-2662935 (April 29, 2024) The problem to be solved
[0008] One embodiment of the present invention aims to provide a hybrid quantum-resistant cryptography-based forward secrecy-supporting communication device and method capable of protecting subscriber privacy by securely encrypting user identification information based on quantum-resistant cryptography.
[0009] One embodiment of the present invention aims to provide a communication device and method that supports forward secrecy based on a hybrid quantum-resistant cryptography, capable of ensuring integrity and preventing replay attacks by performing challenge response authentication using a Milenage Function and a Hash-based Message Authentication Code (HMAC).
[0010] One embodiment of the present invention aims to provide a hybrid quantum-resistant cryptography-based forward secretivity supporting communication device and method that can guarantee forward secretivity and enhance the security of session data by generating and updating a session key using a quantum-resistant cryptography-based Post-Quantum Key Derivation Function (PQ-KDF). means of solving the problem
[0012] Among the embodiments, a hybrid quantum-resistant cryptography-based forward secrecy support communication device comprises: a subscription encryption identification unit that performs quantum-resistant cryptography-based encryption on a user identifier to generate a subscriber's identification information (SUCI, Subscription Concealed Identifier) and transmits said subscriber's identification information (SUCI) to a user terminal; a challenge response authentication unit that generates a random number (RAND) and provides it to the user terminal and inputs said random number (RAND) into a Milenage Function to generate an authentication token (AUTN); and a forward secrecy support unit that encrypts session data based on said authentication token (AUTN) and communicates with the user terminal.
[0013] The above subscription encryption identification unit can encrypt the subscriber's identification information (SUCI) with a public key and transmit it to the user terminal.
[0014] The above subscription encryption identifier can generate the public key using the above quantum-resistant cryptography-based key exchange algorithm.
[0015] The above subscription encryption identifier supports the protection of the subscriber's privacy by performing lattice-based encryption to encrypt the user identifier and performing quantum-resistant cryptography-based encryption, and the lattice-based encryption may utilize the Learning With Errors (LWE) problem.
[0016] The above subscription encryption identifier can implement public key encryption by performing the above quantum-resistant cryptography-based encapsulation algorithm (KEM, Key Encapsulation Mechanism) to generate the subscriber's identification information (SUCI).
[0017] The challenge response authentication unit above can generate a Message Authentication Code (MAC) based on a secret key to generate the above random number (RAND) and the above authentication token (AUTN).
[0018] The challenge response authentication unit can ensure the integrity of the authentication process and prevent replay attacks by additionally performing a Hash-based Message Authentication Code (HMAC) after the execution of the Milenage Function to generate the authentication token (AUTN).
[0019] The challenge response authentication unit can further perform quantum-resistant cryptography-based signature verification on the authentication token (AUTN) after the execution of the HMAC to enhance the integrity and reliability of the authentication data.
[0020] The above forward secrecy support unit can generate a session key by inputting the authentication token (AUTN) into the above quantum-resistant cryptography-based key derivation function (PQ-KDF, Post-Quantum Key Derivation Function) and encrypt the session data through the session key.
[0021] The forward secrecy support unit can enhance the strength and randomness of the session key by additionally inputting the random number (RAND) and the key material provided by the user terminal in addition to the authentication token (AUTN) to generate the session key.
[0022] The forward secrecy support unit described above can dynamically set the update cycle of the session key according to a certain time or data transmission amount, and transmit the updated session key to a user terminal.
[0023] The forward secrecy support unit can dynamically adjust update conditions by analyzing the network status and the data throughput of the user terminal in real time to set the update cycle of the session key.
[0024] Among the embodiments, a hybrid quantum-resistant cryptography-based forward secrecy support communication method performed in a hybrid quantum-resistant cryptography-based forward secrecy support communication device comprises: a subscription encryption identification step of generating a subscriber's identification information (SUCI, Subscription Concealed Identifier) by performing quantum-resistant cryptography-based encryption on a user identifier and transmitting said subscriber's identification information (SUCI) to a user terminal; a challenge response authentication step of generating a random number (RAND) and providing it to said user terminal and inputting said random number (RAND) into a Milenage Function to generate an authentication token (AUTN); and a forward secrecy support step of encrypting session data based on said authentication token (AUTN) and communicating with said user terminal.
[0025] The above subscription encryption identification step may include a step of encrypting the subscriber's identification information (SUCI) with a public key and transmitting it to the user terminal.
[0026] The challenge response authentication step described above may include a step of generating a Message Authentication Code (MAC) based on a secret key to generate the random number (RAND) and the authentication token (AUTN).
[0027] The above forward secrecy support step may include the step of generating a session key by inputting the authentication token (AUTN) into the quantum-resistant cryptography-based key derivation function (PQ-KDF, Post-Quantum Key Derivation Function) and encrypting the session data through the session key. Effects of the invention
[0029] The disclosed technology may have the following effects. However, this does not mean that a specific embodiment must include all of the following effects or only the following effects; therefore, the scope of the rights of the disclosed technology should not be understood as being limited by this.
[0030] A hybrid quantum-resistant cryptography-based forward secrecy-supporting communication device and method according to one embodiment of the present invention can protect subscriber privacy by securely encrypting user identification information based on quantum-resistant cryptography.
[0031] A hybrid quantum-resistant cryptography-based forward secrecy-supporting communication device and method according to one embodiment of the present invention can ensure integrity and prevent replay attacks by performing challenge response authentication using a Milenage Function and a Hash-based Message Authentication Code (HMAC).
[0032] A hybrid quantum-resistant cryptography-based forward secrecy support communication device and method according to one embodiment of the present invention can guarantee forward secrecy and enhance the security of session data by generating and updating a session key using a quantum-resistant cryptography-based key derivation function (PQ-KDF). Brief explanation of the drawing
[0034] FIG. 1 is a diagram illustrating a forward secrecy-supporting communication system according to the present invention. Figure 2 is a diagram illustrating the system configuration of the forward secrecy support communication device of Figure 1. Figure 3 is a diagram illustrating the functional configuration of the forward secrecy support communication device of Figure 1. FIG. 4 is a flowchart illustrating the functional configuration of a forward secrecy support communication device according to the present invention. Figure 5 is a diagram illustrating a hybrid quantum-resistant cryptography-based forward secrecy-supporting 5G authentication protocol (5G-AK-HPQC) in a forward secrecy-supporting communication device. Figure 6 is a diagram illustrating the initiation phase of a hybrid quantum-resistant cryptography-based forward secrecy-supported 5G authentication protocol (5G-AK-HPQC) in a forward secrecy-supported communication device. Figure 7 is a diagram illustrating the challenge-response phase of a hybrid quantum-resistant cryptography-based forward secrecy-supporting 5G authentication protocol (5G-AK-HPQC) in a forward secrecy-supporting communication device. Specific details for implementing the invention
[0035] The description of the present invention is merely an example for structural or functional explanation, and therefore the scope of the present invention should not be interpreted as being limited by the examples described in the text. That is, since the examples are subject to various modifications and may take various forms, the scope of the present invention should be understood to include equivalents capable of realizing the technical concept. Furthermore, the objectives or effects presented in the present invention do not imply that a specific example must include all of them or only such effects; therefore, the scope of the present invention should not be understood as being limited by them.
[0036] Meanwhile, the meaning of the terms described in this application should be understood as follows.
[0037] Terms such as "first," "second," etc., are intended to distinguish one component from another, and the scope of rights shall not be limited by these terms. For example, the first component may be named the second component, and similarly, the second component may be named the first component.
[0038] When it is stated that one component is "connected" to another component, it should be understood that it may be directly connected to that other component, or that there may be other components in between. Conversely, when it is stated that one component is "directly connected" to another component, it should be understood that there are no other components in between. Meanwhile, other expressions describing the relationships between components, such as "between" and "exactly between," or "adjacent to" and "directly adjacent to," should be interpreted in the same way.
[0039] A singular expression should be understood to include a plural expression unless the context clearly indicates otherwise, and terms such as "include" or "have" are intended to specify the existence of the implemented features, numbers, steps, actions, components, parts, or combinations thereof, and should be understood not to preclude the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0040] In each step, identifiers (e.g., a, b, c, etc.) are used for convenience of explanation and do not describe the order of the steps; the steps may occur differently from the specified order unless a specific order is clearly indicated in the context. That is, the steps may occur in the same order as specified, may be performed substantially simultaneously, or may be performed in the reverse order.
[0041] The present invention may be implemented as computer-readable code on a computer-readable recording medium, and the computer-readable recording medium includes all types of recording devices in which data that can be read by a computer system is stored. Examples of computer-readable recording media include ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage device, etc. Additionally, the computer-readable recording medium may be distributed across networked computer systems, so that computer-readable code can be stored and executed in a distributed manner.
[0042] Unless otherwise defined, all terms used herein have the same meaning as generally understood by those skilled in the art to which this invention pertains. Terms defined in commonly used dictionaries should be interpreted as having meanings consistent with the context of the relevant technology and should not be interpreted as having an ideal or overly formal meaning unless explicitly defined in this application.
[0044] FIG. 1 is a diagram illustrating a forward secrecy-supporting communication system according to the present invention.
[0045] Referring to FIG. 1, a forward secrecy-supporting communication system (100) may include a user terminal (110), a forward secrecy-supporting communication device (130), and a database (150).
[0046] A user terminal (110) may be connected via a network with a forward secrecy-supporting communication device (130), receive a secure communication service provided by the forward secrecy-supporting communication device (130), and may be a computing terminal operated by a user. Here, the secure communication service may be a quantum-resistant cryptography-based user authentication and data encryption solution, but is not necessarily limited thereto and may further include session key management, authentication token verification, security authentication receiving key exchange services, privacy protection, and data transmission services.
[0047] The user terminal (110) may be composed of a single or multiple units, and if composed of multiple units, it may include a first user terminal, a second user terminal, ..., and the nth (n is a natural number) user terminal. For example, the user terminal (110) may be implemented as a smartphone, laptop, or computer capable of operating in connection with a forward secrecy support communication device (130), but is not necessarily limited thereto and may be implemented as various devices including a tablet PC, etc.
[0048] Additionally, a user terminal (110) can be connected to a forward secrecy support communication device (130) via a network, and multiple user terminals (110) can be connected to the forward secrecy support communication device (130) simultaneously. The user terminal (110) can install and execute a dedicated program or application for interoperability with the forward secrecy support communication device (130).
[0049] The forward secretion support communication device (130) may be implemented as a server corresponding to a computer or program that performs the forward secretion support communication method according to the present invention. For example, the forward secretion support communication device (130) may be implemented as a server that provides functions for encrypting user identification information based on quantum-resistant cryptography, generating and verifying authentication tokens, and generating and updating session keys, and may enable each step of the forward secretion support communication method according to the present invention to be performed on the server. The forward secretion support communication device (130) may be connected to a user terminal (110) via a wired network or a wireless network such as Bluetooth, WiFi, or LTE, and may transmit and receive data with the user terminal (110) through the wired and wireless network.
[0050] Additionally, the forward confidentiality support communication device (130) may be implemented to operate in connection with an independent external system (not shown in FIG. 1). For example, the forward confidentiality support communication device (130) may operate in conjunction with an ID management and access control system that provides security authentication and privacy protection solutions to users, or in conjunction with an insurance authentication and risk management system that provides insurance transaction security and personal information protection solutions.
[0051] The database (150) may correspond to a storage device that stores various information required during the operation of the forward confidentiality support communication device (130). For example, the database (150) may store security authentication and key management related data such as user authentication information, session keys, and encrypted identifier (SUCI) data, and may store authentication request data, session key update log data, and encrypted communication data generated during the operation of the forward confidentiality support communication device (130), not necessarily limited thereto.
[0052] In FIG. 1, the database (150) is shown as a device independent of the forward confidentiality support communication device (130), but is not necessarily limited thereto and can be implemented by being included in the forward confidentiality support communication device (130).
[0054] Figure 2 is a diagram illustrating the system configuration of the forward secrecy support communication device of Figure 1.
[0055] Referring to FIG. 2, the forward secrecy support communication device (130) may include a processor (210), memory (230), user input / output unit (250), network input / output unit (270), and communication port unit (290).
[0056] The processor (210) can execute a forward secret support communication procedure according to an embodiment of the present invention, manage memory (230) that is read or written during this process, and schedule the synchronization time between volatile memory and non-volatile memory in memory (230). The processor (210) can control the overall operation of the forward secret support communication device (130) and can control the data flow between memory (230), user input / output unit (250), and network input / output unit (270) by being electrically connected to them. The processor (210) can be implemented as a CPU (Central Processing Unit) or GPU (Graphics Processing Unit) of the forward secret support communication device (130).
[0057] The memory (230) may include an auxiliary storage device implemented as non-volatile memory such as an SSD (Solid State Disk) or HDD (Hard Disk Drive) and used to store all data required for the forward secrecy support communication device (130), and may include a main memory device implemented as volatile memory such as RAM (Random Access Memory). Additionally, the memory (230) may store a set of instructions that execute the forward secrecy support communication method according to the present invention by being executed by an electrically connected processor (210).
[0058] The user input / output unit (250) includes an environment for receiving user input and an environment for outputting specific information to the user, and may include an input device including an adapter such as a touch pad, touch screen, virtual keyboard, or pointing device, and an output device including an adapter such as a monitor or touch screen. In one embodiment, the user input / output unit (250) may correspond to a computing device connected via remote access, and in such case, the forward secrecy support communication device (130) may be performed as an independent server.
[0059] The network input / output unit (270) provides a communication environment for connecting to a user terminal (110) through a network and may include an adapter for communication such as a LAN (Local Area Network), MAN (Metropolitan Area Network), WAN (Wide Area Network), and VAN (Value Added Network). Additionally, the network input / output unit (270) may be implemented to provide short-range communication functions such as WiFi and Bluetooth, or wireless communication functions of 4G or higher, for wireless transmission of data.
[0060] The communication port section (290) can be implemented as a port mapping table that performs data routing during the process of transmitting and receiving data through a network. Here, the communication port section (290) can distinguish communication sessions between the user terminal (110) and the server and prevent data collisions during the process of transmitting and receiving data by assigning a unique source port to the user terminal (110).
[0062] Figure 3 is a diagram illustrating the functional configuration of the forward secrecy support communication device of Figure 1.
[0063] Referring to FIG. 3, the forward secrecy support communication device (130) may include a subscription encryption identification unit (310), a challenge response authentication unit (330), a forward secrecy support unit (350), and a control unit (370).
[0064] The forward secrecy support communication device (130) does not need to include all of the above functional configurations simultaneously, and depending on each embodiment, some of the above configurations may be omitted, or some or all of the above configurations may be selectively included. Additionally, the forward secrecy support communication device (130) may be implemented as an independent module that selectively includes some of the above configurations, and the forward secrecy support communication method according to the present invention may be performed through the interoperability between each module. The operation of each configuration is described in detail below.
[0066] The subscription encryption identification unit (310) can generate a subscriber's identification information (SUCI, Subscription Concealed Identifier) by performing quantum-resistant cryptography-based encryption on a user identifier and transmit the subscriber's identification information (SUCI) to a user terminal (110). Here, the user identifier may correspond to data for uniquely identifying a specific user, and may include, for example, an International Mobile Subscriber Identity (IMSI) and a Temporary Mobile Subscriber Identity (TMSI). Additionally, the subscriber's identification information may correspond to identification information protected by performing encryption on the user identifier. The subscription encryption identification unit (310) can collect user identifiers from a mobile communication network including a base station, a mobile communication operator's core network (Home Network, HN), a subscriber database, and an authentication server, and perform encryption on the user identifiers by applying a quantum-resistant cryptography algorithm. The subscription encryption identification unit (310) can transmit the generated subscriber's identification information to a user terminal (110) so that it can be used in the authentication process with the network. Here, the subscription encryption identification unit (310) can prevent the subscriber's identification information from being traced back through traffic analysis by applying techniques such as adding random padding or applying homomorphic encryption during the process of transmitting the subscriber's identification information to the user terminal (110).
[0067] In one embodiment, the subscription encryption identification unit (310) can set an encryption method according to the network type to which the user terminal (110) is connected. Here, the subscription encryption identification unit (310) can check the network type to which the user terminal (110) is connected and select and apply an appropriate encryption method according to the network type. For example, in the case of a 5G network, the subscription encryption identification unit (310) can apply encryption to the subscriber's identification information according to the 3GPP standard, and in addition, in a Wi-Fi environment, it can perform encryption by applying PQC-TLS, which combines TLS 1.3 and quantum-resistant cryptography.
[0068] In one embodiment, the subscription encryption identification unit (310) can encrypt the subscriber's identification information (SUCI) with a public key and transmit it to the user terminal (110). Here, the subscription encryption identification unit (310) can acquire a quantum-resistant cryptographic-based public key from a mobile communication network and collect a user identifier (SUPI, SUbscription Permanent Identifier) when the user terminal (110) is connected to the network. The subscription encryption identification unit (310) can perform encryption on the user identifier (SUPI) using the acquired public key and convert the encrypted data into the subscriber's identification information (SUCI). In one embodiment, the subscription encryption identification unit (310) can periodically update the public key during the process of encrypting the subscriber's identification information (SUCI) with a public key. For example, the subscription encryption identification unit (310) can periodically update the public key by dynamically distributing the key in conjunction with a Key Management System (KMS).
[0069] In one embodiment, the subscription encryption identifier (310) can generate a public key using a quantum-resistant cryptography-based key exchange algorithm. The quantum-resistant cryptography-based key exchange algorithm may include, for example, a lattice-based key exchange, a code-based key exchange, and a multivariate polynomial-based key exchange. The subscription encryption identifier (310) can generate a public key and a private key pair based on the quantum-resistant cryptography-based key exchange algorithm. For example, the subscription encryption identifier (310) can generate a public key / private key pair using a quantum-resistant cryptography-based key exchange algorithm including Kyber, FrodoKEM, and Classic McEliece. Here, the generated public key can be used to encrypt the user identifier (SUPI) to generate the subscriber's identification information (SUCI), and the private key can also be used for decryption at the network authentication server.
[0070] In one embodiment, the subscription encryption identification unit (310) can support the protection of a subscriber's privacy by performing quantum-resistant cryptography-based encryption by performing lattice-based encryption to encrypt a user identifier. Here, lattice-based encryption may correspond to a public-key encryption method using a lattice mathematical structure, and, for example, encryption of the user identifier can be performed by applying a lattice-based encryption technique including the Learning With Errors (LWE). The subscription encryption identification unit (310) can generate a ciphertext by collecting the user identifier of a user terminal (110) in a mobile communication network and performing lattice-based encryption to add a random error value. For example, the subscription encryption identification unit (310) can enhance the security of the ciphertext by adding a random error value by applying the Learning With Errors (LWE), and can also generate subscriber identification information (SUCI) that is secure against specific attack situations by encrypting the user identifier (SUPI) using a public-key encryption method (RLWE, NTRU, etc.).
[0071] In one embodiment, the subscription encryption identification unit (310) can implement public key encryption by performing a quantum-resistant cryptography-based encapsulation algorithm (KEM, Key Encapsulation Mechanism) to generate subscriber identification information (SUCI). Here, the quantum-resistant cryptography-based encapsulation algorithm (KEM) may correspond to an encryption technique for protecting a session key, and, for example, may be used in conjunction with a specific public key encryption method to perform the role of performing encrypted data exchange more securely. The subscription encryption identification unit (310) can generate a highly secure session key based on the quantum-resistant cryptography-based encapsulation algorithm (KEM) and encapsulate the encapsulated session key using a public key by performing encapsulation. Additionally, the subscription encryption identification unit (310) can encrypt the encapsulated ciphertext using a public key encryption method and safely transmit it to a user terminal (110) or a network authentication server (AUSF), and can decrypt the encapsulated ciphertext to extract the session key and perform secure communication using it. That is, the subscription encryption identification unit (310) can perform secure authentication in the network by performing a quantum-resistant cryptography-based encapsulation algorithm (KEM, Key Encapsulation Mechanism) to securely encapsulate the session key or encrypted data and protect it through public key encryption.
[0072] The challenge response authentication unit (330) can generate a random number (RAND) and provide it to the user terminal (110), and input the random number (RAND) into a Milenage Function to generate an authentication token (AUTN). Here, the Milenage Function may correspond to a 3G / 4G / 5G mobile communication network authentication algorithm defined by 3GPP, and, for example, may be utilized in the process of authenticating the user terminal (110) in the network. Additionally, the authentication token may correspond to a data block generated to perform authentication of the user terminal (110) in the network. The challenge response authentication unit (330) can generate an authentication token by generating a random number and inputting the random number (RAND) and a network security key using a Milenage Function. The challenge response authentication unit (330) can transmit the authentication token and the random number to the user terminal (110), whereby the user terminal (110) can perform network authentication by verifying the received authentication token. When network authentication is performed correctly, the user terminal (110) can transmit a response value to the network to perform authentication as to whether it is a legitimate subscriber, and the challenge response authentication unit (330) can compare the response value received from the user terminal (110) with the expected response value calculated from the network, and if the response value and the expected response value match, it can authenticate as a legitimate subscriber. Here, if the response value and the expected response value do not match, the challenge response authentication unit (330) can determine that network authentication has failed.
[0073] In one embodiment, the challenge response authentication unit (330) may generate a Message Authentication Code (MAC) based on a secret key to generate a random number (RAND) and an authentication token (AUTN). Here, the Message Authentication Code may correspond to a code generated to ensure the integrity and authentication of data transmitted over a network, and may, for example, be generated based on a secret key. The challenge response authentication unit (330) may generate a random 128-bit random number (RAND) and provide it to the user terminal (110), and generate a Message Authentication Code (MAC) using the secret key (K) and the random number (RAND). Additionally, the challenge response authentication unit (330) may generate an authentication token (AUTN) by combining the generated Message Authentication Code, the Sequence Number (SQN), and the Authentication Management Field (AMF). The challenge response authentication unit (330) can extract a message authentication code from an authentication token through the user terminal (110) and perform a comparison with a message authentication code calculated internally to determine whether the network is trusted based on whether the message authentication code values match. That is, the challenge response authentication unit (330) can ensure the integrity and reliability of data transmitted during the authentication process by utilizing the message authentication code, and can enable the user terminal (110) to verify that the random number (RAND) and authentication token (AUTN) transmitted by the network have not been tampered with.
[0074] In one embodiment, the challenge response authentication unit (330) can ensure the integrity of the authentication process and prevent replay attacks by additionally performing a Hash-based Message Authentication Code (HMAC) after the execution of the Milenage Function to generate an authentication token (AUTN). Here, the HMAC may correspond to a Message Authentication Code (MAC) algorithm that verifies the integrity and authentication of a message using a secret key, and, for example, can perform the role of verifying that data transmitted over a network has not been tampered with. The challenge response authentication unit (330) can generate a random number and generate an authentication token and a response value based on the Milenage Function, and then use the HMAC to protect the integrity of the authentication token. For example, the challenge response authentication unit (330) can enhance security by re-performing the Message Authentication Code operation on the authentication token generated through the Milenage Function. In one embodiment, the challenge response authentication unit (330) can further secure security by applying HMAC to the authentication data generated by the millenage function to enhance message integrity and prevent attacks attempting to reuse previous authentication messages.
[0075] In one embodiment, the challenge response authentication unit (330) can perform additional quantum-resistant cryptography-based signature verification on the authentication token (AUTN) after performing HMAC to enhance the integrity and reliability of the authentication data. For example, the challenge response authentication unit (330) can generate a signature for the authentication token by performing verification based on a quantum-resistant cryptography-based signature including CRYSTALS-Dilithium, SPHINCS+, and Falcon. The challenge response authentication unit (330) can transmit the generated authentication token and the signature value of the authentication token to a user terminal (110) and allow the user terminal (110) to perform signature verification using the network's public key. Here, if the signature verification is successful, it can be confirmed that the authentication token has not been tampered with and that the network is a trusted authentication authority; conversely, if it is unsuccessful, it may mean that the authentication token has been tampered with or that an attacker has tampered with the authentication information. That is, the challenge response authentication unit (330) can perform integrity verification in the authentication process and strengthen reliability by additionally performing quantum-resistant cryptography-based signature verification on the authentication token (AUTN) after the execution of HMAC, and can maintain authentication security in a quantum computer environment by adding quantum-resistant cryptography-based digital signature verification in addition to the existing authentication data protection method using HMAC.
[0076] The forward secrecy support unit (350) can communicate with the user terminal (110) by encrypting session data based on an authentication token (AUTN). Here, forward secrecy (FS) may correspond to a characteristic in which the security of a subsequent session is maintained even if the encryption key of a previous session is leaked. The forward secrecy support unit (350) can generate a session key based on the authentication token (AUTN) and encrypt session data using symmetric key encryption algorithms such as AES-GCM and ChaCha20-Poly1305 based on the session key. In one embodiment, the forward secrecy support unit (350) can prevent security leakage resulting from the leakage of a previous session key by discarding the previous session key and updating it by dynamically generating a new session key when a certain amount of time has passed or when the amount of data transmission exceeds a certain threshold.
[0077] In one embodiment, the forward secretivity support unit (350) can generate a session key by inputting an authentication token (AUTN) into a quantum-resistant cryptography-based key derivation function (PQ-KDF, Post-Quantum Key Derivation Function) and encrypt session data using the session key. Here, the forward secretivity support unit (350) can generate a session key by inputting an authentication token into a quantum-resistant key derivation function and encrypt session data in communication with a user terminal (110) based on the generated session key. The forward secretivity support unit (350) can ensure the randomness of the session key and enhance security by using a random number (RAND) and additional key material together during the process of inputting the authentication token into the quantum-resistant key derivation function.
[0078] In one embodiment, the forward secretability support unit (350) can strengthen the strength and randomness of the session key by additionally inputting a random number (RAND) and a key material provided by the user terminal (110) in addition to the authentication token (AUTN) to generate a session key. Here, the key material may correspond to input data used in the process of generating and deriving cryptographic keys, and may correspond to, for example, elements utilized to strengthen the security and randomness of the session key or cryptographic key. The forward secretability support unit (350) can generate additional randomness by utilizing unique information and security elements from the user terminal (110) as key materials. For example, the forward secretability support unit (350) can strengthen the strength and randomness of the session key by generating additional randomness using unique information including IMEI (International Mobile Equipment Identity), MAC (Media Access Control) address, and UUID (Universally Unique Identifier), and security elements such as a hardware security module from the user terminal (110) as key materials.
[0079] In one embodiment, the forward confidentiality support unit (350) can dynamically set the session key update cycle according to a certain time or data transmission amount and transmit the updated session key to the user terminal (110). Here, the forward confidentiality support unit (350) can set the session key to change automatically after a certain time has elapsed, for example, the session key can be updated in units of minutes to hours. In addition, the forward confidentiality support unit (350) can automatically generate a new session key when a specific data transmission amount is exceeded. For example, the forward confidentiality support unit (350) can update the session key by setting a data transmission amount exceedance threshold as a condition for updating the session key and continuously monitoring the data transmission amount exceedance threshold to generate a key update trigger when a specific data amount is exceeded.
[0080] In one embodiment, the forward secretion support unit (350) may dynamically update the session key based on network conditions including the security status of the network, signal quality, and packet loss rate. For example, the forward secretion support unit (350) may be configured to automatically update the session key when a handover occurs in a 5G network, and may be configured to update the session key when a security event (e.g., a Man-In-The-Middle attack) occurs in the network, not necessarily limited to this. Additionally, the forward secretion support unit (350) may update the session key when a user accesses a new network or changes base stations.
[0081] In one embodiment, the forward secretivity support unit (350) can dynamically adjust the update conditions by analyzing the network status and the data throughput of the user terminal (110) in real time to set the update cycle of the session key. Here, the forward secretivity support unit (350) can detect an excess of data transmission volume by tracking the total amount of data transmitted so far in real time through network traffic monitoring and generating a session key update trigger when the user exceeds a specific amount of data. Additionally, the forward secretivity support unit (350) can record the amount of data transmitted encrypted using the session key after the session key is assigned to the user terminal (110), and perform a new session key generation process when it exceeds a specific threshold (e.g., 500MB, 1GB, 5GB).
[0082] The control unit (370) controls the overall operation of the forward secrecy support communication device (130) and can manage the control flow or data flow between the subscription encryption identification unit (310), the challenge response authentication unit (330), and the forward secrecy support unit (350).
[0084] FIG. 4 is a flowchart illustrating the functional configuration of a forward secrecy support communication device according to the present invention.
[0085] Referring to FIG. 4, the forward secrecy-supporting communication device (130) can perform quantum-resistant cryptographic-based encryption on a user identifier based on the subscription encryption identification unit (310) to generate subscriber identification information (SUCI, Subscription Concealed Identifier) and transmit the subscriber identification information (SUCI) to the user terminal (110) (step S410). The forward secrecy-supporting communication device (130) can generate a random number (RAND) based on the challenge response authentication unit (330) and provide it to the user terminal (110), and input the random number (RAND) into a Milenage Function to generate an authentication token (AUTN) (step S430).
[0086] The forward secretion support communication device (130) can communicate with the user terminal (110) by encrypting session data based on an authentication token (AUTN) based on the forward secretion support unit (350) (step S450). Here, the forward secretion support communication device (130) generates a session key by inputting the authentication token into a quantum-resistant cryptography-based key derivation function and encrypts session data through the session key, thereby maintaining the security of subsequent sessions even if the previous session key is leaked, and protecting data from Man-in-the-Middle (MITM) attacks and eavesdropping.
[0088] Figure 5 is a diagram illustrating a hybrid quantum-resistant cryptography-based forward secrecy-supporting 5G authentication protocol (5G-AK-HPQC) in a forward secrecy-supporting communication device.
[0089] In FIG. 5, the forward secrecy-supporting communication device (130) may include a process similar to the existing authentication protocol 5G-AKA, which is a hybrid quantum-resistant cryptography-based forward secrecy-supporting 5G authentication protocol (hereinafter, 5G-AKA-HPQC). First, the forward secrecy-supporting communication device (130) can identify a user terminal (110) by utilizing a Subscription Concealed Identifier (SUCI) in the Initiation Phase. Here, once the identification of the user terminal (110) is complete, the forward secrecy-supporting communication device (130) can generate a Challenge value by utilizing a Long-Term Key (K), which is a secret value shared with the user terminal (110) in the network. The Challenge value may correspond to a Random Number (RAND), and the user terminal (110) can generate and transmit a Response (RES) based on the Long-Term Key (K) and the Random Number (RAND) it possesses. The network authenticates the user terminal (110) by verifying the response value, whereas the user terminal (110) can authenticate the network by verifying the network's authentication token (AUTN). The forward secretive support communication device (130) can provide secure communication by performing mutual authentication between the user terminal (110) and the network through the process of generating a challenge value and verifying the response value, while simultaneously performing a key exchange process.
[0091] Figure 6 is a diagram illustrating the initiation phase of a hybrid quantum-resistant cryptography-based forward secrecy-supported 5G authentication protocol (5G-AK-HPQC) in a forward secrecy-supported communication device.
[0092] In FIG. 6, a forward secrecy-supporting communication device (130) can perform the initiation step of a hybrid quantum-resistant cryptography-based forward secrecy-supporting 5G authentication protocol (5G-AK-HPQC) based on the X-Wing encapsulated public key of a home network through a user terminal (110). Here, the forward secrecy-supporting communication device (130) can generate a private key and a public key based on an X-Wing key generation algorithm based on the user terminal (110). Then, the forward secrecy-supporting communication device (130) can generate a seed value by applying a Shake256 hash function to the private key as input.
[0093] In one embodiment, the forward secretability supporting communication device (130) can generate a secret key and an encapsulation value through an X-Wing encapsulated public key and a seed value, and generate a session key using a key derivation function (KDF) with the secret key as input. Additionally, the forward secretability supporting communication device (130) can divide the generated session key into k1 and k2 and divide the public key into pk1 and pk2. The forward secretability supporting communication device (130) can set the encapsulation value to C0 and generate encrypted data C1 by encrypting the subscriber permanent identifier (SUPI) and pk1 through k1. Additionally, the forward secretability supporting communication device (130) can generate a tag C2 to verify the integrity of C1 using k2 and transmit the generated subscriber identification information (SUCI) to the network.
[0094] Next, the forward secretability support communication device (130) can receive subscriber identification information from the user terminal (110) via the serving network (SN) and transmit the received subscriber identification information and the identifier of the serving network to the home network. The forward secretability support communication device (130) can receive the subscriber identification information and the identifier of the serving network from the home network and separate the subscriber identification information into C0, C1, and C2. Here, the forward secretability support communication device (130) can restore the secret key using C0 and the secret key of the home network and generate a home network session key (kHN) by applying a key derivation function with the restored secret key as input. The forward secretive support communication device (130) can separate kHN into kHN1k and kHN2k, verify integrity by comparing C2 with the message authentication code (MAC), output an error if integrity is not verified, and perform decryption if integrity is verified to restore the user identifier and the public key pk1UE of the user terminal (110).
[0096] Figure 7 is a diagram illustrating the challenge-response phase of a hybrid quantum-resistant cryptography-based forward secrecy-supporting 5G authentication protocol (5G-AK-HPQC) in a forward secrecy-supporting communication device.
[0097] In FIG. 7, the forward secretability supporting communication device (130) can generate an authentication vector based on a shared secret value received from a user terminal (110) in a home network (HN). Here, the forward secretability supporting communication device (130) can extract a portion of the public key and encapsulation value (C0) of the user terminal (110) in the home network to set the public key PKue of the user terminal (110), and use PKue to generate an encapsulated secret key and an encapsulation value CHN. Here, the encapsulation value CHN can be set as a random number (RAND). The forward secretability supporting communication device (130) can generate an encryption derived key HPK through a key derivation function with sSHN as input, and then generate a message authentication code to calculate an anonymity key AK.
[0098] In one embodiment, the forward secret support communication device (130) can generate an encryption key (CK), an integrity key (IK), and an expected response value (XRES), and calculate an extended expected response value (XRES*) based thereon. The forward secret support communication device (130) can process the random number (RAND) and the extended expected response value (XRES*) with a SHA-256 hash function to set the upper 128 bits as a hash-based extended response value (HXRES*). The forward secret support communication device (130) can calculate an authentication server key (Kausf) and a SEAF key, generate a serving network authentication vector (SE-AV), and transmit it to the serving network.
[0099] Here, the forward secrecy support communication device (130) is An authentication vector can be received from a home network via a serving network (SN). Here, a forward secret support communication device (130) can store a random number (RAND) and a hash-based extended response value (HXRES*) from the serving network and transmit the random number and the authentication token to a user terminal (110). Then, the forward secret support communication device (130) can transmit the random number and the authentication token received from the serving network to a SIM card based on the user terminal (110). Here, the forward secret support communication device (130) A secret value can be decrypted using a random number and a user private key based on a SIM card, and a cryptographic derived key (HPK) can be generated through a key derivation function (KDF) using the decrypted secret value as input. A forward secretion-supporting communication device (130) can execute an authentication command using a random number, a cryptographic derived key, and an authentication token based on a SIM card.
[0100] For example, the forward secretion support communication device (130) can calculate an anonymity key AK based on a SIM card and separate the authentication token by component (CONC, authentication management field (AMF), and message authentication code (MAC)). Here, the forward secretion support communication device (130) can perform an XOR operation on the anonymity key (AK) and CONC to restore the home network sequence number (SQNHN) value and verify the message authentication code (MAC) by checking the validity of the user terminal (110) sequence number (SQNUE) and the home network sequence number (SQNHN). If the verification is successful, the forward secretion support communication device (130) can generate an encryption key (CK), an integrity key (IK), and a response (RES) and return them to the user terminal (110).
[0101] The forward secretion support communication device (130) can calculate an extended response value (RES*) by inputting an encryption key (CK), an integrity key (IK), a network identifier (IDSN), a random number (RAND), and a response value (RES) through a user terminal. The forward secretion support communication device (130) can generate and store an authentication server key (KAUSF) and a SEAF key, and transmit the extended response value (RES*) to a serving network through the user terminal (110).
[0103] Although the present invention has been described above with reference to preferred embodiments, those skilled in the art will understand that various modifications and changes can be made to the invention without departing from the spirit and scope of the invention as described in the following claims. Explanation of the symbols
[0105] 100: Forward Confidentiality Supported Communication System 110: User terminal 130: Forward secrecy support communication device 150: Database 210: Processor 230: Memory 250: User I / O 270: Network I / O Section 290: Communication port section 310: Subscription Encryption Identifier 330: Challenge Response Authentication Department 350: Forward Confidentiality Support Unit 370: Control unit
Claims
Claim 1 A hybrid quantum-resistant cryptography-based forward secrecy support communication device comprising: a subscription encryption identification unit that generates a subscriber's identification information (SUCI, Subscription Concealed Identifier) by performing quantum-resistant cryptography-based encryption on a user identifier and transmits the subscriber's identification information (SUCI) to a user terminal; a challenge response authentication unit that generates a random number (RAND) and provides it to the user terminal, and inputs the random number (RAND) into a Milenage Function to generate an authentication token (AUTN); and a forward secrecy support unit that encrypts session data based on the authentication token (AUTN) and communicates with the user terminal. Claim 2 A hybrid quantum-resistant cryptography-based forward secrecy-supporting communication device according to claim 1, wherein the subscription encryption identification unit encrypts the subscriber's identification information (SUCI) with a public key and transmits it to the user terminal. Claim 3 A hybrid quantum-resistant cryptography-based forward secrecy-supporting communication device according to paragraph 2, wherein the subscription encryption identification unit generates the public key using the quantum-resistant cryptography-based key exchange algorithm. Claim 4 A hybrid quantum-resistant cryptography-based forward secrecy-supporting communication device according to claim 1, wherein the subscription encryption identifier supports the protection of the subscriber's privacy by performing lattice-based encryption to encrypt the user identifier and performing quantum-resistant cryptography-based encryption, and wherein the lattice-based encryption utilizes the Learning With Errors (LWE) problem. Claim 5 A hybrid quantum-resistant cryptography-based forward secrecy-supporting communication device according to claim 1, wherein the subscription encryption identification unit implements public key encryption by performing the quantum-resistant cryptography-based encapsulation algorithm (KEM, Key Encapsulation Mechanism) to generate the subscriber identification information (SUCI). Claim 6 A hybrid quantum-resistant cryptography-based forward secrecy-supporting communication device according to claim 1, wherein the challenge response authentication unit generates a Message Authentication Code (MAC) based on a secret key to generate the random number (RAND) and the authentication token (AUTN). Claim 7 A hybrid quantum-resistant cryptography-based forward secrecy-supporting communication device according to claim 6, characterized in that the challenge response authentication unit guarantees the integrity of the authentication process and prevents replay attacks by additionally performing a Hash-based Message Authentication Code (HMAC) after the execution of the Milenage Function to generate the authentication token (AUTN). Claim 8 A hybrid quantum-resistant cryptography-based forward secrecy-supporting communication device according to claim 7, wherein the challenge response authentication unit additionally performs quantum-resistant cryptography-based signature verification on the authentication token (AUTN) after the execution of the HMAC to enhance the integrity and reliability of the authentication data. Claim 9 A hybrid quantum-resistant cryptography-based forward secretion support communication device according to claim 1, wherein the forward secretion support unit inputs the authentication token (AUTN) into the quantum-resistant cryptography-based key derivation function (PQ-KDF, Post-Quantum Key Derivation Function) to generate a session key and encrypts the session data through the session key. Claim 10 A hybrid quantum-resistant cryptography-based forward secrecy support communication device according to claim 9, wherein the forward secrecy support unit additionally inputs the random number (RAND) and the key material provided by the user terminal in addition to the authentication token (AUTN) to generate the session key, thereby enhancing the strength and randomness of the session key. Claim 11 A hybrid quantum-resistant cryptography-based forward secrecy support communication device according to claim 1, wherein the forward secrecy support unit dynamically sets the update cycle of the session key according to a certain time or data transmission amount and transmits the updated session key to a user terminal. Claim 12 A hybrid quantum-resistant cryptography-based forward secrecy support communication device according to claim 11, wherein the forward secrecy support unit dynamically adjusts update conditions by analyzing the network status and the data throughput of the user terminal in real time to set the update cycle of the session key. Claim 13 A hybrid quantum-resistant cryptography-based forward secrecy support communication method performed in a hybrid quantum-resistant cryptography-based forward secrecy support communication device, comprising: a subscription encryption identification step of generating a subscriber's identification information (SUCI, Subscription Concealed Identifier) by performing quantum-resistant cryptography-based encryption on a user identifier and transmitting said subscriber's identification information (SUCI) to a user terminal; a challenge response authentication step of generating a random number (RAND) and providing it to said user terminal, and inputting said random number (RAND) into a Milenage Function to generate an authentication token (AUTN); and a forward secrecy support step of encrypting session data based on said authentication token (AUTN) and communicating with said user terminal. Claim 14 A hybrid quantum-resistant cryptography-based forward secrecy-supported communication method according to claim 13, wherein the subscription encryption identification step comprises the step of encrypting the subscriber's identification information (SUCI) with a public key and transmitting it to the user terminal. Claim 15 A hybrid quantum-resistant cryptography-based forward secrecy-supporting communication method, wherein, in claim 13, the challenge response authentication step comprises a step of generating a Message Authentication Code (MAC) based on a secret key to generate the random number (RAND) and the authentication token (AUTN). Claim 16 A hybrid quantum-resistant cryptography-based forward secretion support communication method according to claim 13, wherein the forward secretion support step comprises the step of inputting the authentication token (AUTN) into the quantum-resistant cryptography-based key derivation function (PQ-KDF, Post-Quantum Key Derivation Function) to generate a session key and encrypting the session data through the session key.