Method and apparatus for selecting security profile in wireless communication system

By introducing a UICC-based PQC or traditional profile selection process in the UE, and combining AI/ML to dynamically select security profiles, the compatibility problem of traditional algorithms and PQC algorithms in 5G systems is solved, and the security and user privacy protection of wireless communication systems are improved.

CN120283381APending Publication Date: 2025-07-08SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380085084.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-19
Filing Date
2023-12-12
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In the prior art, 5G wireless communication systems cannot dynamically select security profiles that adapt to traditional and post-quantum cryptography algorithms, resulting in the possible failure of the authentication process between the UE and the network, delay registration and inability to effectively maintain user privacy.

Method used

By introducing UICC-based post-quantum cryptography (PQC) or traditional profile selection process in user equipment (UE), combining artificial intelligence (AI) and machine learning (ML), dynamically selecting and updating security profiles, supporting traditional and PQC algorithms, optimize security profile selection between UE and the network.

Benefits of technology

It realizes better security and user privacy protection in wireless communication systems, dynamically selects security profiles that are adapted to different network environments, reduces latency in the authentication process, and improves the registration success rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120283381A_ABST
    Figure CN120283381A_ABST
Patent Text Reader

Abstract

The present disclosure relates to a 5G communication system or a 6G communication system for supporting a higher data rate than a 4G communication system such as Long Term Evolution (LTE). Embodiments disclosed herein relate to methods and systems for selecting a security profile in a communication network. More specifically, embodiments disclosed herein relate to methods (500, 900, 2200) and systems (200) for performing a security profile selection procedure for a wireless communication network. The proposed method (500, 900, 210) provides for post quantum cryptography (PQC) or quantum cryptography based secure profile selection in a wireless communication network. The method (500, 900, 2210) discloses a plurality of post quantum based security profiles in a User Equipment (UE) (202), and mechanisms and processes involved in security profile selection, primarily for maintaining user privacy in an initial authentication process between the UE (202) and a communication network (204). The selected security profile may be further used for data encryption between the UE (202) and the communication network (204). The mechanism can dynamically select a security profile that can provide better security in a given network environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments disclosed herein relate to wireless communication networks, and more particularly, to methods and systems for performing a security profile selection process for a wireless communication network. Background Art

[0002] Considering the development of wireless communication technologies from generation to generation, these technologies have been mainly developed for human-oriented services such as voice calls, multimedia services, and data services. With the commercialization of 5G (fifth generation) communication systems, the number of connected devices is expected to grow exponentially. These devices are increasingly connected to communication networks. Examples of connected devices can include vehicles, robots, drones, household appliances, displays, smart sensors connected to various infrastructures, construction machinery, and factory equipment. Mobile devices are expected to evolve into various forms such as augmented reality glasses, virtual reality headsets, and holographic devices. In order to provide various services in the 6G (sixth generation) era by connecting hundreds of billions of devices and things, efforts have been made to develop improved 6G communication systems. Therefore, 6G communication systems are called ultra-5G systems.

[0003] It is expected that 6G communication systems will be commercialized around 2030, with a peak data rate reaching tera (1000 giga) - level bps and a radio latency of less than 100 microseconds. Thus, the speed will be 50 times that of 5G communication systems, and the radio latency will be only one - tenth of it.

[0004] To achieve such high data rates and ultra - low latency, it is considered to implement 6G communication systems in the terahertz frequency band (e.g., 95 GHz to 3 THz band). Since the terahertz frequency band has more severe path loss and atmospheric absorption than the millimeter - wave band introduced in 5G, technologies that can ensure the signal transmission distance (i.e., coverage) are expected to become more critical. As the main technologies for ensuring coverage, it is necessary to develop: radio frequency (RF) components, antennas, new waveforms with better coverage than orthogonal frequency - division multiplexing (OFDM), beamforming, and massive multiple - input multiple - output (MIMO), full - dimensional MIMO (FD - MIMO), array antennas, and large - scale antennas and other multi - antenna transmission technologies. In addition, new technologies for improving the signal coverage in the terahertz frequency band have been discussed, such as metasurface - based lenses and antennas, orbital angular momentum (OAM), and reconfigurable intelligent surfaces (RIS).

[0005] In addition, to improve spectral efficiency and overall network performance, the following technologies have been developed for 6G communication systems: full-duplex technology that enables uplink and downlink transmissions to use the same frequency resources simultaneously; network technologies for comprehensively utilizing satellites, high-altitude platform stations (HAPS), etc.; improved network architectures for supporting mobile base stations, etc. and achieving optimization and automation of network operations; conflict avoidance dynamic spectrum sharing technology based on spectrum usage prediction; use of artificial intelligence (AI) in wireless communication from the design stage of developing 6G to improve overall network operations and built-in end-to-end AI support functions; and next-generation distributed computing technology for overcoming the limitations of UE computing capabilities through ultra-high-performance communication and computing resources accessible on the network, such as mobile edge computing (MEC), cloud, etc. In addition, by designing new protocols for 6G communication systems, developing hardware-based security environments and data security usage mechanisms, and developing privacy-preserving technologies, efforts have been made to strengthen connectivity between devices, optimize the network, promote the softwareization of network entities, and improve the openness of wireless communication.

[0006] It is expected that in the field of hyper-connectivity including person-to-machine (P2M) and machine-to-machine (M2M), the research and development of 6G communication systems will bring the next hyper-connectivity experience. In particular, it is expected that services such as truly immersive extended reality (XR), high-fidelity mobile holograms, and digital replicas can be provided through 6G communication systems. In addition, services such as remote surgery, industrial automation, and emergency response for enhancing security and reliability will also be provided through 6G communication systems, enabling these technologies to be applied in various fields such as industry, healthcare, automotive, and home appliances. Summary of the Invention

[0007] Technical Problem

[0008] The main objective of the embodiments herein is to disclose a method and system for performing a security profile selection process for a wireless communication network.

[0009] Another objective of the embodiments herein is to disclose a method and system for security profile selection based on post-quantum cryptography (PQC) or quantum cryptography in a wireless communication network.

[0010] Another objective of the embodiments herein is to disclose a method and system for disclosing multiple post-quantum-based security profiles in a user equipment (UE) and the mechanisms and processes involved in security profile selection, which are mainly used to maintain user privacy during the initial authentication process between the UE and the network.

[0011] Another objective of the embodiments herein is to disclose a mechanism for dynamically selecting a security profile that can provide better security in a given network environment.

[0012] Another objective of the embodiments of this document is to disclose a method and system for a signaling process that defines a profile selection process between a UE and a network through core network, SIM pre-provisioning-based, bearer-independent, and machine learning-based post-quantum era security profile selection.

[0013] The present invention aims to at least solve the above problems and / or disadvantages and at least provide the effects described below. Accordingly, one aspect of the present invention provides a method and apparatus for selecting a security profile in a wireless communication system.

[0014] Solution

[0015] Accordingly, embodiments of this document provide a method for selecting a security profile in a communication network. The method includes: a user equipment (UE) receives a new network service configuration of a universal integrated circuit card (UICC) from a communication network. The UICC may include, but is not limited to, (Subscriber Identity Module) (SIM), Universal Subscriber Identity Module (USIM), embedded SIM (eSIM), integrated SIM, etc. The UICC is configured with new network services by the communication network during pre-provisioning. The method further includes: the UE configures at least one security profile identifier in one of the UE and the UICC for adding at least one security profile in a priority order. The method further includes: the UE selects a security profile based on the configured new network service using the configured security profile identifier.

[0016] Accordingly, embodiments of this document provide a UE having a processor. The processor is configured to receive a new network service configuration of a UICC from a communication network. The UICC is configured with new network services by the communication network during pre-provisioning. The processor is configured to configure at least one security profile identifier in one of the UE and the UICC for adding at least one security profile in a priority order. The processor is configured to select a security profile based on the new network service using the configured security profile identifier.

[0017] Accordingly, embodiments of this document provide a method for selecting a security profile in a communication network. The method includes: the UE receives a message from the communication network. The message includes at least one of a security support indication and a security profile indication supported by the communication network. The method further includes: the UE updates at least one security profile supported by the UE based on the received message. The method further includes: the UE uses the updated security profile to send a registration request having at least one of user identity encryption and UE data encryption to the communication network.

[0018] Accordingly, an embodiment of the present disclosure provides a UE having a processor. The processor is configured to receive a message from a communication network. The message includes at least one of a security support indication and a security profile indication supported by the communication network. The processor is configured to update at least one security profile supported by the UE based on the received message. The processor is configured to use the updated security profile to send a registration request including at least one of user identity encryption and UE data encryption to the communication network.

[0019] Accordingly, an embodiment of the present disclosure provides a method for selecting a PQC profile in a communication network. The method includes: The UE creates and trains an AI-based model using at least one input including one of one or more UE parameters, one or more network parameters, and one or more application parameters. The method further includes: The UE learns at least one PQC profile using the trained AI-based model. The PQC profile may include, but is not limited to, a quantum key distribution (QKD) profile. The method further includes: The UE sends the learned PQC profile to an upper layer for at least one of user identity encryption and UE data encryption.

[0020] Accordingly, an embodiment of the present disclosure provides a UE having a processor. The processor is configured to create and train an AI-based model using at least one input including one of one or more UE parameters, one or more network parameters, and one or more application parameters. The processor is configured to learn at least one PQC profile using the trained AI-based model. The processor is configured to send the learned PQC profile to an upper layer for at least one of user identity encryption and UE data encryption.

[0021] These and other aspects of the example embodiments of the present disclosure will be better understood and appreciated when considered in conjunction with the following description and the accompanying drawings. However, it should be understood that the following description, although indicating example embodiments and their numerous specific details, is for illustrative purposes only and not limiting. Many changes and modifications can be made within the scope without departing from the essence of the example embodiments of the present disclosure, and the example embodiments of the present disclosure include all such modifications.

[0022] Advantages of the Invention

[0023] For those skilled in the art, the advantages and significant features of the present invention will become apparent from the following detailed description, which discloses exemplary embodiments of the present invention in conjunction with the accompanying drawings. For more advanced communication systems, a method and apparatus for selecting a security profile in a wireless communication system are needed. Description of the Drawings

[0024] Embodiments of the present disclosure are described with reference to the accompanying drawings, in which like reference numerals refer to corresponding parts throughout the several views. By referring to the following illustrative drawings, embodiments of the present disclosure can be better understood. Embodiments of the present disclosure are illustrated by way of example in the accompanying drawings, where: Figure 1 shows a process of selecting a security profile in a communication network during UICC pre-configuration according to the prior art; Figure 2 shows a system for selecting a security profile in a communication network according to embodiments disclosed herein; Figure 3 shows multiple modules of a UE processor according to embodiments disclosed herein; Figure 4 shows a dynamic security profile selection / update mechanism with multiple design options (defined for selecting or updating one or more security profiles) in a communication network according to embodiments disclosed herein; Figure 5 shows a method for selecting a security profile in a communication network through UICC pre-configuration according to embodiments disclosed herein; Figure 6 shows a process of selecting a security profile in a new network service independent of existing network services during UICC pre-configuration according to embodiments disclosed herein; Figure 7 shows a process of selecting a security profile in a new network service dependent on existing network services during UICC pre-configuration according to embodiments disclosed herein; Figure 8 shows a process of selecting a security profile in a new network service dependent on an existing network service with a security profile identifier configured as separate parts according to embodiments disclosed herein; Figure 9 shows a method for selecting or updating a security profile based on a request from a communication network according to embodiments disclosed herein; Figure 10 shows a message sequence diagram for selecting or updating PQC support through an identity request according to embodiments disclosed herein; Figure 11 shows a message sequence diagram for selecting or updating a security profile through an identity request according to embodiments disclosed herein; Figure 12 shows a message sequence diagram for selecting or updating PQC support through a registration rejection according to embodiments disclosed herein; Figure 13 shows a message sequence diagram for selecting or updating a security profile through a registration rejection according to embodiments disclosed herein; Figure 14 Shows a message sequence diagram for updating PQC support by any N1 message in a configuration update command or a registration request according to embodiments disclosed herein; Figure 15 Shows a message sequence diagram for updating PQC support by any N1 message in a configuration update command or an identification request according to embodiments disclosed herein; Figure 16 Shows a message sequence diagram for updating a security profile by any N1 message in a configuration update command or a registration request according to embodiments disclosed herein; Figure 17 Shows a message sequence diagram for updating a security profile by any N1 message in a configuration update command or an identification request according to embodiments disclosed herein; Figure 18 Shows a message sequence diagram for PQC / legacy support update or profile update through a BIP session in a registration request according to embodiments disclosed herein; Figure 19 Shows a message sequence diagram for PQC / legacy support update or profile update through a BIP session in an identification request according to embodiments disclosed herein; Figure 20 Shows a process design for AI / ML-based PQC profile selection according to embodiments disclosed herein; Figure 21 Shows a method for selecting a PQC profile in a communication network 204 through an AI model according to embodiments disclosed herein; Figure 22 Shows a user equipment (UE) in a wireless communication system to which embodiments of the present disclosure can be applied; Figure 23 Shows a base station in a wireless communication system to which embodiments of the present disclosure can be applied; Figure 24 Shows a network entity to which embodiments of the present disclosure can be applied. Detailed Description

[0025] The main objective of the embodiments herein is to disclose methods and systems for performing a security profile selection process for a wireless communication network.

[0026] Another objective of the embodiments herein is to disclose methods and systems for security profile selection in a wireless communication network based on post-quantum cryptography (PQC) or quantum cryptography.

[0027] Another objective of the embodiments of this document is to disclose methods and systems for disclosing multiple post - quantum - based security profiles in a user equipment (UE), the mechanisms and processes involved in security profile selection, which are mainly used to maintain user privacy during the initial authentication process between the UE and the network.

[0028] Another objective of the embodiments of this document is to disclose a mechanism for dynamically selecting a security profile that can provide better security in a given network environment.

[0029] Another objective of the embodiments of this document is to disclose methods and systems for defining the signaling process of the profile selection process between the UE and the network through core - network - based, SIM - pre - configured, bearer - independent, and machine - learning - based post - quantum era security profile selection.

[0030] Accordingly, the embodiments of this document provide a method for selecting a security profile in a communication network. The method includes: a user equipment (UE) receives a new network service configuration of a universal integrated circuit card (UICC) from the communication network. The UICC may include, but is not limited to, (Subscriber Identity Module) (SIM), Universal Subscriber Identity Module (USIM), embedded SIM (eSIM), integrated SIM, etc. The UICC is configured with new network services by the communication network during pre - configuration. The method includes: the UE configures at least one security profile identifier in one of the UE and the UICC to add at least one security profile in a priority order. The method includes: the UE selects a security profile using the configured security profile identifier based on the configured new network service.

[0031] Accordingly, the embodiments of this document provide a UE having a processor. The processor is configured to receive a new network service configuration of a UICC from the communication network. The UICC is configured with new network services by the communication network during pre - configuration. The processor is configured to configure at least one security profile identifier in one of the UE and the UICC to add at least one security profile in a priority order. The processor is configured to select a security profile using the configured security profile identifier based on the new network service.

[0032] Accordingly, the embodiments of this document provide a method for selecting a security profile in a communication network. The method includes: the UE receives a message from the communication network. The message includes at least one of a security support indication and a security profile indication supported by the communication network. The method includes: the UE updates at least one security profile supported by the UE based on the received message. The method includes: the UE sends a registration request to the communication network with at least one of user identity encryption and UE data encryption using the updated security profile.

[0033] Accordingly, embodiments herein provide a UE having a processor. The processor is configured to receive a message from a communication network. The message includes at least one of a security support indication and a security profile indication supported by the communication network. The processor is configured to update at least one security profile supported by the UE based on the received message. The processor is configured to send a registration request to the communication network having at least one of user identity encryption and UE data encryption using the updated security profile.

[0034] Accordingly, embodiments herein provide a method for selecting a PQC profile in a communication network. The method includes: The UE creates and trains an AI-based model using at least one input including one of one or more UE parameters, one or more network parameters, and one or more application parameters. The method includes: The UE learns at least one PQC profile using the trained AI-based model. The PQC profile may include, but is not limited to, a quantum key distribution (QKD) profile. The method includes: The UE sends the learned PQC profile to an upper layer for at least one of user identity encryption and UE data encryption.

[0035] Accordingly, embodiments herein provide a UE having a processor. The processor is configured to create and train an AI-based model using at least one input including one of one or more UE parameters, one or more network parameters, and one or more application parameters. The processor is configured to learn at least one PQC profile using the trained AI-based model. The processor is configured to send the learned PQC profile to an upper layer for at least one of user identity encryption and UE data encryption.

[0036] These and other aspects of the example embodiments herein will be better understood and appreciated when considered in conjunction with the following description and the accompanying drawings. However, it should be understood that the following description, while indicating example embodiments and their numerous specific details, is for illustrative purposes only and not limiting. Many changes and modifications can be made within the scope of the example embodiments herein without departing from their essence, and the example embodiments herein include all such modifications.

[0037] The embodiments herein and various features and beneficial details thereof will be more fully explained by reference to the non-limiting embodiments shown in the accompanying drawings and described in detail below. Descriptions of well-known components and processing techniques are omitted to avoid unnecessarily obscuring the embodiments herein. The examples used herein are only intended to facilitate understanding of the manner of practicing the embodiments herein and further enable those skilled in the art to practice the embodiments herein. Therefore, these examples should not be construed as limiting the scope of the embodiments herein.

[0038] To explain this specification, the definitions as defined herein will be applied, and where appropriate, terms used in the singular form will also include the plural form and vice versa. It should be understood that the terms used herein are for the purpose of describing particular embodiments only and are not intended to be limiting. Unless otherwise specified, the terms "comprising", "having", and "including" shall be construed as open-ended terms.

[0039] The words / phrases "exemplary", "example", "illustrative", "in an instance", "etc.", "such as", "for example", "i.e.", etc. are used herein only to mean "as an example, instance, or illustration". Any embodiment or implementation of the subject matter described herein using these words / phrases is not necessarily to be construed as more preferred or advantageous than other embodiments.

[0040] Embodiments herein can be described and illustrated with modules that perform the described functions. These modules can be referred to herein as managers, units, modules, hardware components, etc., which are physically implemented by analog and / or digital circuits (such as logic gates, integrated circuits, microprocessors, microcontrollers, storage circuits, passive electronic components, active electronic components, optical components, hardwired circuits, etc.) and can optionally be driven by firmware. For example, these circuits can be embodied in one or more semiconductor chips or on a substrate support such as a printed circuit board. The circuits constituting the modules can be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and their associated circuits), or by a combination of dedicated hardware that performs some functions of the module and a processor that performs other functions of the module. Each module of an embodiment can be physically separated into two or more interacting and discrete modules without departing from the scope of the present disclosure. Similarly, the modules of an embodiment can be physically combined into more complex modules without departing from the scope of the present disclosure.

[0041] It should be noted that the elements in the drawings are shown for the convenience of this description and understanding and are not necessarily drawn to scale. For example, a flowchart / sequence diagram illustrates a method according to the steps required for understanding the various aspects of the embodiments disclosed herein. Further, in terms of the construction of a device, one or more components of the device can be represented by conventional symbols in the drawings, and the drawings can show only the specific details relevant to understanding the embodiments herein so as not to obscure the drawings with details that are obvious to those of ordinary skill in the art and beneficial to the description herein. Further, in terms of a system, one or more components / modules constituting the system can be represented by conventional symbols in the drawings, and the drawings can show only the specific details relevant to understanding the embodiments herein so as not to obscure the drawings with details that are obvious to those of ordinary skill in the art and beneficial to the description herein.

[0042] The accompanying drawings are used to facilitate an easy understanding of various technical features, and it should be understood that the embodiments presented herein are not limited by the accompanying drawings. Accordingly, the present disclosure should be construed to include any modifications, equivalents, and alternatives in addition to those specifically set forth in the accompanying drawings and the corresponding description. The use of words such as first, second, third, etc. to describe components / elements / steps is for the purpose of this description and should not be construed as being in sequential order / placement / occurrence unless otherwise specified.

[0043] Embodiments herein disclose methods and systems for designing mechanisms and processes involved in the selection of security profiles for wireless communication networks. Now referring to the accompanying drawings, specifically referring to Figures 2 to 21 , in which like reference characters consistently denote corresponding features throughout the figures, in which embodiments are shown.

[0044] In recent years, several broadband wireless technologies have been developed to meet the growing number of broadband users, thereby providing better applications and services. The second-generation (2G) wireless communication systems have been developed to provide voice services while ensuring user mobility. The third-generation (3G) wireless communication systems support not only voice services but also data services. In recent years, the fourth-generation (4G) wireless communication systems have been developed to provide high-speed data services. However, currently, the 4G wireless communication systems face the problem of insufficient resources and cannot meet the growing demand for high-speed data services. This problem is solved by deploying the fifth-generation (5G) wireless communication systems to meet the growing demand for high-speed data services. In addition, the 5G wireless communication systems provide ultra-reliability and support low-latency applications.

[0045] A quantum computer is a computer that utilizes quantum mechanical effects. These effects include superposition that allows a qubit to be in a combination of several states simultaneously, and entanglement that allows connections to be established between separate quantum systems such that they cannot be described independently. There are some quantum algorithms that utilize quantum mechanical effects and are capable of solving certain cryptographic problems more efficiently than on classical computers. The Shor quantum algorithm for integer factorization runs in polynomial time on a quantum computer. A variant of the Shor algorithm enables a quantum computer to compute discrete algorithms over finite fields and elliptic curves in polynomial time. This variant renders several other public-key cryptosystems, including Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH), insecure. To address the threat of quantum computing to asymmetric cryptography, it is necessary to replace existing algorithms with new quantum-resistant algorithms (also known as post-quantum cryptography (PQC) algorithms). Therefore, wireless communication networks such as beyond 5G (e.g., 6G) need to quickly adapt to these PQC algorithms to enhance security.

[0046] PQC involves various algorithms for different purposes such as key establishment, digital signatures, etc. Some of these algorithms include CRYSTALS-KYBER for key establishment, and CRYSTALS-Dilithium, FALCON, and SPHINCS+ for digital signatures with post-quantum security.

[0047] In the current system (e.g., 5G system), the globally unique 5G subscription permanent identifier is called SUPI, as defined in 3GPP TS 23.501. The Subscription Concealed Identifier (SUCI) is a privacy-protected identifier that contains the concealed SUPI. According to TS 33.501, SUPI is protected for privacy in the air by using SUCI. The UE shall use a protection scheme or security profile with the original public key to generate the SUCI, i.e., the home network public key securely configured under the control of the home network.

[0048] 5G uses traditional asymmetric encryption algorithms, which may not be secure due to the development of quantum computing (QC) mechanisms. In a beyond 5G network, devices can support traditional asymmetric encryption algorithms and / or PQC algorithms simultaneously. Different devices can have different requirements and will accordingly have different support for encryption algorithms.

[0049] The current profiles (or protection schemes) only exist in non-PQC algorithms, such as the null scheme, Elliptic Curve Integrated Encryption Scheme (ECIES) profile A, ECIES profile B, etc. The initial authentication based on the null scheme is only performed when security is not required. ECIES profile A and ECIES profile B are based on Elliptic Curve Cryptography (ECC) and are vulnerable to quantum attacks. These profiles are configured during the pre-configuration of the SIM, and there is no method to dynamically select various profiles. As shown in Table 1 below, according to the 3GPP TS 31.102 specification, in the Universal Subscriber Identity Module (USIM) elementary file "EFSUCI_Calc_Info", only the highest-priority profile needs to be selected by default for initial authentication (or) SUCI encryption. 3GPP mentions one or more protection scheme profiles for hiding SUPI in Appendix C of the TS 33.501 specification.

[0050]

[0051] Table 1

[0052] In a 5G or beyond 5G network, both traditional encryption algorithms and new algorithms based on quantum algorithms (such as quantum key distribution or PQC) can be applied. Therefore, new profiles for protection schemes that can be used to hide SUPI need to be defined.

[0053] In a 5G system, since 3GPP only supports two protection scheme profiles for initial authentication, there is no way to dynamically select or update the protection scheme. In a network of beyond 5G (as it supports both traditional and new encryption algorithms such as PQC algorithms simultaneously), a user or any other device can have multiple profiles available. Therefore, there is no mechanism capable of dynamically selecting a protection scheme or profile that provides better security in a given network environment. Additionally, if the UE and the network support different protection schemes, then the UE may not be able to successfully register due to a failed authentication process, which may further delay the registration process. Therefore, proper negotiation of the protection scheme process is required between the UE and the network.

[0054] Currently, in an embedded universal integrated circuit card (eUICC), it is only stipulated that the UE can decide whether to perform SUCI encryption and whether SUCI encryption can be performed by the USIM / mobile equipment (ME). The UE cannot decide whether PQC algorithms need to be used for SUCI encryption. Network service support is the configuration provided by the network during SIM pre-configuration. Network services include, for example, service n°124, which is for subscription identifier privacy support, and service n°125, which is for SUCI calculation by the USIM.

[0055] Figure 1 The process of selecting a security profile in a communication network during SIM configuration is shown. As shown in step 102, the SIM is configured with network service support and a security profile during pre-configuration. The UE 202 verifies in step 104 whether the configured network service n°124 is supported. If network service n°124 is supported, the UE 202 verifies network service n°125 in step 106; otherwise, as shown in step 108, null encryption or no encryption is performed on the SUPI.

[0056] If network service n°125 is supported, the UE 202 performs SUCI calculation through the universal subscriber identity module (USIM) in step 110; otherwise, as shown in step 112, the SUCI calculation will be performed by the ME. The UE 202 selects the highest-priority security profile identifier from the USIM (EF: 4F07) in step 114, where only ECIES A and ECIES B are provided for SUCI calculation.

[0057] As shown in Table 2 below and Figure 1 there is no network service support to select traditional or PQC algorithms for SUCI hiding.

[0058]

[0059] Table 2

[0060] Currently, 3GPP 31.102 (EF SUCI_Calc_Info) only specifies one protection scheme or security profile identifier with the highest priority, which is used as the default value and only supports traditional non-PQC algorithms. Due to the introduction of PQC-based algorithms, if the UE (or) network can support both traditional algorithms and PQC algorithms simultaneously, then the UE or network cannot select the default values of the two types of profiles. Therefore, there is no multiple default security profile identifiers.

[0061] Therefore, there is a need in the art for a solution that can overcome the above disadvantages and other problems.

[0062] Figure 2 A system 200 for selecting a security profile in a communication network 204 is shown. The system 200 includes a user equipment (UE) 202 and a communication network 204 for performing a security profile selection process. The UE 202 further includes a processor 206, a communication module 208, and a storage module 210.

[0063] In an embodiment herein, the processor 206 is configured with a process for post-quantum cryptography (PQC) or traditional profile selection pre-configured based on a Universal Integrated Circuit Card (UICC). The UICC may include, but is not limited to, a (Subscriber Identity Module) (SIM), a Universal Subscriber Identity Module (USIM), an Embedded SIM (eSIM), an Integrated SIM, etc. The processor 206 is configured with a process for PQC or traditional profile selection through a core network. The processor 206 is configured with a process for PQC or traditional profile update through an independent bearer protocol (BIP) session between the UE 202 and the communication network 204. The processor 206 is configured with a PQC profile selection process based on artificial intelligence (AI) / machine learning (ML). As Figure 3 shown, the processor 206 further includes a configuration module 302, a security profile module 304, a registration module 306, and an AI module 308.

[0064] In an embodiment herein, the UE 202 receives a new network service configuration of the UICC from the communication network 204, where the UICC is configured with the new network service by the communication network 204 during pre-configuration. The new network service can be one of an independent network service and a dependent network service. The independent network service is independent of the existing network service. The dependent network service depends on the existing network service. The new network service is configured in the UICC to enable one or more PQC algorithms for performing at least one of user identity encryption and UE data encryption. In an embodiment herein, the communication network 204 may configure the new network service for the UICC before configuring the UICC into the UE 202, and then configure the configured UICC into the UE 202.

[0065] In an embodiment of the present disclosure, the configuration module 302 may receive a new network service configuration of the UICC. The configuration module 302 may configure at least one security profile identifier in one of the UE 202 and the UICC to add at least one security profile in a priority order. In an embodiment of the present disclosure, the security profile identifier is configured as a combined part of a legacy profile and a PQC profile. In an embodiment of the present disclosure, one or more security profile identifiers are configured as separate parts of a legacy profile and a PQC profile.

[0066] In an embodiment of the present disclosure, the security profile module 304 may store one or more security profiles. The security profile module 304 may select a security profile from the stored security profiles using the configured security profile identifier. The security profile module 304 may select a security profile based on the configured new network service. The security profile includes at least one of a legacy profile and a PQC profile.

[0067] In an embodiment of the present disclosure, the security profile module 304 may verify the configured new network service. If the configured new network service is a stand-alone network service and is enabled, the security profile module 304 may perform at least one of user identity encryption and UE data encryption using the PQC profile. If the configured new network service is a stand-alone network service and is disabled, the security profile module 304 may perform at least one of user identity encryption and UE data encryption using the legacy profile. The security profile module 304 may select at least one of a legacy profile and a PQC profile having a high-priority security profile identifier.

[0068] In an embodiment of the present disclosure, the security profile module 304 may verify the configured new network service. If the configured new network service is a dependent network service and both the existing network service and the dependent network service are enabled, the security profile module 304 may perform at least one of user identity encryption and UE data encryption using the PQC profile. If the configured new network service is a dependent network service and one of the existing network service and the dependent network service is disabled, the security profile module 304 may perform at least one of user identity encryption and UE data encryption using the legacy profile. The security profile module 304 may select at least one of a legacy profile and a PQC profile having a high-priority security profile identifier.

[0069] In an embodiment of the present disclosure, the security profile module 304 may receive a message from the communication network 204. The message includes at least one of a security support indication and a security profile indication supported by the communication network 204. The security support indication includes one of a PQC support indication and a legacy support indication. The security profile indication includes one of a PQC profile indication and a legacy profile indication supported by the communication network 204. The security profile module 304 may update at least one security profile supported by the UE 202 based on the received security support indication and security profile indication supported by the communication network 204. In an embodiment of the present disclosure, the message from the communication network 204 may include at least one of an identity request message, a registration rejection message, a system information block (SIB) / master information block (MIB) message, a radio resource control (RRC) message, a BIP message, an N1 message, etc. In an embodiment of the present disclosure, if the message is a registration rejection message, the communication network 204 adds a cause code to the registration rejection message. The communication network 204 adds the cause code to request the UE 202 to use a new type of security profile in the next registration request or message response to share at least one of user identity encryption and UE data encryption. The communication network 204 adds an information element for at least one of security support and security profile to the message to indicate to the UE 202 the encryption type required for at least one of user identity encryption and UE data encryption. In an embodiment of the present disclosure, the N1 message may include a configuration update command message for requesting the UE 202 to use a new type of security profile in the next registration request or message response to share at least one of user identity encryption and UE data encryption.

[0070] In an embodiment of the present disclosure, the registration module 306 may send a registration request with at least one of user identity encryption and UE data encryption to the communication network 204 using the updated security profile. The registration module 306 may send a subscription concealed identifier (SUCI) encrypted using the updated security profile to the communication network 204.

[0071] In an embodiment of the present disclosure, the AI module 308 may create and train an AI-based model using at least one input including one of one or more UE parameters, one or more network parameters, and one or more application parameters. The AI module 308 may learn at least one PQC profile using the trained AI-based model. The PQC profile may include, but is not limited to, a quantum key distribution (QKD) profile. The AI module 308 may send the learned at least one PQC profile to the upper layer for at least one of user identity encryption and UE data encryption.

[0072] In an embodiment of the present disclosure, the processor 206 may process and execute data of multiple modules of the UE 202 respectively. The processor 206 is configured to execute instructions stored in the storage module 210. The processor 206 may include one or more microprocessors, circuits, and other hardware configured for processing. The processor 206 may be at least one of a single processor, a multi-processor, multi-homogeneous or heterogeneous cores, multiple different types of central processing units (CPUs), a microcontroller, a dedicated media, and other accelerators. The processor 206 may be an application processor (AP), a graphics-only processing unit (such as a graphics processing unit (GPU), a vision processing unit (VPU)), and / or an artificial intelligence (AI)-dedicated processor (such as a neural processing unit (NPU)).

[0073] In an embodiment of the present disclosure, multiple modules of the processor 206 of the UE 202 may communicate through the communication module 208. The communication module 208 may be in the form of a wired network or a wireless communication network module. The wireless communication network may include, but is not limited to, the Global Positioning System (GPS), the Global System for Mobile Communications (GSM), Wi-Fi, Bluetooth Low Energy, Near Field Communication (NFC), etc. Depending on the usage environment, the wireless communication may also include one or more of Bluetooth, ZigBee, short-range wireless communication (such as Ultra-Wideband (UWB)), medium-range wireless communication (such as Wi-Fi), or long-range wireless communication (such as 3G / 4G / 5G / 6G and non-3GPP technologies or WiMAX).

[0074] In an embodiment of the present disclosure, the storage module 210 may include one or more volatile and non-volatile storage components capable of storing data and instructions to be executed by the modules of the UE 202. Examples of the storage module 210 may include, but are not limited to, NAND, Embedded MultiMediaCard (eMMC), Secure Digital (SD) card, Universal Serial Bus (USB), Serial Advanced Technology Attachment (SATA), Solid State Drive (SSD), etc. The storage module 210 may also include one or more computer-readable storage media. Examples of non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memory, or electrically programmable read-only memory (EPROM) or electrically erasable programmable (EEPROM) memory forms. In addition, in some examples, the storage module 210 may be regarded as a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be construed to mean that the storage module 210 is immovable. In certain examples, the non-transitory storage medium may store data that may change over time (such as in random access memory (RAM) or a cache).

[0075] Figure 2Example modules of the UE 202 are shown respectively, but it should be understood that other embodiments are not limited thereto. In other embodiments, the UE 202 may include fewer or more modules. Additionally, the labels or names of the modules are for illustrative purposes only and do not limit the scope of the present invention. One or more modules may be combined together to perform the same or substantially similar functions in the UE 202.

[0076] Figure 4 A dynamic security profile selection / update mechanism 400 with various design options defined to select or update one or more security profiles in a communication network 204 is shown. These design options include a design to select PQC / legacy profiles based on UICC pre-configuration as shown at 402, a design to select PQC / legacy profiles through the core network as shown at 404, a design to update PQC / legacy profiles through a BIP session between the UE 202 and the communication network 204 as shown at 406, and a design of an AI / ML-based PQC profile selection process as shown at 408.

[0077] Figure 5 A method 500 for selecting a security profile in a communication network 204 through UICC pre-configuration is shown. The method 500 includes: as shown in step 502, the UE 202 receives a new network service configuration of the UICC from the communication network 204. The UICC is configured with the new network service during pre-configuration by the communication network 204. The method 500 further includes: as shown in step 504, the UE 202 configures at least one security profile identifier in one of the UE 202 and the UICC to add at least one security profile in a priority order. The method 500 includes: as shown in step 506, the UE 202 selects at least one security profile based on the configured new network service using the configured at least one security profile identifier.

[0078] The various actions in the method 500 may be performed in the order shown, or in a different order or simultaneously. Additionally, in some embodiments, Figure 5 some of the actions listed may be omitted.

[0079] In the embodiments of the present document, the selection of the security configuration file pre-configured in the UICC can be carried out in two steps. The first step includes creating a new network service during UICC pre-configuration. The new network service can be independent of other network services. The new network service can be dependent on existing network services. The second step includes configuring a new elementary file (EF), such as a security profile identifier, to adapt to the new security profile of the UICC. The new security profile of the UICC is defined in EFSUCI_Calc_Info and / or EFPQC_SUCI_Calc_Info. The security profile identifier can be configured as a combined part of a traditional profile and a PQC profile, or can be configured as multiple separate parts of different security profiles (such as a traditional profile and a PQC profile).

[0080] For example, based on the new network service in the UICC, the default traditional and PQC security profiles with high priority mentioned in EFSUCI_Calc_Info and / or EFPQC_SUCI_Calc_Info can be selected. For example, the default option can be to select the PQC profile according to UICC pre-configuration.

[0081] In the embodiments of the present document, the new network service is independent of the existing network service and is configured to consider the PQC algorithm in the encryption process of converting the subscription permanent identifier (SUPI) to SUCI. In this case, if the new network service is declared available or enabled, the SUCI calculation will be performed by the PQC algorithm; otherwise, if the new network service is declared unavailable or disabled, the SUCI calculation will be performed by the traditional algorithm.

[0082] The following modifications need to be made in 3GPP TS 31.102: 4.2.8 USIM Service Table Elementary File (EF UST) for a new network service independent of the existing network service.

[0083]

[0084] 4.4.11 DF 5GS Content of the level file

[0085] 4.4.11.1 Introduction

[0086] Figure 6Flow 600 for selecting a security profile in a new network service independent of existing network services during UICC pre - configuration is shown. As shown in step 602, UE 202 verifies whether the configured new network service is independent of the existing network service. If the configured new network service is an independent network service and is enabled, then as shown in step 604, UE 202 performs at least one of user identity encryption and UE data encryption using a PQC profile. For example, SUCI calculation will be performed by a PQC algorithm. UE 202 selects the highest - priority PQC profile identifier in step 606. If the configured new network service is an independent network service and is disabled, then as shown in step 608, UE 202 performs at least one of user identity encryption and UE data encryption using a legacy profile. For example, SUCI calculation will be performed by a legacy algorithm. UE 202 selects the highest - priority legacy profile identifier for SUCI calculation in step 610.

[0087] The various actions in method 600 can be performed in the order shown, or in a different order or simultaneously. Additionally, in some embodiments, Figure 6 some of the actions listed in

[0088] In the embodiments herein, the new network service depends on the existing network service and is configured to consider the PQC algorithm during the encryption process of converting SUPI to SUCI. Table 3 shows the SUCI functionality of the new network service that depends on the existing network service.

[0089]

[0090] Table 3

[0091] As shown in Table 3, if both the existing service n°124 and the new network service n°XXX are declared "available", then SUCI calculation will be performed by a PQC algorithm; if the existing service n°124 is declared "available" and the new network service n°XXX is not declared "available", then SUCI calculation will be performed by a traditional method.

[0092] Figure 7Illustrates the process 700 of selecting a security profile in a new network service that depends on an existing network service during UICC pre-configuration. As shown in step 702, the UICC is configured with a new network service and a security profile during pre-configuration. The UE 202 verifies in step 704 whether the configured new network service is a dependent network service and whether the dependent network service (e.g., n°124) is supported. If the dependent network service n°124 is supported, the UE 202 verifies the existing network service (e.g., n°125) in step 706; otherwise, as shown in step 708, null encryption or no encryption is performed on the SUPI. If the existing network service n°125 is supported, the UE 202 performs SUCI calculation through the UICC in step 710; otherwise, as shown in step 712, the SUCI calculation will be performed by the ME.

[0093] Subsequently, after the UICC performs the SUCI calculation (step 710), the UE 202 verifies the support for the new network service n°XXX in step 714. If the UE 202 supports the new network service n°XXX, then as shown in step 716, the UICC will perform the SUCI calculation using the PQC algorithm. After the ME performs the SUCI calculation (step 712), the UE 202 verifies the support for the new network service n°XXX in step 720. If the UE 202 supports the new network service n°XXX, then as shown in step 722, the ME will perform the SUCI calculation using the PQC algorithm. Therefore, if the configured new network service is a dependent network service and both the existing network service and the dependent network service are enabled, the UE 202 will perform at least one of user identity encryption and UE data encryption using the PQC profile.

[0094] Otherwise, as shown in steps 718 and 724, the UICC and the ME will perform the SUCI calculation using the traditional algorithm. Therefore, if the configured new network service is a dependent network service and one of the existing network service and the dependent network service is disabled, the UE 202 will perform at least one of user identity encryption and UE data encryption using the traditional profile. The UE 202 selects in step 726 the highest-priority security profile identifier for at least one of the traditional profile and the PQC profile from the UICC (EF: 4F07) for the SUCI calculation. This step illustrates the configuration of the security profile as a combined part of the traditional and PQC security profiles.

[0095] The various actions in method 700 can be performed in the order shown, or in a different order or simultaneously. Additionally, in some embodiments, Figure 7 some of the actions listed in

[0096] Therefore, the new network service n°XXX will only be considered when service n°124 is declared "available". If both service n°124 and service n°125 are declared "available", then "the PQC-based SUCI calculation will be performed by the UICC"; if service n°124 is declared "available" and service n°125 is not declared "available", then "the PQC SUCI calculation will be performed by the ME".

[0097] 5.3.XX PQC-based SUCI Calculation Information Process

[0098] Requirement: "The PQC-based SUCI calculation will be performed by the ME" (i.e., service n°124 and service n°XXX are "available", and service n°125 is "not available").

[0099] Request: As part of the SUCI calculation performed by the ME, the ME performs a read process on EFSUCI_Calc_Info or EFPQC_SUCI_Calc_Info.

[0100] 5.3.XX PQC-based SUCI Calculation Process Performed by the USIM

[0101] Requirement: "The PQC SUCI calculation is performed by the USIM" (i.e., service n°124, service n°125, and service n°XXX are all "available").

[0102] Request: The ME uses the GET IDENTITY command in the SUCI context to retrieve the SUCI calculated by the USIM.

[0103] In the embodiments of this document, the newly added PQC profile can be configured in the USIM / ME in two options: Option 1: A combined part of the traditional and PQC security profiles (as shown in step 726 of Figure 7 ). Option 2: Multiple parts for different security profile configurations: one for the traditional security profile and one for the PQC security profile.

[0104] Default security profiles need to be configured for the PQC and traditional algorithms respectively. Based on the different combinations of the UE 202 and the network supporting the PQC and traditional algorithms, one or more security profiles can be used simultaneously.

[0105] In the embodiments of this document, for the configuration of the combination part of traditional and PQC security profiles, a new security profile identifier needs to be introduced for PQC, and one of them is selected as the default item (e.g., the highest priority). Both traditional and PQC algorithms can be part of the combination of UE 202 or UICC (EF 4F07). Based on the support of PQC by UE 202 or the communication network, the highest priority security profile identifier of PQC or traditional can be selected.

[0106] Table 4 shows 3GPP 31.102: 4.4.11.8 EF SUCI_Calc_Info (Subscription Concealed Identifier Calculation Information EF) (ID: 4F07).

[0107]

[0108] Table 4

[0109] Table 5 indicates the file details of EF SUCI_Calc_Info (Subscription Concealed Identifier Calculation Information EF).

[0110]

[0111] Table 5

[0112] If "perform PQC-based SUCI calculation" (i.e., service n°124 in EF UST is "available" and service n°XXX in EF UST is "available"), then this file should have other values of the PQC profile.

[0113] If "do not perform PQC-based SUCI calculation" (i.e., service n°124 in EF UST is "available" and service n°XXX in EF UST is "unavailable"), then this file should not have other values of the PQC profile.

[0114] If service n°124 in EF UST is "unavailable", the ME cannot access this file.

[0115] Note: The way to make the file "unavailable to the ME" depends on the specific implementation. For example, the file may not exist, the file may exist but the ME cannot read it, or the file may exist but has been disabled.

[0116] - PQC security profile identifier list data object

[0117] Content: If the length of the PQC security profile identifier list data object is not zero, this data object contains a list of PQC security profile identifiers and the corresponding key indices. The first PQC security profile identifier entry has the highest priority, and the last PQC security profile identifier entry has the lowest priority. The key index value indicates the position of the home network public key applicable to the PQC profile in the home network public key list.

[0118] Table 6 indicates the encoding of the legacy and PQC security profile configuration combination parts.

[0119]

[0120] Table 6

[0121] In the embodiments herein, multiple parts for different security profile configurations (one for the legacy profile and one for the PQC profile) include the new security profile identifiers introduced for PQC, and one of them is selected as the default item (e.g., the highest priority). The legacy algorithm and the PQC algorithm can be part of different EFs (EF 4F07 and EF 4FXX) of the UICC respectively. Based on the support of PQC by the UE 202 or the communication network, the PQC or the legacy highest priority profile identifier can be selected. A new EF PQC_SUCI_Calc_Info needs to be added in the UICC application (3GPP 31.102). EF PQC_SUCI_Calc_Info is the PQC subscription hidden identifier calculation information EF (ID: 4FXX).

[0122] Table 7 shows the legacy EF SUCI_Calc_Info (EF: 4F07).

[0123]

[0124] Table 7

[0125] Table 8 indicates the EF_PQC_SUCI_Calc_Info for PQC (EF: 4FXX).

[0126]

[0127] Table 8

[0128] Figure 8Flow 800 shows the process of selecting a security profile in a new network service that depends on an existing network service and the security profile identifier is configured as a separate part. As shown in step 802, the UICC is configured with the new network service and the security profile during pre-configuration. The UE 202 verifies in step 804 whether the configured new network service is a dependent network service and whether the dependent network service (e.g., n°124) is supported. If the dependent network service n°124 is supported, the UE 202 verifies the existing network service (e.g., n°125) in step 806; otherwise, as shown in step 808, null encryption or no encryption is performed on the SUPI. If the existing network service n°125 is supported, the UE 202 performs SUCI calculation through the UICC in step 810; otherwise, as shown in step 812, the SUCI calculation will be performed by the ME.

[0129] Subsequently, after the UICC performs the SUCI calculation (step 810), the UE 202 verifies the support for the new network service n°XXX in step 814. If the UE 202 supports the new network service n°XXX, then as shown in step 816, the UICC will perform the SUCI calculation using the PQC algorithm. After the ME performs the SUCI calculation (step 812), the UE 202 verifies the support for the new network service n°XXX in step 820. If the UE 202 supports the new network service n°XXX, then as shown in step 822, the ME will perform the SUCI calculation using the PQC algorithm. Therefore, if the configured new network service is a dependent network service and both the existing network service and the dependent network service are enabled, the UE 202 will perform at least one of user identity encryption and UE data encryption using the PQC profile. The UE 202 selects the highest priority security profile identifier for the PQC profile from the UICC (EF: 4FXX) in step 826 for the SUCI calculation.

[0130] Otherwise, as shown in steps 818 and 824, the UICC and the ME will perform the SUCI calculation using the traditional algorithm. Therefore, if the configured new network service is a dependent network service and one of the existing network service and the dependent network service is disabled, the UE 202 will perform at least one of user identity encryption and UE data encryption using the traditional profile. The UE 202 selects the highest priority security profile identifier for the traditional profile from the UICC (EF: 4F07) in step 828 for the SUCI calculation. This step shows the configuration of the security profile as a separate part for the traditional security profile and the PQC security profile.

[0131] The various actions in method 800 can be performed in the order shown, or in a different order or simultaneously. Additionally, in some embodiments,Figure 8 Some of the actions listed can be omitted.

[0132] Tables 9 and 10 indicate the encoding of the individual parts of the traditional and PQC security profile configurations.

[0133]

[0134] Table 9

[0135] Table 10

[0136] 4.4.11.XX EF PQC_SUCI_Calc_Info (PQC Subscription Hidden Identifier Calculation Information EF)

[0137] If "perform PQC-based SUCI calculation" (i.e., service n°124 in EF UST is "available" and service n°XXX in EF UST is "available"), then this file shall exist. This EF contains the information required by the ME to support the subscription identifier privacy defined in 3GPP TS 33.501.

[0138] If "do not perform PQC-based SUCI calculation" (i.e., service n°124 in EF UST is "available" and service n°XXX in EF UST is "unavailable"), then the ME shall not have access to this file.

[0139] If service n°124 in EF UST is "unavailable", then the ME shall not have access to this file.

[0140] Note: The way to make the file "unavailable to the ME" depends on the specific implementation. For example, the file may not exist, the file may exist but the ME cannot read it, or the file may exist but is disabled.

[0141] - PQC Profile Identifier List Data Object.

[0142] Content: This data object shall always exist. If the length of the PQC Profile Identifier List Data Object is not zero, then this data object contains a list of PQC profile identifiers and the corresponding key indices. The first PQC profile identifier entry has the highest priority and the last PQC profile identifier entry has the lowest priority. The key index value indicates the position of the home network public key applicable to the PQC profile in the home network public key list.

[0143] 4.7 Files of the USIM

[0144] This clause includes the file structure of the Universal Integrated Circuit Card (UICC) and the Application Dedicated File (ADF). USIM The ADF shall be selected using the Application Identifier (AID) and the information in the EF DIR . USIM

[0145]

[0146] Table 11 indicates Appendix A (Informative): EF changes via data download or USIM Application Toolkit (USAT) applications.

[0147]

[0148] Table 11

[0149] Table 12 indicates Appendix E (Informative): Recommended content of EF during pre-personalization.

[0150]

[0151] Table 12

[0152] Table 13 indicates the H.9 list of SFI values for the DF 5GS level.

[0153]

[0154] Table 13

[0155] Figure 9 Method 900 for selecting or updating a security profile based on a request from communication network 204 is shown. The method 900 includes: As shown in step 902, UE 202 receives a message from communication network 204. The message includes at least one of a security support indication and a security profile indication supported by communication network 204. The security support indication includes one of a PQC support indication and a legacy support indication. The security profile indication includes one of a PQC profile indication and a legacy profile indication supported by communication network 204. The message from communication network 204 includes at least one of an identity request message, a registration rejection message, an SIB / MIB message, an RRC message, a BIP message, and an N1 message.

[0156] The method 900 includes: As shown in step 904, UE 202 updates at least one security profile supported by UE 202 based on the received message. The method 900 includes: As shown in step 906, UE 202 uses the updated security profile to send a registration request to communication network 204 that includes at least one of user identity encryption and UE data encryption.

[0157] ​The various actions in method 900 can be performed in the order shown, or in a different order or simultaneously. Additionally, in some embodiments, Figure 9 some of the actions listed in Figure 9 can be omitted.

[0158] In the embodiments herein, the selection or update of the security profile can be performed by the core network. Since PQC support and PQC profiles are core-network dependent, the core network can indicate its support to the UE 202 through various options so that the UE 202 can update its own security profile. These options can be, but are not limited to, selecting / updating PQC support via an identity request, selecting / updating the security profile via an identity request, selecting / updating PQC support via a registration rejection, selecting / updating the security profile via a registration rejection, updating PQC support via any N1 message, and updating the security profile via any N1 message.

[0159] Figure 10 Message sequence diagram 1000 shows the selection or update of PQC support via an identity request. As shown in step 1004, the UE 202 can share the SUCI in a registration request using a legacy / PQC security profile. The core network 1002 can have different support for PQC / legacy security profiles. Instead of an authentication failure or a registration rejection, the core network 1002 can notify the UE 202 of its PQC / legacy support by requesting an identity request to share the SUCI using a new security profile (legacy / PQC), as shown in step 1006.

[0160] It can be stipulated that it is not mandatory for the UE 202 to send the SUCI in the registration request, so that the core network 1002 can assume that the UE 202 does not know the legacy type or PQC type of the security profile used to hide the SUPI and respond with an identity request containing the supported type. This solution can reduce the latency time of the registration process. If the core network 1002 sends an identity request for any other purpose, the core network 1002 adds PQC / legacy support information elements so that the UE 202 knows the type required to hide the SUCI. Subsequently, the UE 202 sends an identification response containing the updated SUCI to the core network 1002, as shown in step 1008. A new information element identifier (IEI) can be introduced, or spare bits in an existing IEI can be reused. Additionally, a default legacy / PQC profile can be used according to network support.

[0161] In the embodiments herein, the standard impact (TS 24.501) is as follows: 8.2.21 Identity request 8.2.21.1 Message definition The identity request message is sent by the Access and Mobility Management Function (AMF) to the UE 202 to request the UE 202 to provide a specified identity.

[0162] Message type: Identity Request

[0163] Importance: Dual

[0164] Direction: AMF to UE

[0165] Table 14 indicates the content of the identity request message.

[0166]

[0167] Table 14

[0168] 9.11.3.XX PQC Support

[0169] The IEI for PQC support is 1 bit; 1 - Supports PQC; 0 - Does not support PQC.

[0170] The PQC support indication can also be part of the 5GS identity type

[0171] 9.11.3.3 5GS Identity Type

[0172] The purpose of the 5GS identity type information element is to specify which identity is being requested.

[0173] The 5GS identity type is an Information Element of type 1.

[0174] The encoding of the 5GS identity type information element is shown in Table 15 and Table 16.

[0175]

[0176] Table 15

[0177] Table 16

[0178] Figure 11 Figure 1100 shows the message sequence for selecting or updating a security profile via an identity request. The UE 202 can use a legacy / PQC security profile in the registration request to share the SUCI, as shown in step 1102. The core network 1002 can have different security profile support scenarios. Instead of an authentication failure or registration rejection, the core network 1002 can notify the UE 202 of its PQC / legacy profile support via an identity request for requesting to share the SUCI using a new security profile (legacy / PQC), as shown in step 1104.

[0179] It can be stipulated that it is not mandatory for the UE 202 to send the SUCI in the registration request. The core network 1002 can assume that the UE 202 does not know the security profile for hiding the SUPI and respond with an identity request containing the correct security profile. This solution can reduce the latency time of the registration process. If the core network 1002 also sends an identity request for any other purpose, the core network 1002 adds a security profile information element so that the UE 202 knows the type required to hide the SUCI. Subsequently, the UE 202 sends an identification response containing the updated SUCI to the core network 1002, as shown in step 1106.

[0180] Table 17 indicates the content of the identity request message.

[0181]

[0182] Table 17

[0183] 9.11.3.XX Security Profile

[0184] The IEI for the security profile ID indicating SUPI hiding is 4 bits. Table 18 indicates the security profile IEI.

[0185]

[0186] Table 18

[0187] Figure 12 Figure 1200 shows a message sequence diagram for selecting or updating PQC support through a registration rejection. The UE 202 can use a traditional / PQC security profile in the registration request to share the SUCI, as shown in step 1202. The core network 1002 can have different support for the PQC / traditional security profile. The core network 1002 can notify the UE 202 of its PQC / traditional support situation through a registration rejection for requesting to share the SUCI using a new security profile (traditional / PQC) with a cause code of "yyy", as shown in step 1204.

[0188] It may be specified that it is not mandatory for the UE 202 to send the SUCI in the registration request. The core network 1002 may know that the UE 202 does not know the legacy or PQC type of the security profile for hiding the SUPI and respond with a registration rejection containing the supported type. If the core network 1002 also sends a registration rejection with the cause code "yyy" for any other purpose, the core network 1002 adds a PQC / legacy support information element to enable the UE 202 to know the type required to hide the SUCI. Subsequently, the UE 202 may send a registration request with the SUPI hidden using the new security profile type, as shown in step 1206. The default legacy / PQC profile may be used based on network support.

[0189] 8.2.9 Registration Rejection

[0190] Table 19 indicates the new IEI. A new IEI may be introduced: PQC Support Type

[0191] Table 19

[0192] Figure 13 Message sequence diagram 1300 shows the selection or update of the security profile through a registration rejection. The UE 202 may use the legacy / PQC security profile in the registration rejection to share the SUCI, as shown in step 1302. The core network 1002 may have different support for the PQC / legacy security profile. The core network 1002 may notify the UE 202 of its security profile support by sending a registration rejection with the cause code "yyy" for requesting to share the SUCI using the new security profile (legacy / PQC), as shown in step 1304.

[0193] It may also be specified that it is not mandatory for the UE 202 to send the SUCI in the registration request. The core network 1002 may assume that the UE 202 does not know the legacy or PQC security profile for hiding the SUPI and respond with a registration rejection containing the updated security profile. If the core network 1002 also sends a registration rejection with the cause code "yyy" for any other purpose, the core network 1002 adds a security profile information element to enable the UE 202 to know the type required to hide the SUCI. The UE 202 may send a registration request with the SUPI hidden using the new security profile type, as shown in step 1306.

[0194] Figure 14Figure 1400 shows a message sequence diagram for updating PQC support via any N1 message in a configuration update command or a registration request. As shown in step 1402, the core network 1002 can update its PQC / legacy support status to the UE 202 via any N1 message (such as a configuration update command message) to request the UE 202 to share the SUCI using a new security profile (legacy / PQC) starting from the next registration request. The UE 202 can send a registration request with the SUPI hidden using the new security profile type, as shown in step 1404. The default legacy / PQC profile can be used according to network support.

[0195] Figure 15 Figure 1500 shows a message sequence diagram for updating PQC support via any N1 message in a configuration update command or an identification request. As shown in step 1502, the core network 1002 can update its PQC / legacy support status to the UE 202 via any N1 message (such as a configuration update command message) to request the UE 202 to share the SUCI using a new security profile (legacy / PQC) starting from the next identification response. The core network 1002 can send an identification request for the SUCI to the UE 202, as shown in step 1504. The UE 202 sends an identification response with the SUPI hidden using the new security profile type to the core network 1002, as shown in step 1506.

[0196] 8.2.19 Configuration Update Command

[0197] Table 21 indicates the new IEI. A new IEI can be introduced for the PQC support type.

[0198]

[0199] Table 21

[0200] Figure 16 Figure 1600 shows a message sequence diagram for updating the security profile via any N1 message in a configuration update command or a registration request. As shown in step 1602, the core network 1002 can update its security profile to the UE 202 via any N1 message (such as a UE configuration update message) to request the UE 202 to share the SUCI using a new security profile (legacy / PQC) starting from the next registration request. The UE 202 can send a registration request with the SUPI hidden using the new security profile type, as shown in step 1604.

[0201] Figure 17FIG. 1700 shows a message sequence diagram for updating a security profile by any N1 message in a configuration update command or an identification request. As shown in step 1702, the core network 1002 may update its security profile for the UE 202 by any N1 message, such as a UE configuration update message, to request the UE 202 to use a new type of security profile (conventional / PQC) to share the SUCI starting from the next identification response. The core network 1002 may send an identification request for the SUCI to the UE 202, as shown in step 1704. The UE 202 may send an identification response with the SUPI hidden using the new type of security profile to the core network 1002, as shown in step 1706.

[0202] Figure 18 FIG. 1800 shows a message sequence diagram for PQC / conventional support update or profile update via a BIP session in a registration request. As shown in step 1802, the core network 1002 may update its PQC / conventional support or security profile for the UE 202 by any independent bearer protocol message to request the UE 202 to use a new type of security profile (conventional / PQC) to share the SUCI starting from the next registration request. The UE 202 may send a registration request with the SUPI hidden using the new type of security profile, as shown in step 1804. The default conventional / PQC profile may be used according to network support.

[0203] Figure 19 FIG. 1900 shows a message sequence diagram for PQC / conventional support update or profile update via a BIP session in an identification request. As shown in step 1902, the core network 1002 may update its PQC / conventional support or security profile for the UE 202 by any independent bearer protocol message to request the UE 202 to use a new type of security profile (conventional / PQC) to share the SUCI starting from the next registration request. The core network 1002 may send an identification request for the SUCI to the UE 202, as shown in step 1904. The UE 202 may send an identification response with the SUPI hidden using the new type of security profile, as shown in step 1906.

[0204] Figure 20Illustrates the process design for AI / ML-based PQC profile selection. An ML / AI-based model can be created and trained using UE parameters, network parameters, or application parameters as inputs, and then the PQC profile can be learned from the created model. This PQC profile can be sent to the upper layer for SUCI hiding or any application use. UE parameters can include, but are not limited to, UE type (such as Internet of Things (IoT) device / low-power UE), network slice type, supported security level, one or more security algorithms supported by UE202, etc. Network parameters can include, but are not limited to, physical cell ID, provided core network service name, etc. Application parameters can include, but are not limited to, application ID that requires a PQC profile for authentication or signature.

[0205] Figure 21 Illustrates a method 2100 for selecting a PQC profile in a communication network 204 through an AI model. The method 2100 includes: as shown in step 2102, UE 202 creates and trains an AI-based model using at least one input including one of one or more UE parameters, one or more network parameters, and one or more application parameters. The method 2100 includes: as shown in step 2104, UE 202 learns at least one PQC profile using the trained AI-based model. The method 2100 includes: as shown in step 2106, UE 202 sends the learned PQC profile to the upper layer for at least one of user identity encryption and UE data encryption.

[0206] The various actions in method 2100 can be performed in the order shown, or in a different order or simultaneously. Additionally, in some embodiments, Figure 21 some of the actions listed in can be omitted.

[0207] Therefore, the proposed system 200 employs the PQC security algorithm of the ultra 5G network to avoid the threats posed by quantum machines, as quantum machines may crack the current encryption algorithms based on asymmetric, symmetric, and hash. The proposed system 200 especially employs the PQC security algorithm for SUCI encryption / decryption during initial authentication, where user privacy is of utmost importance.

[0208] The proposed methods 500, 900, 2100 and the signaling mechanism of the configuration file selection process for the ultra 5G network can support multiple encryption algorithm configuration files between the UE 202 and the communication network 204, such as 5G traditional algorithms and / or post-quantum cryptographic algorithms and / or quantum algorithms. The introduction of PQC / traditional profile selection based on UICC pre-configuration introduces new network service support elements and adds elementary files to the UICC to support post-quantum / quantum cryptography. The PQC / traditional profile selection performed by the core network provides the selection / update of PQC support and security profiles through any N1 message. The proposed methods 500, 900, 2100 provide PQC / traditional profile updates through the BIP session between the UE 202 and the communication network 204. The proposed methods 500, 900, 2100 provide machine learning-based PQC profile selection. The proposed methods 500, 900, 2100 define the N1 / RRC / SIB / MIB message structures to support traditional, post-quantum or quantum-based profile selection. The methods 500, 900, 2100 provide an indication of post-quantum or quantum support from the communication network 204 to the UE 202. The methods 500, 900, 2100 provide an indication of post-quantum or quantum profiles from the communication network 204 to the UE 202. The methods 500, 900, 2100 provide a new state machine at the UE 202 and the communication network 204 for maintaining the post-quantum state. Therefore, post-quantum cryptography is regarded as one of the key technologies for 6G security.

[0209] Figure 22 The structure of a UE to which embodiments of the present disclosure can be applied is shown.

[0210] Reference Figure 22 , the UE includes a radio frequency (RF) processor 2210, a baseband processor 2220, a storage unit 2230, and a controller 2240.

[0211] The RF processor 2210 performs functions of transmitting and receiving signals through a wireless channel, such as frequency band conversion and amplification of signals. That is, the RF processor 2210 up-converts the baseband signal provided by the baseband processor 2220 into an RF band signal, transmits the RF band signal through an antenna, and then down-converts the RF band signal received through the antenna into a baseband signal. For example, the RF processor 2210 may include a transmit filter, a receive filter, an amplifier, a mixer, an oscillator, a digital-to-analog converter (DAC), an analog-to-digital converter (ADC), etc. Although Figure 22Only one antenna is shown, but the UE may include multiple antennas. In addition, the RF processor 2210 may include multiple RF chains. Moreover, the RF processor 2210 may perform beamforming. To perform beamforming, the RF processor 2210 may control the phase and amplitude of each signal transmitted / received through the multiple antennas or antenna elements. The RF processor may perform MIMO and receive multiple layers when performing MIMO operations. The RF processor 2210 may appropriately configure the multiple antennas or antenna elements according to the control of the controller to perform scanning of the receiving beam or control the direction and beam width of the receiving beam so that the receiving beam corresponds to the transmitting beam.

[0212] The baseband processor 2220 performs the conversion function between the baseband signal and the bit stream according to the physical layer standard of the system. For example, when transmitting data, the baseband processor 2220 generates complex symbols by encoding and modulating the transmitted bit stream. In addition, when receiving data, the baseband processor 2220 reconstructs the received bit stream by demodulating and decoding the baseband signal provided by the RF processor 2210. For example, in the orthogonal frequency division multiplexing (OFDM) scheme, when transmitting data, the baseband processor 2220 encodes and modulates the transmitted bit stream, maps the complex symbols to subcarriers, and then configures the OFDM symbols through the inverse fast Fourier transform (IFFT) operation and cyclic prefix (CP) insertion. In addition, when receiving data, the baseband processor 2220 divides the baseband signal provided by the RF processor 2210 in units of OFDM symbols, reconstructs the signal mapped to the subcarriers through the fast Fourier transform (FFT) operation, and then reconstructs the received bit stream through demodulation and decoding.

[0213] The baseband processor 2220 and the RF processor 2210 transmit and receive signals as described above. Therefore, the baseband processor 2220 and the RF processor 2210 may be referred to as a transmitter, a receiver, a transceiver, or a communication unit. In addition, at least one of the baseband processor 2220 and the RF processor 2210 may include multiple communication modules to support a variety of different radio access technologies. Additionally, at least one of the baseband processor 2220 and the RF processor 2210 may include different communication modules to process signals in different frequency bands. For example, different radio access technologies may include an LTE network and an NR network. In addition, different frequency bands may include the super high frequency (SHF) (e.g., 2.5 GHz and 5 GHz) bands and the millimeter wave (e.g., 60 GHz) bands.

[0214] The storage unit 2230 stores data such as basic programs, applications, and setting information for UE operation. The storage unit 2230 provides the stored data according to the request of the controller 2240.

[0215] The controller 2240 controls the overall operation of the UE. For example, the controller 2240 transmits / receives signals through the baseband processor 2220 and the RF processor 2210. In addition, the controller 2240 may record data in and read data from the storage unit 2230. To this end, the controller 2240 may include at least one processor. For example, the controller 2240 may include a communication processor (CP) that performs communication control and an application processor (AP) that controls high-levels such as applications.

[0216] Figure 23 A block diagram of a base station in a wireless communication system to which embodiments of the present disclosure may be applied is shown.

[0217] As Figure 23 shown, the base station includes an RF processor 2310, a baseband processor 2320, a backhaul communication unit 2330, a storage unit 2340, and a controller 2350.

[0218] The RF processor 2310 performs functions of transmitting and receiving signals through a wireless channel, such as frequency band conversion and amplification of signals. That is, the RF processor 2310 up-converts the baseband signal provided by the baseband processing unit 2320 into an RF band signal, then transmits the converted signal through an antenna, and down-converts the RF band signal received through the antenna into a baseband signal. For example, the RF processor 2310 may include a transmit filter, a receive filter, an amplifier, a mixer, an oscillator, a DAC, and an ADC. Although Figure 23 only one antenna is shown, the first access node may include multiple antennas. In addition, the RF processor 2310 may include multiple RF chains. Moreover, the RF processor 2310 may perform beamforming. To perform beamforming, the RF processor 2310 may control the phase and amplitude of each signal transmitted and received through multiple antennas or antenna elements. The RF processor may perform downlink MIMO operations by transmitting one or more layers.

[0219] The baseband processor 2320 performs the conversion function between baseband signals and bitstreams according to the physical layer standard of the first radio access technology. For example, when transmitting data, the baseband processor 2320 generates complex symbols by encoding and modulating the transmitted bitstream. In addition, when receiving data, the baseband processor 2320 reconstructs the received bitstream by demodulating and decoding the baseband signal provided by the RF processor 2310. For example, in the OFDM scheme, when transmitting data, the baseband processor 2320 can encode and modulate the transmitted bitstream, map the complex symbols to subcarriers, and then configure the OFDM symbols through IFFT operations and CP insertion. Additionally, when receiving data, the baseband processor 2320 divides the baseband signal provided by the RF processor 2310 into OFDM symbol units, restores the signal mapped to the subcarriers through FFT operations, and then restores the received bitstream through demodulation and decoding. The baseband processor 2320 and the RF processor 2310 transmit and receive signals as described above. Therefore, the baseband processor 2320 and the RF processor 2310 can be referred to as transmitters, receivers, transceivers, or communication units.

[0220] The communication unit 2330 provides an interface for communicating with other nodes within the network.

[0221] The storage unit 2340 stores data such as basic programs, applications, and setting information for MeNB operations. In particular, the storage unit 2340 can store information about the bearers allocated to the access UEs and the measurement results reported by the access UEs. In addition, the storage unit 2340 can store information about the reference for determining whether to provide multiple connections to the UEs or to stop multiple connections. Additionally, the storage unit 2340 provides the data stored therein according to the request of the controller 2350.

[0222] The controller 2350 controls the overall operation of the MeNB. For example, the controller 2350 transmits and receives signals through the baseband processor 2320 and the RF processor 2310 or through the backhaul communication unit 2330. In addition, the controller 2350 can record data in and read data from the storage unit 2340. To this end, the controller 2350 can include at least one processor.

[0223] Although the present disclosure has been described in conjunction with various embodiments, those skilled in the art can make various changes and modifications. The present disclosure is intended to cover such changes and modifications that fall within the scope of the appended claims.

[0224] Figure 24 is a configuration diagram of a network entity according to an embodiment. This network entity can correspond to the AMF node in each embodiment. Refer to Figure 24, the network entity may include a transceiver 2410, a controller 2420, and a storage unit 2430. The controller 2420 may be defined as a circuit, an application specific integrated circuit, or at least one processor.

[0225] The transceiver 2410 may send / receive signals to / from other network entities. The controller 2420 may control the overall operation of the UE. The storage unit 2430 may store at least one piece of information sent / received through the transceiver 2410 and information generated through the controller 2420.

[0226] Various embodiments of the present disclosure may be implemented by software including instructions stored in a machine (e.g., a computer) readable storage medium. The machine may be a device that calls instructions from the machine readable storage medium and operates according to the called instructions, and may include an electronic device. When the instructions are executed by a processor, the processor may directly execute the functions corresponding to the instructions, or execute the functions using other components under the control of the processor. The instructions may include code generated or executed by a compiler or an interpreter. The machine readable storage medium may be provided in the form of a non-transitory storage medium. Here, as used herein, the term "non-transitory" is a limitation on the medium itself (i.e., tangible, rather than a signal), rather than a limitation on the persistence of data storage.

[0227] Embodiments disclosed herein may be implemented by at least one software program running on at least one hardware device, the software program performing network management functions to control network elements. Figure 2 The network elements shown in include modules that may be at least one of a hardware device, or a combination of a hardware device and software modules.

[0228] The embodiments disclosed herein describe methods and systems 200 for designing mechanisms and processes involved in secure profile selection in a wireless communication network. Thus, it can be understood that the scope of protection extends to such programs, and in addition to the computer-readable means containing messages therein, such computer-readable storage means contains program code means for implementing one or more steps of the method when the program runs on a server, a mobile device, or any suitable programmable device. The method is implemented, in at least one embodiment, by a software program written, for example, in Very High Speed Integrated Circuit Hardware Description Language (VHDL) or other programming languages, or by one or more VHDL or several software modules executed on at least one hardware device. The hardware device can be any programmable portable device. The device can also include, for example, hardware means such as an ASIC, or a combination of hardware and software means such as an ASIC and an FPGA, or at least one microprocessor and at least one memory containing software modules. The method embodiments described herein can be implemented partly in hardware and partly in software. Alternatively, the present invention can be implemented on different hardware devices, for example, using multiple CPUs.

[0229] The foregoing description of specific embodiments will fully disclose the general nature of the embodiments herein, such that others can, by applying current knowledge, readily modify and / or adapt these specific embodiments for various applications without departing from the general concept. Therefore, these adaptations and modifications should and are intended to be understood as being within the equivalent meaning and scope of the disclosed embodiments. It should be understood that the phrases or terms employed herein are for the purpose of description and not of limitation. Thus, although the embodiments herein are described in terms of embodiments and examples, those skilled in the art will recognize that the embodiments and examples disclosed herein can be practiced with modifications within the scope of the embodiments described herein.

Claims

1. A method performed by a user equipment UE in a wireless communication system, the method comprising: Receiving configuration information about a new network service for a universal integrated circuit card UICC from a network entity; Configuring at least one security profile identifier in one of the UE and the UICC for adding at least one security profile in a priority order; And Based on the configuration information, selecting the at least one security profile using the configured at least one security profile identifier.

2. The method according to claim 1, Among them, The at least one security profile includes at least one of a legacy profile or a post-quantum cryptography PQC profile, Wherein, the at least one security profile identifier is configured as a combined part of the legacy profile and the PQC profile, and Wherein, one or more security profile identifiers are configured as separate parts of the legacy profile and the PQC profile.

3. The method according to claim 1, Among them, The new network service includes an independent network service and a dependent network service, Wherein, the independent network service is independent of an existing network service, Wherein, the dependent network service depends on the existing network service, and Wherein, the new network service is configured in the UICC to enable one or more PQC algorithms to perform at least one of user identity encryption and UE data encryption.

4. The method according to claim 3, wherein selecting the at least one security profile includes: Verifying the new network service; In the case where the new network service is an independent network service and is enabled, performing at least one of the user identity encryption and the UE data encryption using a PQC profile; In the case where the new network service is an independent network service and is disabled, performing at least one of the user identity encryption and the UE data encryption using a legacy profile; And Selecting the at least one security profile identifier with a high priority from the legacy profile and the PQC profile.

5. The method according to claim 3, wherein selecting the at least one security profile includes: Verifying the new network service; In the case where the new network service is a dependent network service and both the existing network service and the dependent network service are enabled, performing at least one of the user identity encryption and the UE data encryption using a PQC profile; In the case where the new network service is a dependent network service and one of the existing network service and the dependent network service is disabled, performing at least one of the user identity encryption and the UE data encryption using a legacy profile; And Selecting the at least one security profile identifier with a high priority from the legacy profile and the PQC profile.

6. The method according to claim 1, further comprising: Receiving a message for updating the at least one security profile from the network entity, wherein the message includes at least one of a security support indication and a security profile indication; Update the at least one security configuration file based on the received message; and Send a registration request message to the communication network based on the at least one updated security configuration file, the registration request message including at least one of user identity encryption and UE data encryption.

7. A method performed by a network entity in a wireless communication system, the method comprising: Generate configuration information about a new network service for a Universal Integrated Circuit Card (UICC); And Send the configuration information about the new network service for the UICC to a User Equipment (UE); Wherein, at least one security configuration file identifier is configured in one of the UE and the UICC for adding at least one security configuration file in a priority order, and Wherein, the at least one security configuration file is selected based on the configuration information by using at least one configured security configuration file identifier.

8. The method according to claim 1, Among them, The at least one security configuration file includes at least one of a legacy configuration file or a Post-Quantum Cryptography (PQC) configuration file, Wherein, the at least one security configuration file identifier is configured as a combined part of the legacy configuration file and the PQC configuration file, and Wherein, one or more security configuration file identifiers are configured as separate parts of the legacy configuration file and the PQC configuration file.

9. A User Equipment (UE) in a wireless communication system, the UE comprising: A transceiver; And A controller configured to: Receive configuration information about a new network service for a Universal Integrated Circuit Card (UICC) from a network entity; Configure at least one security configuration file identifier in one of the UE and the UICC for adding at least one security configuration file in a priority order; And Select the at least one security configuration file based on the configuration information by using the configured at least one security configuration file identifier.

10. The UE according to claim 9, Among them, The at least one security configuration file includes at least one of a legacy configuration file or a Post-Quantum Cryptography (PQC) configuration file, Wherein, the at least one security configuration file identifier is configured as a combined part of the legacy configuration file and the PQC configuration file, and Wherein, one or more security configuration file identifiers are configured as separate parts of the legacy configuration file and the PQC configuration file.

11. The UE according to claim 9, Among them, The new network service includes a stand-alone network service and a dependent network service, Wherein, the stand-alone network service is independent of the existing network service, Wherein, the dependent network service depends on the existing network service, and Wherein, the new network service is configured in the UICC for enabling one or more PQC algorithms to perform at least one of user identity encryption and UE data encryption.

12. The UE according to claim 11, wherein, The controller is further configured to: Verify the new network service, In the case where the new network service is a stand-alone network service and is enabled, perform at least one of the user identity encryption and the UE data encryption by using the PQC configuration file When the new network service is an independent network service and is disabled, at least one of the user identity encryption and the UE data encryption is performed using a traditional configuration file, and select at least one security configuration file identifier with a high priority from the traditional configuration file and the PQC configuration file.

13. The UE according to claim 11, wherein, The controller is further configured to: verify the new network service, when the new network service is a dependent network service and both the existing network service and the dependent network service are enabled, at least one of the user identity encryption and the UE data encryption is performed using a PQC configuration file, when the new network service is a dependent network service and one of the existing network service and the dependent network service is disabled, at least one of the user identity encryption and the UE data encryption is performed using a traditional configuration file, and select at least one security configuration file identifier with a high priority from the traditional configuration file and the PQC configuration file.

14. The UE according to claim 11, wherein, The controller is further configured to: receive a message for updating at least one security configuration file from a network entity, where the message includes at least one of a security support indication and a security configuration file indication, update at least one security configuration file based on the received message, and send a registration request message to the communication network based on at least one updated security configuration file, where the registration request message includes at least one of user identity encryption and UE data encryption.

15. A network entity in a wireless communication system, the network entity comprising: a transceiver; and a controller configured to: generate configuration information about a new network service for a universal integrated circuit card UICC; and send the configuration information about the new network service for the UICC to a user equipment UE, where at least one security configuration file identifier is configured in one of the UE and the UICC for adding at least one security configuration file in a priority order, and where the at least one security configuration file is selected based on the configuration information by using at least one configured security configuration file identifier.