Method and system for primary authentication using hybrid key exchange / hybrid encryption in communication network

By adopting hybrid key exchange and hybrid encryption methods in wireless communication systems, combining EC and PQC algorithms to generate temporary shared keys, the security issues of traditional ECC algorithms under the threat of quantum computers are solved, and high-security authentication and data encryption against quantum attacks are achieved.

CN120642379APending Publication Date: 2025-09-12SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480012199.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-02-13
Filing Date
2024-02-13
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

When facing the threat of quantum computers, the traditional elliptic curve cryptography (ECC) algorithm of existing wireless communication systems is insecure and cannot effectively protect the subscription permanent identifier (SUPI) between the user equipment (UE) and the home network (HN), making the main authentication process vulnerable to attacks.

Method used

A hybrid key exchange and hybrid encryption method is adopted, combined with elliptic curve (EC) key generation technology and post-quantum cryptography (PQC) to generate a temporary shared key, which is used to generate ciphertext values ​​and message authentication codes to implement the UE registration process with the HN.

Benefits of technology

Provides high security against quantum threats, prevents "store now, decrypt later" attacks, supports hybrid security, ensures data encryption between UE and HN, and is not limited to hiding SUPI.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120642379A_ABST
    Figure CN120642379A_ABST
Patent Text Reader

Abstract

The present disclosure relates to a 5G communication system or a 6G communication system for supporting higher data rates beyond 4G communication systems such as Long Term Evolution (LTE). The present disclosure discloses a method for registering a user equipment (UE) (101) with a home network (HN) (103) using a hybrid key exchange, the method comprising generating a temporary public key and a temporary private key, and generating a first temporary shared key based on the temporary private key and a home network public key based on an elliptic curve (EC). Further, the method includes generating a second temporary shared key and an encrypted shared key based on the post quantum cryptography-based public key. Further, the method includes generating a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key, and generating a ciphertext value and a message authentication code tag value. Finally, the method includes sending a registration request for registering the UE with the home network, along with the temporary public key, the encrypted shared key, the ciphertext value, and the MAC tag value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates generally to wireless communication networks and, more particularly, to methods and systems / apparatus for registering a user equipment (UE) with a home network (HN) using hybrid key exchange and hybrid key encryption in a communication network (e.g., a 6G network). Background Art

[0002] As wireless communications have advanced over generations, technologies have been developed primarily for services targeting humans, such as voice calls, multimedia services, and data services. Following the commercialization of 5G (5th Generation) communication systems, the number of connected devices is expected to grow exponentially. These devices will increasingly be connected to communication networks. Examples of connected things include vehicles, robots, drones, home appliances, displays, smart sensors connected to various infrastructure, construction machinery, and factory equipment. Mobile devices are expected to evolve into various form factors, such as augmented reality glasses, virtual reality headsets, and holographic devices. To provide a variety of services in the 6G (6th Generation) era by connecting hundreds of billions of devices and things, efforts are ongoing to develop improved 6G communication systems. For these reasons, 6G communication systems are referred to as beyond 5G systems.

[0003] The 6G communication system, which is expected to be commercialized around 2030, will have a peak data rate of terabit (1,000 gigabits) per second and a radio latency of less than 100 microseconds, and will therefore be 50 times faster than the 5G communication system and have 1 / 10 the radio latency of the 5G communication system.

[0004] To achieve such high data rates and ultra-low latency, 6G communication systems are being considered in the terahertz band (e.g., the 95 GHz to 3 THz band). Because path loss and atmospheric absorption in the terahertz band are expected to be more severe than in the mmWave band introduced in 5G, technologies that ensure signal transmission distance (i.e., coverage) will become even more critical. Key technologies for ensuring coverage include the development of radio frequency (RF) components, antennas, novel waveforms with better coverage than orthogonal frequency division multiplexing (OFDM), beamforming, massive multiple-input multiple-output (MIMO), full-dimensional MIMO (FD-MIMO), array antennas, and multi-antenna transmission technologies such as massive antennas. Furthermore, new technologies for improving terahertz band signal coverage are being discussed, such as metamaterial-based lenses and antennas, orbital angular momentum (OAM), and reconfigurable smart surfaces (RIS).

[0005] Furthermore, to improve spectrum efficiency and overall network performance, the following technologies are being developed for 6G communication systems: full-duplex technology, enabling uplink and downlink transmissions to use the same frequency resources simultaneously; network technologies for integrated utilization of satellites, high-altitude platform stations (HAPS), and other systems; improved network structures for supporting mobile base stations and enabling network operation optimization and automation; dynamic spectrum sharing technologies for collision avoidance based on prediction of spectrum usage; the use of artificial intelligence (AI) in wireless communications to improve overall network operations by leveraging AI from the design phase of 6G development and internalizing end-to-end AI support functions; and next-generation distributed computing technologies for overcoming the limitations of UE computing capabilities by enabling ultra-high-performance communication and computing resources on the network, such as mobile edge computing (MEC) and the cloud. Furthermore, efforts are continuing to enhance connectivity between devices, optimize networks, promote the softwareization of network entities, and increase the openness of wireless communications by designing new protocols for use in 6G communication systems, developing mechanisms for implementing hardware-based security environments and secure data usage, and developing technologies for maintaining privacy.

[0006] Research and development of 6G communication systems in hyper-connectivity, including human-to-machine (P2M) and machine-to-machine (M2M), are expected to enable the next generation of hyper-connected experiences. Specifically, 6G communication systems are expected to provide services such as truly immersive extended reality (XR), high-fidelity mobile holograms, and digital replicas. Furthermore, services such as remote surgery, industrial automation, and emergency response for enhanced safety and reliability will be provided through 6G communication systems, enabling these technologies to be applied in various fields such as industry, healthcare, automobiles, and home appliances. Summary of the Invention

[0007] Technical issues

[0008] The present invention solves at least the above problems and / or disadvantages and provides at least the advantages described below.Accordingly, one aspect of the present invention provides a method and apparatus for primary authentication using hybrid key exchange and hybrid encryption in a communication network.

[0009] Solution to the problem

[0010] According to one aspect of the present disclosure, a method performed by a user equipment is provided. The method includes: generating (702) an ephemeral public key and an ephemeral private key based on an elliptical curve (EC) key generation technique; generating (704) a first temporary shared key based on the temporary private key and a home network public key based on an elliptical curve (EC); generating (706) a second temporary shared key and an encrypted shared key based on a public key associated with the home network based on post-quantum cryptography (PQC); generating (708) a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key; generating (710) a cipher-text value and a message authentication code (MAC) tag value based on at least the temporary hybrid shared key; and sending (712) a registration request for registering the UE (101) with the home network (103), along with the ephemeral public key, the encrypted shared key, the cipher-text value, and the MAC tag value.

[0011] According to one aspect of the present disclosure, a method performed by a home network is provided. The method includes: receiving a registration request from a UE, wherein the registration request includes a temporary public key, an encrypted shared key, a ciphertext value, and a message authentication code (MAC) tag value; generating a first temporary shared key based on at least the temporary public key and a public key based on Elliptical Curve Cryptography (ECC) associated with the home network (103); generating a second temporary shared key based on the encrypted shared key and a private key based on Post Quantum Cryptography (PQC) associated with the home network (103); generating a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key; generating a temporary decryption key and a temporary MAC key based on at least the temporary hybrid shared key; generating plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key; and registering the UE (101) with the home network (103) based on the generated plaintext.

[0012] According to one aspect of the present disclosure, a user equipment is provided. The user equipment includes: a transceiver; and a controller configured to generate a temporary public key and a temporary private key based on an elliptic curve (EC) key generation technique, generate a first temporary shared key based on the temporary private key and a home network public key based on an elliptic curve (EC), generate a second temporary shared key and an encrypted shared key based on a public key associated with the home network based on post-quantum cryptography (PQC), generate a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key, generate a ciphertext value and a message authentication code (MAC) tag value based on at least the temporary hybrid shared key, and send a registration request for registering a UE (101) to the home network (103), as well as the temporary public key, the encrypted shared key, the ciphertext value, and the MAC tag value.

[0013] According to one aspect of the present disclosure, a home network is provided. The home network includes: a transceiver; and a controller configured to receive a registration request from a UE, wherein the registration request includes a temporary public key, an encrypted shared key, a ciphertext value, and a message authentication code (MAC) tag value, generate a first temporary shared key based on at least the temporary public key and a public key based on elliptic curve cryptography (ECC) associated with the home network (103), generate a second temporary shared key based on the encrypted shared key and a private key based on post-quantum cryptography (PQC) associated with the home network (103), generate a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key, generate a temporary decryption key and a temporary MAC key based on at least the temporary hybrid shared key, generate plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key, and register the UE (101) to the home network (103) based on the generated plaintext.

[0014] Advantageous Effects of the Invention

[0015] In an embodiment, the present disclosure provides shared key generation that combines with traditional ECC and PQC algorithms to derive a shared key. This key performs SUPI concealment for primary authentication between the UE and the HN. Furthermore, the present disclosure provides a hybrid encryption method that allows minimal modification to current 3GPP specifications to support hybrid security. Thus, the present disclosure prevents "store now, decrypt later" attacks.

[0016] In an embodiment, the present disclosure generates a hybrid shared key that can be used to hide SUPI. This shared key provides security against quantum threats and has a high security guarantee. This hybrid shared key can also be used to encrypt data between the UE and the network, and is not limited to SUPI.

[0017] Advantages and salient features of the present invention will become apparent to those skilled in the art through the following detailed description of exemplary embodiments of the present invention disclosed in conjunction with the accompanying drawings.For more enhanced communication systems, methods and networks are needed to generate waveforms with low peak-to-average power ratio using phase continuity. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The novel features and characteristics of the present disclosure are set forth in the appended claims. However, the disclosure itself, as well as the preferred mode of use, further objects and advantages, will be best understood by reference to the following detailed description of illustrative embodiments when read in conjunction with the accompanying drawings. One or more embodiments will now be described, by way of example only, with reference to the accompanying drawings, wherein like reference numerals represent like elements, and wherein:

[0019] Figure 1A The format and protocol output of SUCI as defined in the prior art are shown.

[0020] Figure 1B A flow chart of a Subscription Permanent Identifier (SUPI) hiding procedure at a UE based on an Elliptic Curve Based Integrated Encryption Scheme (ECIES) according to the prior art is shown.

[0021] Figure 1C A flow chart of the SUCI de-concealment process at the HN 103 based on ECIES according to the prior art is shown.

[0022] Figure 1D The complete sequence flow chart of the SUCI hiding and de-hiding process according to the prior art is briefly shown.

[0023] Figure 2A An exemplary environment 200a is shown in which a user equipment (UE) 101 is registered with a home network (HN) 103 according to some embodiments of the present disclosure.

[0024] Figure 2B A detailed block diagram 200b of the UE 101 shown in FIG. 1 is shown according to some embodiments of the present disclosure.

[0025] Figure 2C A detailed block diagram 200c of the HN 103 shown in FIG. 1 is shown, according to some embodiments of the present disclosure.

[0026] Figure 2D A detailed block diagram 200d of the UE 101 shown in FIG. 1 is shown according to some embodiments of the present disclosure.

[0027] Figure 2E A detailed block diagram 200e of the HN 103 shown in FIG. 1 is shown, according to some embodiments of the present disclosure.

[0028] Figure 2F A flow chart illustrating hybrid SUPI hiding at the UE 101 using legacy and PQC based shared key generation according to some embodiments of the present disclosure is shown.

[0029] Figure 2G A block diagram illustrating the output of a modified scheme based on hybrid SUPI hiding using traditional and PQC based shared key generation according to some embodiments of the present disclosure is shown.

[0030] Figure 2H A flow chart illustrating hybrid SUCI de-concealment at UE 101 using legacy and PQC based shared key generation according to some embodiments of the present disclosure is shown.

[0031] Figure 2I A sequence diagram illustrating hybrid SUPI hiding and de-hiding using conventional and PQC based shared key generation according to some embodiments of the present disclosure is shown.

[0032] Figure 3A A flow chart illustrating hybrid SUPI hiding at the UE 101 using PQC and PQC-based shared key generation according to some embodiments of the present disclosure is shown.

[0033] Figure 3B A block diagram illustrating the output of a modified scheme based on hybrid SUPI hiding using PQC and PQC-based shared key generation according to some embodiments of the present disclosure is shown.

[0034] Figure 3C A flow chart is shown for hybrid SUCI de-concealment at the UE 101 using PQC and PQC-based shared key generation according to some embodiments of the present disclosure.

[0035] Figure 3D A sequence diagram illustrating hybrid SUPI hiding and de-hiding using PQC and PQC-based shared key generation according to some embodiments of the present disclosure is shown.

[0036] Figure 4A A flow chart illustrating hybrid SUPI hiding at the UE 101 using legacy and PQC based shared key encryption according to some embodiments of the present disclosure is shown.

[0037] Figure 4B A flow chart illustrating hybrid SUCI de-concealment at the UE 101 using traditional and PQC based shared key decryption according to some embodiments of the present disclosure is shown.

[0038] Figure 4C A sequence diagram illustrating hybrid SUPI hiding and de-hiding using conventional and PQC based shared key encryption and decryption according to some embodiments of the present disclosure is shown.

[0039] Figure 5A A flow chart illustrating hybrid SUPI concealment at the UE 101 using PQC and PQC-based ciphering in a parallel manner according to some embodiments of the present disclosure is shown.

[0040] Figure 5B A block diagram illustrating a modified scheme output based on hybrid SUPI hiding using PQC and PQC-based shared key encryption in a parallel manner according to some embodiments of the present disclosure is shown.

[0041] Figure 5C A flow chart illustrating hybrid SUCI de-concealment at the HN 103 using PQC and PQC-based decryption in a parallel manner according to some embodiments of the present disclosure is shown.

[0042] Figure 6A A flow chart illustrating hybrid SUPI concealment at the UE 101 using PQC and PQC-based ciphering in a sequential manner according to some embodiments of the present disclosure is shown.

[0043] Figure 6B A block diagram illustrating the output of a modified scheme based on hybrid SUPI concealment using PQC and PQC-based encryption according to some embodiments of the present disclosure is shown.

[0044] Figure 6C A flow chart illustrating hybrid SUPI de-concealment at the HN 103 using PQC and PQC-based decryption in a sequential manner according to some embodiments of the present disclosure is shown.

[0045] Figure 7A Shown is a flow chart illustrating a method 700a for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key exchange according to some embodiments of the present disclosure.

[0046] Figure 7B Shown is a flow chart illustrating a method 700b for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key exchange according to some embodiments of the present disclosure.

[0047] Figure 7C Shown is a flow chart illustrating a method 700c for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key exchange according to some embodiments of the present disclosure.

[0048] Figure 7D A flow chart illustrating a method 700d for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key exchange according to some embodiments of the present disclosure is shown.

[0049] Figure 8A A flow chart illustrating an alternative method 800a for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption is shown, according to some embodiments of the present disclosure.

[0050] Figure 8B Shown is a flow chart illustrating a method 800b for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure.

[0051] Figure 8C Shown is a flow chart illustrating a method 800c for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure.

[0052] Figure 8D Shown is a flow chart illustrating a method 800d for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure.

[0053] Figure 8E Shown is a flow chart illustrating a method 800e for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure.

[0054] Figure 8F Shown is a flow chart illustrating a method 800f for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure. DETAILED DESCRIPTION

[0055] These and other aspects of the example embodiments herein will be better appreciated and understood when considered in conjunction with the following description and accompanying drawings. However, it should be understood that the following description, while indicating example embodiments and many of their specific details, is given by way of illustration and not limitation. Many changes and modifications may be made within the scope of the example embodiments herein without departing from the spirit thereof, and the example embodiments herein include all such modifications.

[0056] The embodiments of this invention and their various features and advantageous details are explained more fully with reference to the non-limiting embodiments shown in the accompanying drawings and described in detail in the following description. Descriptions of well-known components and processing techniques are omitted so as not to unnecessarily obscure the embodiments of this invention. The examples used herein are intended only to facilitate understanding of the manner in which the embodiments of this invention may be practiced and to further enable those skilled in the art to practice the embodiments of this invention. Therefore, the examples should not be interpreted as limiting the scope of the embodiments of this invention.

[0057] For the purposes of interpreting this specification, the definitions (as defined herein) will apply, and where appropriate, terms used in the singular will also include the plural, and vice versa. It should be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. Unless otherwise specified, the terms "including," "having," and "comprising" should be interpreted as open-ended terms.

[0058] The words / phrases “exemplary,” “example,” “illustrative,” “in an instance,” “and the like,” “and so on,” “etc.,” “etcetera,” “for example,” and “i.e.” are used herein merely to mean “serving as an example, instance, or illustration.” Any embodiment or implementation of the subject matter described herein using the words / phrases “exemplary,” “example,” “illustrative,” “in an instance,” “and the like,” “and so on,” “etc.,” “etcetera,” “for example,” and “i.e.” are not necessarily to be construed as preferred or advantageous over other embodiments.

[0059] The embodiments herein may be described and illustrated in terms of blocks that perform one or more of the described functions. These blocks, which may be referred to herein as managers, units, modules, hardware components, etc., are physically implemented by analog and / or digital circuitry (such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hard-wired circuitry, etc.) and may optionally be driven by firmware. The circuitry may, for example, be embodied in one or more semiconductor chips or on a substrate support such as a printed circuit board. The circuitry comprising a block may be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuitry), or by a combination of dedicated hardware that performs some of the functions of the block and a processor that performs other functions of the block. Each block of an embodiment may be physically separated into two or more interacting and discrete blocks without departing from the scope of this disclosure. Similarly, the blocks of an embodiment may be physically combined into more complex blocks without departing from the scope of this disclosure.

[0060] It should be noted that the elements in the accompanying drawings are shown for the purposes of this description and ease of understanding, and may not necessarily be drawn to scale. For example, a flow chart / sequence diagram illustrates the method in terms of the steps required to understand the various aspects of the embodiments disclosed herein. Furthermore, depending on the configuration of the device, one or more components of the device may have been represented in the accompanying drawings by conventional symbols, and the accompanying drawings may only show those specific details relevant to understanding the present embodiment, so as not to obscure the drawings with details that would be readily apparent to a person of ordinary skill in the art having the benefit of the description herein. Furthermore, depending on the system, one or more components / modules comprising the system may have been represented in the accompanying drawings by conventional symbols, and the accompanying drawings may only show those specific details relevant to understanding the present embodiment, so as not to obscure the drawings with details that would be readily apparent to a person of ordinary skill in the art having the benefit of the description herein.

[0061] The accompanying drawings are used to facilitate easy understanding of various technical features, and it should be understood that the embodiments presented herein are not limited by the accompanying drawings. Therefore, the present disclosure should be interpreted as extending to any modifications, equivalents, and alternatives other than those specifically set forth in the accompanying drawings and corresponding descriptions. The use of words such as first, second, and third to describe components / elements / steps is for the purpose of this description and should not be interpreted as sequential ordering / placement / appearance unless otherwise specified.

[0062] It should be understood by those skilled in the art that any block diagram herein represents a conceptual view of an illustrative system embodying the principles of the present subject matter. Similarly, it should be understood that any flow chart, flow diagram, state transition diagram, pseudo code, etc. represent various processes that can be represented in a computer-readable medium and executed by a computer or processor, whether or not such a computer or processor is explicitly shown.

[0063] In this document, the word “exemplary” is used herein to mean “serving as an example, instance, or illustration.” Any embodiment or implementation of the present subject matter described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments.

[0064] While the present disclosure is susceptible to various modifications and alternative forms, specific embodiments thereof have been shown by way of example in the drawings and will be described in detail below. However, it should be understood that there is no intention to limit the present disclosure to the particular forms disclosed, but on the contrary, the present disclosure is to cover all modifications, equivalents, and alternatives falling within the scope of the present disclosure.

[0065] The terms "comprise," "comprising," or any other variations thereof are intended to cover a non-exclusive inclusion, such that an arrangement, apparatus, or method that comprises a list of components or steps includes not only those components or steps, but may also include other components or steps not expressly listed or inherent to such arrangement, apparatus, or method. In other words, the presence of one or more elements in a system or apparatus preceded by "comprising" does not, without more constraints, preclude the presence of other or additional elements in the system or apparatus.

[0066] In recent years, several broadband wireless technologies have been developed to meet the growing demand for broadband subscribers and provide better applications and services. Second-generation (2G) wireless communication systems were developed to provide voice services while ensuring user mobility. Third-generation (3G) wireless communication systems support not only voice services but also data services. In recent years, fourth-generation (4G) wireless communication systems have been developed to provide high-speed data services. However, currently, 4G wireless communication systems lack the resources to meet the growing demand for high-speed data services. This problem is being addressed by the deployment of fifth-generation (5G) wireless communication systems to meet the growing demand for high-speed data services. In addition, 5G wireless communication systems provide ultra-reliability and support low-latency applications.

[0067] In 6G, quantum computers or machines will become widely used, potentially posing a threat to current wireless security systems. Quantum computers are computers that exploit the effects of quantum mechanics. These effects include superposition, which allows quantum bits (qubits) to exist in a combination of several states at once, and entanglement, which allows separate quantum systems to be linked, making them impossible to describe independently. Quantum algorithms exist that exploit these effects to solve certain cryptographic problems more efficiently than on classical computers. Shor's quantum algorithm for integer factorization runs in polynomial time on quantum computers. Variants of Shor's algorithm enable quantum computers to compute discrete logarithms over finite fields and elliptic curves in polynomial time. This variant renders several other public key cryptosystems, including Diffie-Hellman (DH) and elliptic curve Diffie-Hellman (ECDH), insecure. To address the threat posed by quantum computing to asymmetric cryptography, it is necessary to migrate to quantum-resistant algorithms, also known as post-quantum cryptography (PQC). Therefore, wireless communication networks, including those beyond the fifth generation (5G) and the sixth generation (6G), need to adapt these PQC algorithms to enhance security.

[0068] PQC algorithms involve a variety of algorithms used for different purposes, such as key establishment, digital signatures, etc. Some of these algorithms are CRYSTALS-KYBER, BIKE, Classic McEliece, HQC, and SIKE for key establishment, and CRYSTALS-Dilithium, FALCON, and SPHINCS+ for post-quantum secure digital signatures.

[0069] In current systems (e.g., 5G systems), the globally unique 5G Subscription Permanent Identifier (SUPI) is defined in 3GPP specification TS 23.501. The Subscription Concealed Identifier (SUCI) is a privacy-preserving identifier that contains the concealed SUPI. According to 3GPP specification TS 33.501, the SUPI is protected over the air using the SUCI. The UE should generate the SUCI using a protection scheme with an original public key (i.e., a home network public key securely provided under the control of the home network).

[0070] 5G uses traditional asymmetric cryptographic algorithms, which are becoming less secure due to the development of quantum computing (QC) machines. Therefore, 6G will require the adoption of new post-quantum cryptographic algorithms. In the case of 6G, devices may support both traditional asymmetric cryptographic algorithms and / or PQC algorithms. Different devices may have different requirements, and their support for cryptographic algorithms may vary accordingly.

[0071] Currently, profiles (or protection schemes) exist only for non-PQC algorithms, such as the Null scheme, Elliptic Curve Integrated Encryption Scheme (ECIES) Profile A, and ECIES Profile B. Primary authentication based on the Null scheme is performed only when security is not required. ECIES Profile A and ECIES Profile B are based on elliptic curve cryptography (ECC) and are vulnerable to quantum attacks. These profiles are configured in the SIM (Subscriber Identity Module) during provisioning, and there is no dynamic way to select a profile. As described in the table below, according to the 3GPP TS 31.102 specification, for primary authentication (or) SUCI encryption, only the highest-priority profile in the USIM Elementary File "EF SUCI_Calc_Info" is required by default. 3GPP has already specified profiles for protection schemes for hiding subscription permanent identifiers in TS 33.501, as described below.

[0072]

[0073] ECIES Profile A:

[0074] The Subscriber Identity De-Concealing Function (SIDF) and the Maintenance Entity (ME) will implement this profile. SIDF is a functional element of UDM (Unified Data Management) responsible for decrypting the SUCI (Subscription Concealed Identifier) ​​to reveal the subscriber's SUPI (Subscription Permanent Identifier). The ECIES parameters for this profile shall be as follows:

[0075] -EC domain parameters: Curve25519

[0076] -EC Diffie-Hellman primitive: X25519

[0077] -Point Compression: N / A

[0078] -KDF: ANSI-X9.63-KDF

[0079] -Hash: SHA-256

[0080] -SharedInfo1: (temporary public key octet string)

[0081] -MAC: HMAC-SHA-256

[0082] -mackeylen: 32 octets (256 bits)

[0083] -maclen: 8 octets (64 bits)

[0084] -SharedInfo2: Empty string

[0085] -ENC: AES-128, CTR mode

[0086] -enckeylen: 16 octets (128 bits)

[0087] -icblen: 16 octets (128 bits)

[0088] -Backward compatibility mode: false

[0089] ECIES Profile B:

[0090] ME and SIDF shall implement this profile. The ECIES parameters of this profile shall be as follows:

[0091] -EC domain parameters: secp256r1

[0092] -EC Diffie-Hellman primitive: Elliptic Curve Cofactor Diffie-Hellman primitive

[0093] -Point compression: true

[0094] -KDF: ANSI-X9.63-KDF

[0095] -Hash: SHA-256

[0096] -SharedInfo1: (temporary public key octet string)

[0097] -MAC: HMAC-SHA-256

[0098] -mackeylen: 32 octets (256 bits)

[0099] -maclen: 8 octets (64 bits)

[0100] -SharedInfo2: Empty string

[0101] -ENC: AES-128, CTR mode

[0102] -enckeylen: 16 octets (128 bits)

[0103] -icblen: 16 octets (128 bits)

[0104] -backwards-compatibility-mode: false

[0105] In 6G, both legacy and new cryptographic algorithms, potentially based on quantum algorithms (such as quantum key distribution (PQC)), will be applicable. Therefore, in this context, new profiles will need to be defined for the protection scheme used to conceal the subscription permanent identifier. In 5G systems, there is no protection scheme identifier to support the PQC algorithm used for concealing the SUPI and de-hiding the SUCI. The new PQC algorithm profile proposed by the National Institute of Standards and Technology (NIST) has new parameters that need to be defined by 3GPP. Only ECIES profiles A and B (as reiterated above) are defined in 33.501, which are not quantum-safe. If the UE and home network (HN) support different protection schemes—for example, if the UE supports legacy but the network supports the PQC profile—the device may initiate registration using a hidden SUCI created using the legacy algorithm. In response, the network may deny authentication, and the UE will be unable to successfully register due to the authentication failure, further delaying the registration process. Similarly, if the UE and network support legacy protection schemes, the device can initiate registration using a hidden SUCI created from a legacy algorithm. An attacker can then use a quantum machine to break a legacy algorithm like ECIES (using elliptic curve cryptography) and decode the SUCI to extract the IMSI (International Mobile Subscriber Identity). If the attacker uses this IMSI to extract user information such as location, the IMSI is highly vulnerable.

[0106] Figure 1A The format and scheme output of SUCI as defined in the prior art are shown. Figure 1AAs shown, the SUCI is a privacy-preserving identifier that contains the hidden SUPI defined in TS 33.501. The SUCI consists of the SUPI type, home network identifier, routing indicator (RI), protection scheme identifier (PSI), home network public key identifier, and scheme output (SO). The "SUPI type" identifies the identifier type. The SUPI type has values ​​between 0 and 7; for example, in the case of an IMSI-type SUPI, the value "0" is used, while in the case of a network-specific identifier, the value "1" is used. The HNPKI is used to identify the subscriber's home network (HN); for example, in the case of an IMSI-type SUPI, the HNPKI consists of the mobile country code (MCC) and mobile network code (MNC). The RI consists of 1 to 4 decimal digits assigned using the HN operator. The PSI has values ​​between 0 and 15 and is used to specify which encryption profile should be used to hide the SUPI. The HNPKI has values ​​between 0 and 255 and represents the public key provided by the home public land mobile network (HPLMN) or standalone non-public network (SNPN). It is used to identify the key used for SUPI protection. In addition, SO can include a string of variable length or hexadecimal numbers, and it depends on the protection scheme used. For example, in the case of encryption profile A, SO consists of the UE temporary public key, ciphertext and mac tag value.

[0107] In 5G, SUPI hiding and SUCI dehiding are performed at the UE and HN, respectively, using the Elliptic Curve Integrated Encryption Scheme (ECIES). ECIES allows the UE to encrypt the subscription identifier using elliptic curve cryptography, symmetric key cryptography, and hash operations. ECIES performs encryption based on a protection scheme profile. Furthermore, during SIM provisioning, the HN shares the protection scheme profile with the UE. These profiles are defined in TS 33.501. The profiles also include various configuration parameters for the ECIES scheme. Overall, ECIES allows two parties to establish and exchange secure information over an insecure channel. The ECIES scheme consists of five distinct steps: key generation, key agreement, key derivation, symmetric key encryption, and a hash-based message authentication code (HMAC) function.

[0108] Figure 1BA flowchart illustrates the process of hiding the Subscription Permanent Identifier (SUPI) at a UE using an Elliptic Curve Integrated Encryption Scheme (ECIES) based on the prior art. In step 1, the UE generates a public / private key pair using elliptic curve cryptography according to the protection scheme profile. Furthermore, in step 2, the UE uses its own temporary private key and provides the HN public key to derive a shared secret using an Elliptic Curve Diffie-Hellman (ECDH) key agreement operation. ECDH key agreement allows two parties to derive the same shared secret using each other's public shared key and their own private secret. Furthermore, in step 3, after generating the shared secret, the UE uses a key derivation function to derive multiple keys from the shared secret. The ANSI-X9.63 key derivation function (KDF) is used to derive multiple keys from the shared secret. In the SUPI hiding scenario, the UE uses the KDF to generate the Initial Control Block (ICB), MAC key, and Advanced Encryption Standard (AES) encryption key. Finally, in step 4, the UE uses the symmetric key encryption algorithm AES to hide the SUPI and generate the hidden SUPI value. In step 5, the UE uses a hash-based message authentication code (HMAC) function to ensure integrity protection for the generated hidden SUPI. HMAC uses the derived MAC key to generate a MAC tag for the hidden SUPI. The aforementioned steps can be used for SUPI hiding. In these five operations, key generation and key agreement are based on elliptic curve-based public key cryptography. After the SUPI is hidden, the UE sends the SUCI to the HN 103.

[0109] Figure 1C FIG. 1 shows a flow chart of the SUCI de-hiding process at the HN 103 based on ECIE according to the prior art. Figure 1C As shown, during SUCI dehiding, HN 103 uses its private key and the UE's temporary public key to derive a shared key. Subsequently, similar to SUPI hiding, HN 103 uses a key derivation function to derive multiple keys from the shared key. In the case of SUCI dehiding, HN 103 uses a KDF to generate an ICB (Initial Control Block), a MAC key, and an AES decryption key. Furthermore, in the next step, HN 103 performs SUCI dehiding using symmetric key decryption and verifies integrity protection using an HMAC function. Similarly, SUPI hiding and SUCI dehiding also rely on elliptic curve-based cryptography.

[0110] Figure 1D The complete sequence flow chart of the SUCI hiding and dehiding process according to the prior art is briefly shown. Figure 1DAs shown, initially, in step 1 (S1), HN 103 supplies its public key to UE 101. Further, when UE 101 wishes to initiate SUPI hiding, it performs public / private key generation (step 2 (S2), shared secret generation (step 3 (S3), and multiple other key generation steps (step S4). It then encrypts the SUPI and generates a MAC tag using AES encryption and an HMAC function (step S5). These steps are part of SUPI hiding. After completing SUPI hiding, UE 101 creates a scheme output, which includes the UE public key, ciphertext, and MAC tag. Here, the ciphertext includes the hidden SUPI, and the MAC tag includes the MAC of the hidden SUPI. As shown in step 6, the scheme output is transmitted from UE 101 to HN 103 as part of a SUCI packet (S6). Upon receiving the SUCI, HN 103 initiates the SUCI de-hiding process. Furthermore, HN 103 generates a shared secret using key agreement and multi-key generation using a KDF, as shown in step 7 (S7). Subsequently, HN 103 verifies the integrity of the hidden SUPI using an HMAC function and decrypts the SUPI using an AES decryption function. Both SUPI hiding and SUCI dehiding rely on elliptic curve-based cryptography.

[0111] The current SUPI hiding and SUCI hiding processes are both based on an ECIES-based encryption scheme, which is not quantum-resistant. Overall, ECIES consists of the five steps described above. Of these five steps, two (key generation and key agreement) are based on elliptic curve primitives. Because elliptic curve cryptography relies on logarithm-hard problems, which are easily solvable using quantum machines, the reliance on elliptic curves for key agreement renders the entire SUPI hiding and dehiding process insecure. Similarly, SUPI dehiding (which also uses ECIES) uses elliptic curves for key agreement and is also not quantum-resistant.

[0112] To protect against quantum threats, 6G requires replacing classical (quantum-unsafe) algorithms with quantum-safe algorithms. The master authentication process needs to be defined based on new algorithms, such as quantum-safe PQC and quantum key distribution (QKD). These PQC algorithms have been designed and evaluated to achieve security assurance against quantum threats. However, the scope of testing, evaluation, and maturity of these algorithms is not as well established as that of classical algorithms. Therefore, simply adopting PQC algorithms for master authentication is insufficient to achieve highly reliable security assurance. Hybrid solutions are needed for master authentication in 6G, particularly for SUPI hiding and dehiding.

[0113] In 6G, a master authentication process needs to be defined based on a hybrid solution that uses a combination of new algorithms such as quantum-safe PQC and QKD with well-tested traditional algorithms established in current systems. A new mechanism for hybrid shared key generation needs to be defined that can use both traditional and PQC methods for shared key generation. Hybrid encryption also needs to be defined that can use a combination of traditional and PQC-based encryption for any identifier, such as the SUPI or any other equivalent identifier between the UE 101 and the network, to achieve high security guarantees.

[0114] The information disclosed in this background section of this disclosure is only for enhancement of understanding of the general background of the invention and should not be taken as an acknowledgment or any form of suggestion that this information constitutes the prior art already known to those skilled in the art.

[0115] In an embodiment, the present invention discloses a method for registering a user equipment (UE) with a home network (HN) using hybrid key exchange. The method includes generating a temporary public key and a temporary private key based on elliptic curve (EC) key generation technology, and generating a first temporary shared key based on the temporary private key and an elliptic curve (EC)-based home network public key. Furthermore, the method includes generating a second temporary shared key and an encrypted shared key based on a post-quantum cryptography (PQC)-based public key associated with the HN. Furthermore, the method includes generating a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key. Thereafter, the method includes generating a ciphertext value and a message authentication code (MAC) tag value based on at least the temporary hybrid shared key. Finally, the method includes sending a registration request to register the UE with the HN, along with the temporary public key, the encrypted shared key, the ciphertext value, and the MAC tag value.

[0116] In an embodiment, the present invention discloses a method for registering a user equipment (UE) with a home network (HN) using hybrid key exchange. The method includes receiving a registration request from the UE, wherein the registration request includes a temporary public key, an encrypted shared secret, a ciphertext value, and a message authentication code (MAC) tag value; generating a first temporary shared secret based on at least the temporary public key and an elliptic curve cryptography (ECC)-based public key associated with the HN; generating a second temporary shared secret based on the encrypted shared secret and a post-quantum cryptography (PQC)-based private key associated with the HN; generating a temporary hybrid shared secret based on the first temporary shared secret and the second temporary shared secret; and generating a temporary decryption key and a temporary MAC key based on at least the temporary hybrid shared secret. Finally, the method includes generating plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key, and registering the UE with the HN based on the generated plaintext.

[0117] In an embodiment, the present invention discloses a method for registering a user equipment (UE) with a home network (HN) using hybrid key exchange. The method includes generating a first temporary shared key and a first encrypted shared key based on a home network public key based on a first post-quantum cryptography (PQC), and generating a second temporary shared key and a second encrypted shared key based on a home network public key based on a second PQC. Furthermore, the method includes generating a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key. Furthermore, the method includes generating a ciphertext value and a message authentication code (MAC) tag value based on at least the temporary hybrid shared key. Finally, the method includes sending a registration request for registering the UE with the HN, along with the first encrypted shared key, the second encrypted shared key, the ciphertext value, and the MAC tag value.

[0118] In an embodiment, the present invention discloses a method for registering a user equipment (UE) with a home network (HN) using hybrid key exchange. The method includes receiving a registration request from the UE, wherein the registration request includes a first encryption shared key, a second encryption shared key, a ciphertext value, and a message authentication code (MAC) tag value; generating a first temporary shared key based on the first encryption shared key and a first post-quantum cryptography (PQC)-based private key associated with the HN; generating a second temporary shared key based on the second encryption shared key and a second PQC-based private key associated with the HN; and generating a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key. Thereafter, the method includes generating plaintext by performing symmetric decryption of the ciphertext value based on at least a temporary decryption key. Finally, the method includes generating plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key, and registering the UE with the HN based on the generated plaintext.

[0119] In an embodiment, the present invention discloses a method for registering a user equipment (UE) with a home network (HN) using hybrid key encryption. The method includes generating a temporary public key and a temporary private key based at least on elliptic curve (EC) key generation technology, and generating a temporary shared key based on the temporary private key and an EC-based home network public key. Furthermore, the method includes generating a temporary encryption key and a temporary message authentication code (MAC) key based at least on the temporary hybrid shared key. Furthermore, the method includes generating an intermediate ciphertext value by performing symmetric encryption of plaintext based on the temporary encryption key. Thereafter, the method includes generating a ciphertext value based on the intermediate ciphertext value and a home network public key based on post-quantum cryptography (PQC). Finally, the method includes generating a MAC tag value based at least on the ciphertext value and a temporary MAC tag key, and sending a registration request to register the UE with the HN, along with the temporary public key, the ciphertext value, and the MAC tag value.

[0120] In an embodiment, the present invention discloses a method for registering a user equipment (UE) with a home network (HN) using hybrid key encryption. The method includes receiving a registration request from the UE, wherein the registration request includes a temporary public key, a ciphertext value, and a message authentication code (MAC) tag value; generating a temporary shared key based on the temporary public key and an elliptic curve (EC)-based private key associated with the HN; generating a temporary decryption key and a temporary MAC key based on the temporary shared key; generating an intermediate ciphertext value by applying post-quantum cryptography (PQC) decryption to the ciphertext value based on a PQC-based HN public key; and generating plaintext by performing symmetric decryption of the intermediate ciphertext value based on at least the temporary decryption key. Finally, the method includes generating plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key; and registering the UE with the HN based on the generated plaintext.

[0121] In an embodiment, the present invention discloses a method for registering a user equipment (UE) with a home network (HN) using hybrid-key encryption. The method includes splitting plaintext into a first portion and a second portion. Furthermore, the method includes generating a first ciphertext value based on a first post-quantum cryptography (PQC)-based public key associated with the HN. Thereafter, the method includes generating a second ciphertext value based on a second PQC-based public key associated with the HN. Finally, the method includes sending a registration request to register the UE with the HN, along with the first ciphertext value and the second ciphertext value.

[0122] In an embodiment, the present invention discloses a method for registering a user equipment (UE) with a home network (HN) using hybrid key encryption. The method includes receiving a registration request from the UE, wherein the registration request includes a first ciphertext value and a second ciphertext value, and generating a first portion of plaintext by decrypting the first ciphertext value based on a first post-quantum cryptography (PQC) private key associated with the HN. Furthermore, the method includes generating a second portion of plaintext by decrypting the second ciphertext value based on a second PQC private key associated with the HN. Thereafter, the method includes generating plaintext by combining the first portion of plaintext and the second portion of plaintext. Finally, the method includes registering the UE with the HN based on the generated plaintext.

[0123] In an embodiment, the present invention discloses a method for registering a user equipment (UE) with a home network (HN) using hybrid key encryption. The method includes generating an intermediate ciphertext value based on a home network public key based on a first post-quantum cryptography (PQC) and plaintext. Furthermore, the method includes generating a ciphertext value based on the intermediate ciphertext value and a home network public key based on a second PQC. Finally, the method includes sending a registration request along with the ciphertext value to the UE to register the UE with the HN.

[0124] In an embodiment, the present invention discloses a method for registering a user equipment (UE) with a home network (HN) using hybrid key encryption. The method includes receiving a registration request, wherein the registration request includes a ciphertext value. Furthermore, the method includes generating an intermediate ciphertext value based on the ciphertext value and a home network private key based on a second PQC. Thereafter, the method includes generating plaintext based on the intermediate ciphertext value and the home network private key based on a first PQC. Finally, the method includes registering the UE with the home network based on the generated plaintext.

[0125] In an embodiment, the present invention discloses a user equipment (UE) for registering with a home network. The UE includes a processor and a memory. The processor is communicatively coupled to the memory and configured to generate a temporary public key and a temporary private key based on an elliptic curve (EC) key generation technique, and to generate a first temporary shared key based on the temporary private key and an elliptic curve (EC)-based home network public key. Furthermore, the processor is configured to generate a second temporary shared key and an encrypted shared key based on a post-quantum cryptography (PQC)-based public key associated with the home network. Furthermore, the processor is configured to generate a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key. Thereafter, the processor is configured to generate a ciphertext value and a message authentication code (MAC) tag value based on at least the temporary hybrid shared key. Finally, the processor is configured to send a registration request for registering the UE with the home network, along with the temporary public key, the encrypted shared key, the ciphertext value, and the MAC tag value.

[0126] In an embodiment, the present invention discloses a user equipment (UE) for registering with a home network. The UE includes a processor and a memory. The processor is communicatively coupled to the memory and configured to receive a registration request from the UE, wherein the registration request includes a temporary public key, an encrypted shared key, a ciphertext value, and a message authentication code (MAC) tag value. The processor is configured to generate a first temporary shared key based on at least the temporary public key and an elliptic curve cryptography (ECC)-based public key associated with the home network. Furthermore, the processor is configured to generate a second temporary shared key based on the encrypted shared key and a post-quantum cryptography (PQC)-based private key associated with the home network. Furthermore, the processor is configured to generate a temporary hybrid shared key based on the first and second temporary shared keys. Thereafter, the processor is configured to generate a temporary decryption key and a temporary MAC key based on at least the temporary hybrid shared key. Finally, the processor is configured to generate plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key, and register the UE with the home network based on the generated plaintext.

[0127] In an embodiment, the present invention discloses a user equipment (UE) for registering with a home network. The UE includes a processor and a memory. The processor is communicatively coupled to the memory and is configured to generate a first temporary shared key and a first encrypted shared key based on a home network public key based on a first post-quantum cryptography (PQC), and to generate a second temporary shared key and a second encrypted shared key based on a home network public key based on a second PQC. Furthermore, the processor is configured to generate a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key. Thereafter, the processor is configured to generate a ciphertext value and a message authentication code (MAC) tag value based on at least the temporary hybrid shared key. Finally, the processor is configured to send a registration request for registering the UE with the home network, along with the first encrypted shared key, the second encrypted shared key, the ciphertext value, and the MAC tag value.

[0128] In an embodiment, the present invention discloses a user equipment (UE) for registering with a home network. The UE includes a processor and a memory. The processor is communicatively coupled to the memory and configured to receive a registration request from the UE, wherein the registration request includes a first encryption shared key, a second encryption shared key, a ciphertext value, and a message authentication code (MAC) tag value. The processor is configured to generate a first temporary shared key based on the first encryption shared key and a first post-quantum cryptography (PQC)-based private key associated with the home network. Furthermore, the processor is configured to generate a second temporary shared key based on the second encryption shared key and a second PQC-based private key associated with the home network. Furthermore, the processor is configured to generate a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key. Thereafter, the processor is configured to generate a temporary decryption key and a temporary MAC key based on at least the temporary hybrid shared key. Finally, the processor is configured to generate plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key, and register the UE with the home network based on the generated plaintext.

[0129] In one embodiment, the present invention discloses a user equipment (UE) for registering with a home network. The UE includes a processor and a memory. The processor is communicatively coupled to the memory and is configured to generate at least a temporary public key and a temporary private key based on an elliptic curve (EC) key generation technique, and to generate a temporary shared key based on the temporary private key and an EC-based home network public key. Furthermore, the processor is configured to generate at least a temporary encryption key and a temporary message authentication code (MAC) key based on the temporary hybrid shared key. Furthermore, the processor is configured to generate an intermediate ciphertext value by performing symmetric encryption of plaintext based on the temporary encryption key. Thereafter, the processor is configured to generate a ciphertext value based on the intermediate ciphertext value and a home network public key based on post-quantum cryptography (PQC). Finally, the processor is configured to generate a MAC tag value based on at least the ciphertext value and the temporary MAC tag key, and to send a registration request for registering the UE with the home network, along with the temporary public key, the ciphertext value, and the MAC tag value.

[0130] In an embodiment, the present invention discloses a user equipment (UE) for registering with a home network. The UE includes a processor and a memory. The processor is communicatively coupled to the memory and is configured to receive a registration request from the UE, wherein the registration request includes a temporary public key, a ciphertext value, and a message authentication code (MAC) tag value, and to generate a temporary shared key based on the temporary public key and an elliptic curve (EC)-based private key associated with the home network. Furthermore, the processor is configured to generate a temporary decryption key and a temporary MAC key based on the temporary shared key. Furthermore, the processor is configured to generate an intermediate ciphertext value by applying post-quantum cryptography (PQC) decryption to the ciphertext value based on a PQC-based home network public key. Thereafter, the processor is configured to generate plaintext by performing symmetric decryption of the intermediate ciphertext value based on at least the temporary decryption key. Finally, the processor is configured to register the UE with the home network based on the generated plaintext.

[0131] In one embodiment, the present invention discloses a user equipment (UE) for registering with a home network. The UE includes a processor and a memory. The processor is communicatively coupled to the memory and configured to generate a first ciphertext value based on a first post-quantum cryptography (PQC)-based public key associated with the home network. Thereafter, the processor is configured to generate a second ciphertext value based on a second PQC-based public key associated with the home network. Finally, the processor is configured to send a registration request to register the UE with the home network, along with the first ciphertext value and the second ciphertext value.

[0132] In an embodiment, the present invention discloses a user equipment (UE) for registering with a home network. The UE includes a processor and a memory. The processor is communicatively coupled to the memory and configured to receive a registration request from the UE, wherein the registration request includes a first ciphertext value and a second ciphertext value. Furthermore, the processor is configured to generate a first portion of plaintext by decrypting the first ciphertext value based on a first post-quantum cryptography (PQC) private key associated with the home network. Furthermore, the processor is configured to generate a second portion of plaintext by decrypting the second ciphertext value based on a second PQC private key associated with the home network. Thereafter, the processor is configured to generate plaintext by combining the first portion and the second portion of plaintext. Finally, the processor is configured to register the UE with the home network based on the generated plaintext.

[0133] In one embodiment, the present invention discloses a user equipment (UE) for registering with a home network. The UE includes a processor and a memory. The processor is communicatively coupled to the memory and configured to generate an intermediate ciphertext value based on a home network public key and plaintext using a first post-quantum cryptography (PQC) technique. Thereafter, the processor is configured to generate a ciphertext value based on the intermediate ciphertext value and the home network public key using a second PQC technique. Finally, the processor is configured to send a registration request along with the ciphertext value to the UE to register the UE with the home network.

[0134] In one embodiment, the present invention discloses a user equipment (UE) for registering with a home network. The UE includes a processor and a memory. The processor is communicatively coupled to the memory and configured to receive a registration request, wherein the registration request includes a ciphertext value. Furthermore, the processor is configured to generate an intermediate ciphertext value based on the ciphertext value and a home network private key based on a second PQC. Thereafter, the processor is configured to generate plaintext based on the intermediate ciphertext value and the home network private key based on a first PQC. Finally, the processor is configured to register the UE with the home network based on the generated plaintext.

[0135] The foregoing summary is illustrative only and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features will become apparent by reference to the drawings and the following detailed description.

[0136] In an embodiment, the first step in adapting post-quantum algorithms to 3GPP is to create a profile for each algorithm that contains the parameter configuration required for that specific algorithm. Since 3GPP relies on NIST to obtain new algorithms, the creation of such PQC profiles with various parameters can be based on the PQC algorithm standardized by NIST. The created PQC profile can be used for a variety of purposes to maintain UE security, such as master authentication of subscriber data, protection from fake base stations, etc. The PQC-based profile can be designed to have various possibilities or structures, for example, including security level, key length, etc. In an embodiment, it can also include a hybrid profile that combines a PQC profile with a traditional profile to provide enhanced security. Such a method of creating a PQC profile for easy access and enhanced security has been explained in detail below.

[0137] In one aspect of the present invention, a new protection scheme identifier can be added to support the PQC algorithm, which is reserved for future use. Key changes to the profile can include: first, removing the required elliptic curve-related parameters, as PQC's key-based encryption algorithm can be used for SUPI hiding. Second, the SharedInfo1 parameter can be the encrypted shared key octet string output by the PQC algorithm's key encapsulation function. Third, because AES-128 (CTR) is susceptible to quantum attacks, AES-256 or its variants can be used for symmetric encryption.

[0138] If the UE and the network support the PQC protection scheme, the UE can initiate registration with the network using the hidden SUCI created from the PQC algorithm, as the PQC profile is present in the device or SIM or e-SIM according to the proposed solution. In response, the network will accept the authentication, and the UE will be able to perform a successful registration without any further delays during the registration process. Furthermore, if the UE and the network support the PQC protection scheme, the device can initiate registration using the hidden SUCI created from the PQC algorithm according to the proposed solution, and an attacker cannot use a quantum machine to break the PQC algorithm to decode the SUCI, as the PQC algorithm is quantum-safe. Therefore, the attacker cannot extract the IMSI, and user information such as location is protected.

[0139] Furthermore, there are multiple ways or options for creating these PQC-based profiles, and several embodiments thereof are described herein. In one embodiment, a common profile is created for each PQC algorithm. Here, each algorithm may have a protection scheme identifier and security level, which can be separated from the profile parameters and maintained separately. Depending on the selected algorithm and based on the security level, various parameters for SUPI hiding / SUCI dehiding may be determined. This security level may be part of the Universal Subscriber Identity Module (USIM), any access network message indication, or core network message indication. Each PQC algorithm may have a common profile created independently of the security level. All NIST-standardized PQC algorithms for key encapsulation and digital signatures may be part of the protection scheme. Therefore, while the initial intention is to use the key encapsulation mechanism for primary authentication, both the key encapsulation and digital signature algorithms defined herein can be later used for different purposes.

[0140] The following modifications may be required to incorporate the 3GPP TS 33.501 standard specification in Annex C: Protection scheme for hiding subscription permanent identifiers:

[0141] 0x0: Zero scheme, the size of the input, i.e., the size of the username used in case of Network Access Identifier (NAI) format or the size of the Mobile Subscriber Identification Number (MSIN) used in case of IMSI

[0142] 0x1: ECIES Profile , a total of 256-bit public key, 64-bit MAC, plus the size of the input.

[0143] 0x2: ECIES Profile , a total of 264-bit public key, 64-bit MAC, plus the size of the input.

[0144] 0x3: KYBER, total 768 / 1088 / 1568 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0145] 0x4: BIKE, total 1572 / 3114 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0146] 0x5: Classic McEliece, total 128 / 188 / 240 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0147] 0x6: HQC, a total of 4481 / 9026 / 14469 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0148] 0x7: SIKE, a total of 346 / 486 / 596 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0149] 0x8: Dilithium, an algorithm based on NIST-standardized digital signatures

[0150] 0x9: FALCOM, an algorithm based on NIST-standardized digital signatures

[0151] 0xA: SPHINCS+, an algorithm based on NIST-standardized digital signatures.

[0152] The value 0xB is reserved for future standardized protection schemes. The values ​​0xC to 0xF are reserved for proprietary protection schemes specified by the home operator.

[0153] The following modifications may be required to incorporate the 3GPP TS 33.501 standard specification in Annex C: A new section for the PQC profile needs to be created like the ECIE.

[0154] CXX PQC Profile

[0155] Unless otherwise noted, the PQC profiles follow the terminology and processing specified in the selected NIST PQC algorithm document.

[0156] To generate successive counter blocks from the initial counter block (ICB) in CTR mode, the profile should use the standard increment function in Section B.1 of NIST Special Publication 800-38A, where m = 32 bits. The ICB corresponds to T1 in Section 6.5. AES-128 or AES-256 (with or without CTR) in CTR mode is preferred. If 256-bit security is required, AES-256 is required.

[0157] - The value of the MAC tag in the PQC profile shall be the L most significant octets of the output generated by the HMAC function, where L is equal to maclen.

[0158] - The PQC profile uses its own standardized processes for key generation (PQC KEM algorithm key generation process) and shared secret calculation (PQC KEM algorithm shared secret generation).

[0159] - The shared secret output octet string from the PQC KEM algorithm should be used as input in the KDF.

[0160] The public profile for the Kyber algorithm may be provided as mentioned in Table 1.A and may include various parameters fixed according to security levels 1, 3, and 5 as shown in Table 1.B.

[0161]

[0162] Table 1.A

[0163]

[0164] Table 1.B

[0165] The public profile for BIKE (Bit-flipping Key Encapsulation) algorithm may be provided as mentioned in Table 2.A and may include various parameters fixed according to security levels 1, 3, 5 as in Table 2.B.

[0166]

[0167] Table 2.A

[0168]

[0169] Table 2.B

[0170] The public profile for the Hamming Quasi-Cyclic (HQC) algorithm may be provided as mentioned in Table 3.A and may include various parameters fixed according to security levels 1, 3, 5 as in Table 3.B.

[0171]

[0172] Table 3.A

[0173]

[0174] Table 3.B

[0175] The public profile for the classic McEliece algorithm may be provided as mentioned in Table 4.A and may include various parameters fixed according to security levels 1, 3, and 5 as shown in Table 4.B.

[0176]

[0177] Table 4.A

[0178]

[0179] Table 4.B

[0180] In another embodiment, a separate profile can be created for each level of the PQC algorithm. Here, each algorithm creates a profile or protection scheme identifier along with the security level. Depending on the selected algorithm, various parameters for SUPI hiding / SUCI dehiding can be fixed, as the security level is already part of the protection scheme creation. Therefore, each PQC algorithm can include a separate profile created for each security level. In an embodiment, all NIST-standardized PQC algorithms for key encapsulation and digital signatures can be part of the protection scheme. Therefore, while the initial intention is to use the key encapsulation mechanism for primary authentication, both the key encapsulation and digital signature algorithms defined here can be later used for different purposes. In an embodiment, some of the NIST Round 4 candidate algorithms can also be standardized.

[0181] In an embodiment, the following modifications may be required to be incorporated into the 3GPP standard specification: Protection scheme for hiding subscription permanent identifier:

[0182] 0x0: Zero scheme, the size of the input, i.e., the size of the username used in case of NAI format or the size of the MSIN used in case of IMSI

[0183] 0x1: ECIES Profile , a total of 256-bit public key, 64-bit MAC, plus the size of the input.

[0184] 0x2: ECIES Profile , a total of 264-bit public key, 64-bit MAC, plus the size of the input.

[0185] 0x3: KYBER512, total 768 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0186] 0x4: KYBER768, a total of 1088 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0187] 0x5: KYBER1024, a total of 1568 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0188] 0xX: McEliece348864, total 128 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0189] 0xX: McEliece460896, total 188 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0190] 0xX: McEliece6688128, total 240 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0191] 0xX: BIKE1, total 1572 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0192] 0xX: BIKE3, total 3114 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0193] 0xX: HQC-128, a total of 4481 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0194] 0xX: HQC-192, a total of 9026 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0195] 0xX: HQC-256, a total of 14469 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0196] 0xX: SIKEp434, a total of 346 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0197] 0xX: SIKEp610, a total of 486 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0198] 0xX: SIKEp751, a total of 596 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0199] 0xX: Dilithium, an algorithm based on NIST-standardized digital signatures

[0200] 0xX: FALCOM, an algorithm based on NIST-standardized digital signatures

[0201] 0xX: SPHINCS+, an algorithm based on NIST-standardized digital signatures.

[0202] Values ​​0xC to 0xF are reserved for proprietary protection schemes specified by the home operator.

[0203] Furthermore, profiles for the Kyber algorithm may be provided as mentioned in Table 5 for Kyber 512 with security level 1, Table 6 for Kyber 768 with security level 3, and Table 7 for Kyber 1024 with security level 5.

[0204]

[0205] Table 5

[0206]

[0207] Table 6

[0208]

[0209] Table 7

[0210] Furthermore, profiles for the Kyber algorithm may be provided as mentioned in Table 8 for BIKE with security level 1, Table 9 for BIKE with security level 3, and Table 10 for BIKE with security level 5.

[0211]

[0212] Table 8

[0213]

[0214] Table 9

[0215]

[0216] Table 10

[0217] Furthermore, profiles for the HQC algorithm may be supplied as mentioned in Table 11 for HQC-128 with security level 1, Table 12 for HQC-192 with security level 3, and Table 13 for HQC-256 with security level 5.

[0218]

[0219] Table 11

[0220]

[0221] Table 12

[0222]

[0223] Table 13

[0224] In addition, profiles for the classic Mc-Eliece algorithm can be provided as mentioned in Table 14 for Mc-Eliece with security level 1, Table 15 for Mc-Eliece with security level 3, Table 16 for profile configuration 1 with security level 5, Table 17 for profile configuration 2 with security level 5, and Table 18 for profile configuration 3 with security level 5.

[0225]

[0226] Table 14

[0227]

[0228] Table 15

[0229]

[0230] Table 16

[0231]

[0232] Table 17

[0233]

[0234] Table 18

[0235] In another aspect of the present invention, new protection scheme identifiers based on the NIST-proposed PQC algorithm can also be hybrid, i.e., a combination of two different algorithms. Similar to the hybrid key exchange in TLS (Transport Layer Security), 3GPP can also adopt this approach to combine two algorithms for enhanced security protection and support a fallback mechanism if one of the two algorithms is compromised in the future. Furthermore, the shared secret key of one algorithm can be concatenated with the other to form a combined shared secret key for the hybrid algorithm. These new hybrid protection scheme identifiers can be added to support PQC algorithms, which are reserved for future use in Annex C of 33.501.

[0236] In an embodiment, there may be four such options in the creation of a PQC based scheme identifier or profile.

[0237] Option 1: Traditional + PQC KEM Profile

[0238] Option 2: PQC KEM + PQC KEM Profile

[0239] Option 3: PQC KEM + PQC Digital Signature Profile

[0240] Option 4: Traditional + PQC Digital Signature Profile.

[0241] In all of the above options, the security level based on the PQC scheme identifier can be part of the profile or separate from the profile, as described above.

[0242] In embodiments, a combination of traditional and PQC KEM-based profiles can be created. A hybrid profile, a combination of elliptic curve cryptography (ECC) and PQC algorithms, can also be created as a new profile to enhance security and serve as a fallback mechanism in the event that the PQC-based algorithm becomes compromised in the future for any reason. One algorithm can be of the traditional type, i.e., an elliptic curve-based protection scheme identifier, and the other algorithm can be a post-quantum KEM-based scheme identifier. The elliptic curve-based protection scheme can be in accordance with 3GPP 33.501, i.e., ECIES Profile A or ECIES Profile B. All NIST-standardized PQC algorithms for key encapsulation can be part of the PQC-based protection scheme. In embodiments, some of the NIST Round 4 candidate algorithms can also be standardized.

[0243] This approach is needed as an important step towards the evolution of PQC, which provides for the use of classical standardized cryptographic algorithms in combination with post-quantum algorithms, contributing to cryptographic flexibility, i.e., a smooth transition from classical to PQC. Since NIST-standardized PQC algorithms are tested for a minimum duration, if any PQC algorithm is compromised, the algorithm security strength can be regressed to the classical (ECIES) algorithm, although if the PQC algorithm is compromised, it may not be quantum-safe.

[0244] In addition, the following modifications need to be incorporated into the 3GPP standard specification: Protection scheme for hiding subscription permanent identifiers:

[0245] 0x0: Zero scheme, the size of the input, i.e., the size of the username used in case of NAI format or the size of the MSIN used in case of IMSI

[0246] 0x1: ECIES Profile , a total of 256-bit public key, 64-bit MAC, plus the size of the input.

[0247] 0x2: ECIES Profile , a total of 264-bit public key, 64-bit MAC plus the size of the input.

[0248] 0x3: KYBER, total 768 / 1088 / 1568 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0249] 0x4: ECIES Profile A+KYBER

[0250] 0x5: ECIES Profile B+KYBER

[0251] 0x6: ECIES Profile A+BIKE

[0252] 0x7: ECIES Profile B+BIKE

[0253] 0x8: ECIES Profile A+ Classic McEliece

[0254] 0x9: ECIES Profile B+ Classic McEliece

[0255] 0xA: ECIES Profile A+HQC

[0256] 0xB: ECIES profile B+HQC.

[0257] Similar to 0x5 to 0xC, any combination of the conventional scheme ECIES Profile A / B and the below-mentioned PQC KEM-based scheme can be constructed.

[0258] BIKE, total 1572 / 3114 bytes encrypted shared secret, 64-bit MAC, plus the size of the input

[0259] Classic McEliece, total 128 / 188 / 240 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0260] HQC, a total of 4481 / 9026 / 14469 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0261] SIKE, a total of 346 / 486 / 596 bytes of encrypted shared secret, 64-bit MAC, plus the size of the input

[0262] Values ​​0xC to 0xF are reserved for proprietary protection schemes specified by the home operator.

[0263] The following modifications may be needed to incorporate the 3GPP TS 33.501 standard specification in Annex C: A new section for the hybrid profile (ECIES Profile A+PQC) needs to be created like ECIES.

[0264] CXX Hybrid Profile

[0265] Unless otherwise specified, hybrid profiles adhere to the terminology and processing specified in SECG Version 2 and the selected NIST PQC algorithm document. Profiles should use "named curves" over prime fields.

[0266] - To generate consecutive counter blocks from an initial counter block (ICB) in CTR mode, the profile shall use the standard increment function in Section B.1 of NIST Special Publication 800-38A, where m = 32 bits. ICB corresponds to T1 in Section 6.5.

[0267] AES-128 or AES-256 in CTR mode (with or without CTR) are preferred. If you need to maintain 256-bit security, you need AES-256.

[0268] - The value of the MAC tag in the hybrid profile shall be the L most significant octets of the output generated by the HMAC function, where L is equal to maclen.

[0269] The hybrid profile uses its own standardized processes for key generation (Section 6 of RFC 7748 and the PQC KEM algorithm key generation procedure) and shared secret calculation (Section 5 of RFC 7748 and the shared secret generated by the PQC KEM algorithm). The calculated shared secret is a combination of two shared secrets, one generated from ECIES and the other from the PQC KEM algorithm. The Diffie-Hellman primitive X25519 (Section 5 of RFC 7748) takes two random octet strings as input, decodes them into a scalar and a coordinate, performs a multiplication, and encodes the result as an octet string. The shared secret output octet string from X25519, combined with the shared secret generated by the PQC KEM, should be used as input Z in the KDF (Section 3.6.1).

[0270] - Since point compression is not applied, the prefix rules for compression types defined in Section 5.1.3 shall not be used, i.e., there shall be no prefix for ephemeral public keys.

[0271] - The profile should not use backward compatibility mode (and therefore not be compatible with version 1 of SECG).

[0272] A hybrid profile of ECIES Profile A combined with the Kyber-1024 algorithm and security level 5 can be provided as mentioned in Table 19 (below), and can also have various parameters modified according to the security level (1, 3, 5) it supports, as marked below. The Level 1 and Level 3 parameters mentioned in Table 1.B can be replaced accordingly. Similarly, any combination of ECIES Profile A and other PQC KEMs (Tables 1B, 2B, 3B, 4B of Solution 1) can be made into a hybrid profile.

[0273]

[0274] Table 19

[0275] The following modifications may be needed to incorporate the 3GPP TS 33.501 standard specification in Annex C: A new section for the hybrid profile (ECIES Profile B + PQC) needs to be created like ECIES.

[0276] CXX Hybrid Profile

[0277] Unless otherwise specified, hybrid profiles adhere to the terminology and processing specified in SECG Version 2 and the selected NIST PQC algorithm document. Profiles should use "named curves" over prime fields.

[0278] To generate successive counter blocks from the initial counter block (ICB) in CTR mode, the profile should use the standard increment function in Section B.1 of NIST Special Publication 800-38A, where m = 32 bits. The ICB corresponds to T1 in Section 6.5. AES-128 or AES-256 (with or without CTR) in CTR mode is preferred. If 256-bit security is required, AES-256 is required.

[0279] - The value of the MAC tag in the hybrid profile shall be the L most significant octets of the output generated by the HMAC function, where L is equal to maclen.

[0280] The hybrid profile uses its own standardized processes for key generation (Section 6 of RFC 7748 and the PQC KEM algorithm key generation procedure) and shared secret calculation (Section 5 of RFC 7748 and the shared secret generated by the PQC KEM algorithm). The calculated shared secret is a combination of two shared secrets, one generated from ECIES and the other from the PQC KEM algorithm. The Diffie-Hellman primitive X25519 (Section 5 of RFC 7748) takes two random octet strings as input, decodes them into a scalar and a coordinate, performs a multiplication, and encodes the result as an octet string. The shared secret output octet string from X25519, combined with the shared secret generated by the PQC KEM, should be used as input Z in the KDF (Section 3.6.1).

[0281] - The algorithm SHOULD use point compression to save overhead and SHOULD use the Elliptic Curve Cofactored Diffie-Hellman primitive (Section 3.3.2) to enable future addition of profiles with a cofactor h ≠ 1.

[0282] - For curves with cofactor h = 1, the two primitives (Sections 3.3.1 and 3.3.2) are equal. The profile shall not use backward compatibility mode (and is therefore not compatible with version 1 of SECG).

[0283] A hybrid profile of ECIES Profile B combined with the Kyber-1024 algorithm and security level 5 can be provided as mentioned in Table 20 (below), and can also have various parameters modified according to the security level (1, 3, 5) it supports, as marked below. The Level 1 and Level 3 parameters mentioned in Table 1.B can be replaced accordingly. Similarly, any combination of ECIES Profile B and other PQC KEMs (Tables 1B, 2B, 3B, 4B of Solution 1) can be made into a hybrid profile.

[0284]

[0285] Table 20

[0286] In another embodiment, a combined profile based on both PQC and KEM is utilized. In this context, a hybrid profile can also consist of two KEM algorithms that can be post-quantum, i.e., both are scheme identifiers based on post-quantum cryptography (KEM). All NIST-standardized PQC algorithms used for key encapsulation can be part of a PQC-based protection scheme. Some of the NIST Round 4 candidate algorithms can also be standardized. Since NIST-standardized PQC algorithms are tested for a minimum duration, if any one of the PQC algorithms is compromised, the other PQC algorithm can be protected to ensure security is not compromised. Therefore, even in the post-quantum era, even if the security of one of the PQC algorithms is compromised, these types of scheme identifiers cannot be compromised.

[0287] Figure 2A An exemplary environment 200a is shown in which a user equipment (UE) 101 registers with a home network (HN) 103 using hybrid key exchange, according to some embodiments of the present disclosure.

[0288] like Figure 2A As shown, exemplary environment 100 may include UE 101 and HN 103. UE 101 may include, but is not limited to, a smartphone, mobile device, tablet, laptop, desktop, or any device that can register with HN 103. HN 103 may include, but is not limited to, a base station, a network service station, a network provider, etc. UE 101 may communicate with HN 103 via communication network 213. Communication network 117 may be implemented as one of several types of networks, such as an intranet or a local area network (LAN). Communication network 213 may be a dedicated network or a shared network, representing a combination of several types of networks using various protocols, such as Hypertext Transfer Protocol (HTTP) or Transmission Control Protocol (TCP) and Transport Layer Security (TLS), Wireless Application Protocol (WAP), etc.

[0289] UE 101 may include a memory 201, an interface 203, and a processor 205. HN 103 may include an interface 207, a memory 209, and a processor 211. Figures 2B to 2E A detailed diagram of the UE 101 and the HN 103 is explained in FIG.

[0290] In an embodiment, UE 101 may initially generate a temporary public key and a temporary private key based on elliptic curve (EC) key generation technology. For example, UE 101 may use an elliptic curve cryptography (ECC) algorithm to generate a public and private key pair. ECC is a key-based technology used to encrypt data. In other words, ECC is a public key cryptography algorithm that can be used to perform critical security functions such as encryption, authentication, and digital signatures. After generating the temporary public key and temporary private key, UE 101 may generate a first temporary shared key based on the temporary private key and the elliptic curve (EC)-based HN 103 public key. UE 101 may use an elliptic curve Diffie-Hellman (ECDH) key agreement operation. ECDH key agreement allows the first temporary shared key to be derived using the UE 101 private key and the EC-based HN 103 public key. In other words, UE 101 generates the first temporary shared key by applying ECC technology to the temporary private key and the EC-based HN 103 public key.

[0291] Similarly, in the next step, UE 101 may generate a second temporary shared key and an encrypted shared key based on the post-quantum cryptography (PQC)-based public key associated with HN 103. Specifically, UE 101 may use the PQC-based HN 103 public key as input for PQC key encapsulation to generate the second temporary shared key. PQC encapsulation is an encapsulation technique that takes the HN 103 public key as input and outputs an encapsulation of a shared secret key and a secret key. In other words, UE 101 generates the second temporary shared key by applying the PQC Key Encapsulation Mechanism (KEM) technique to the PQC-based public key associated with HN 103.

[0292] In the next step, UE 101 may generate a temporary mixed shared key based on the first temporary shared key and the second temporary shared key. For example, UE 101 may combine the first temporary shared key and the second temporary shared key to generate the temporary mixed shared key. In one example, the temporary mixed shared key may be generated using concatenation, an exclusive-OR (XOR) mathematical function, or an HMAC function. For example, mixed temporary shared key (S) = first temporary shared key (S1) || second temporary shared key (S2), or S = S1 XOR S2, or an HMAC function with S1 and S2 as input.

[0293] For example, after generating a temporary hybrid shared secret key, UE 101 derives multiple keys from the temporary hybrid shared secret key using a key derivation function. A key derivation function (such as ANSI-X9.63-KDF) is used to derive multiple keys from the hybrid shared secret key. In the next step, after generating the temporary hybrid shared secret key, UE 101 may generate a ciphertext value and a message authentication code (MAC) tag value based on at least the temporary hybrid shared secret key. Specifically, UE 101 may generate a temporary encryption key and a temporary MAC key based on at least the temporary hybrid shared secret key. Similarly, UE 101 may generate a ciphertext value by performing symmetric encryption of plaintext based on the temporary encryption key. Finally, UE 101 may generate a MAC tag value by applying a MAC function to the temporary MAC key and the ciphertext value.

[0294] When SUPI hiding is performed, UE 101 uses a key distribution function (KDF) to generate an initial counter block (ICB), a MAC key, and an Advanced Encryption Standard (AES) encryption key. UE 101 then uses the symmetric key encryption algorithm (AES) to hide the SUPI and generate a hidden SUPI value. UE 101 uses a hash-based message authentication code (HMAC) function to ensure integrity protection for the generated hidden SUPI. HMAC uses the derived MAC key to generate a MAC tag for the hidden SUPI. The aforementioned steps can be used for SUPI hiding. Among these five operations, key generation and key agreement are based on elliptic curve-based public key cryptography. After SUPI hiding, UE 101 sends the SUCI to HN 103. That is, finally, UE 101 may send a registration request to register UE 101 with HN 103, along with the temporary public key, encrypted shared key, ciphertext value, and MAC tag value. In an alternative embodiment, UE 101 may create a security profile. UE 101 can create a security profile based on creating a PQC-based profile using one or more PQC parameters for encryption, decryption, encapsulation, and decapsulation of identities and data sent from UE 101 to HN 103, and creating a hybrid profile using one or more hybrid parameters for encryption, decryption, encapsulation, and decapsulation of identities and data sent from UE 101 to HN 103. Furthermore, UE 101 can perform primary authentication using the one or more PQC parameters and the one or more hybrid parameters before sending data from UE 101 to HN 103. The one or more hybrid parameters may include, but are not limited to, a type of PQC KEM algorithm, a type of PQC digital signature algorithm, a security level, and the like. The one or more hybrid parameters form a PQC and hybrid (i.e., traditional + PQC) profile.

[0295] In response to the registration request from UE 101, HN 103 may generate a first temporary shared key based on at least the temporary public key and an ECC-based public key associated with HN 103. HN 103 generates the first temporary shared key by applying an ECC technique to the temporary private key and the ECC-based public key of HN 103. In a next step, HN 103 may generate a second temporary shared key based on the encrypted shared key and the PQC-based private key associated with HN 103. HN 103 generates the second temporary shared key by applying a PQC key decapsulation mechanism (KDM) technique to the encrypted shared key and the PQC-based public key associated with HN 103.

[0296] In the next step, HN 103 can generate a temporary mixed shared key based on the first temporary shared key and the second temporary shared key. In one example, the temporary mixed shared key can be generated using a concatenation, an XOR mathematical function, or an HMAC function. For example, the mixed temporary shared key (S) = the first temporary shared key (S1) || the second temporary shared key (S2), or S = S1 XOR S2, or an HMAC function with S1 and S2 as input.

[0297] For example, after generating a temporary hybrid shared secret key, HN 103 uses a key derivation function to derive multiple keys from the temporary hybrid shared secret key. A key derivation function, such as an ANSI-X9.63 KDF, is used to derive multiple keys from the hybrid shared secret key. In the next step, after generating the temporary hybrid shared secret key, HN 103 may generate a temporary decryption key and a temporary MAC key based on at least the temporary hybrid shared secret key. Similarly, HN 103 may generate plaintext by performing symmetric decryption of the ciphertext value based on the at least one temporary decryption key. The plaintext may include 15 digits. Finally, HN 103 may register UE 101 with HN 103 based on the generated plaintext.

[0298] In another embodiment, UE 101 is registered with HN 103 using a hybrid key exchange. UE 101 may generate a first temporary shared key and a first encrypted shared key based on a home network public key based on a first post-quantum cryptography (PQC). Specifically, UE 101 may generate the first temporary shared key and the first encrypted shared key by applying a PQC key encapsulation mechanism (KEM) technique to the home network public key based on the first PQC. UE 101 may generate a second temporary shared key and a second encrypted shared key based on a home network public key based on a second PQC. Specifically, UE 101 may generate the second temporary shared key and the second encrypted shared key by applying a PQC KEM technique to the home network public key based on the second PQC.

[0299] In the next step, UE 101 may generate a temporary mixed shared key based on the first temporary shared key and the second temporary shared key. In one example, the temporary mixed shared key may be generated using concatenation, an XOR mathematical function, or an HMAC function. For example, mixed temporary shared key (S) = first temporary shared key (S1) || second temporary shared key (S2), or S = S1 XOR S2, or an HMAC function with S1 and S2 as input.

[0300] For example, after generating a temporary hybrid shared secret key, UE 101 derives multiple keys from the temporary hybrid shared secret key using a key derivation function. A key derivation function (such as ANSI-X9.63-KDF) is used to derive multiple keys from the hybrid shared secret key. In the next step, after generating the temporary hybrid shared secret key, UE 101 may generate a ciphertext value and a message authentication code (MAC) tag value based on at least the temporary hybrid shared secret key. Specifically, UE 101 may generate a temporary encryption key and a temporary MAC key based on at least the temporary hybrid shared secret key. Similarly, UE 101 may generate a ciphertext value by performing symmetric encryption of plaintext based on the temporary encryption key. Finally, UE 101 may generate a MAC tag value by applying a MAC function to the temporary MAC key and the ciphertext value.

[0301] In the next step, UE 101 may send a registration request along with the temporary public key, the encrypted shared key, the ciphertext value, and the MAC tag value to register UE 101 to HN 103. The MAC tag value may be used to perform an integrity check in HN 103.

[0302] In response to the registration request from UE 101, HN 103 may generate a first temporary shared key based on at least the first encrypted shared key and a first post-quantum cryptography (PQC)-based private key associated with HN 103. HN 103 may also generate a second temporary shared key based on the second encrypted shared key and a second PQC-based private key associated with HN 103. In a next step, HN 103 may generate a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key. HN 103 generates the second temporary shared key by applying a PQC key decapsulation mechanism (KDM) technique to the encrypted shared key and a PQC-based public key associated with HN 103.

[0303] In the next step, HN 103 may generate a temporary mixed shared key based on the first temporary shared key and the second temporary shared key. In one example, the temporary mixed shared key may be generated using concatenation, an XOR mathematical function, or an HMAC function. For example, the mixed temporary shared key (S) = the first temporary shared key (S1) || the second temporary shared key (S2), or S = S1 XOR S2, or an HMAC function with S1 and S2 as input.

[0304] For example, after generating a temporary hybrid shared secret key, HN 103 uses a key derivation function to derive multiple keys from the temporary hybrid shared secret key. A key derivation function, such as an ANSI-X9.63 KDF, is used to derive multiple keys from the hybrid shared secret key. In the next step, after generating the temporary hybrid shared secret key, HN 103 may generate a temporary decryption key and a temporary MAC key based on at least the temporary hybrid shared secret key. Similarly, HN 103 may generate plaintext by performing symmetric decryption of the ciphertext value based on the at least one temporary decryption key. The plaintext may include 15 digits. Finally, HN 103 may register UE 101 with HN 103 based on the generated plaintext.

[0305] In another embodiment, UE 101 is registered with HN 103 using hybrid key encryption. UE 101 may generate a temporary public key and a temporary private key based at least on elliptic curve (EC) key generation techniques. UE 101 may generate a temporary shared key based on the temporary private key and the EC-based home network public key. In a next step, UE 101 may generate a temporary encryption key and a temporary message authentication code (MAC) key based at least on the temporary hybrid shared key. UE 101 may generate an intermediate ciphertext value by performing symmetric encryption of the plaintext using the temporary encryption key.

[0306] In the next step, UE 101 may generate a ciphertext value based on the intermediate ciphertext value and the PQC-based HN 103 public key. Specifically, UE 101 may generate the ciphertext value by applying PQC-based encryption to the intermediate ciphertext value based on the PQC HN 103 public key. In the next step, UE 101 may generate a MAC tag value based on at least the ciphertext value and the temporary MAC tag key. Specifically, UE 101 may generate the MAC tag value by applying a MAC function to the temporary MAC key and the ciphertext value.

[0307] In the next step, UE 101 may send a registration request along with the temporary public key, the ciphertext value, and the MAC tag value to register UE 101 to HN 103. The MAC tag value may be used to perform an integrity check in HN 103.

[0308] In response to the registration request, HN 103 may generate a temporary shared key based on the temporary public key and an elliptic curve (EC)-based private key associated with home network 103. HN 103 may also generate a temporary decryption key and a temporary MAC key based on the temporary shared key. In the next step, HN 103 may generate an intermediate ciphertext value by applying post-quantum cryptography (PQC) decryption to the ciphertext value based on the PQC-based home network public key. In the next step, HN 103 may generate plaintext by performing symmetric decryption of the intermediate ciphertext value based on at least the temporary decryption key. Finally, HN 103 may register UE 101 with HN 103 based on the generated plaintext.

[0309] In another embodiment, UE 101 is registered with HN 103 using hybrid key encryption. Specifically, UE 101 may split the plaintext into a first portion and a second portion. In the next step, UE 101 may generate a first ciphertext value based on a first post-quantum cryptography (PQC)-based public key associated with home network 103. Specifically, UE 101 may generate the first ciphertext value by applying a first post-quantum cryptography (PQC) key encapsulation mechanism (KEM) technique to the first portion of the plaintext and the first PQC-based home network public key. UE 101 may generate a second ciphertext value based on a second PQC-based public key associated with HN 103. Specifically, UE 101 may generate the second ciphertext value by applying a second PQC KEM technique to the second portion of the plaintext and the PQC-based public key associated with the home network. Finally, UE 101 may send a registration request to register UE 101 with HN 103, along with the first and second ciphertext values.

[0310] HN 103 may receive a registration request. In response to receiving the registration request, HN 103 may generate a first portion of plaintext by decrypting a first ciphertext value based on a first post-quantum cryptography (PQC) private key associated with home network 103. HN 103 may generate a second portion of plaintext by decrypting a second ciphertext value based on a second PQC private key associated with home network 103. Specifically, HN 103 may decrypt the first ciphertext value by applying a first PQC decryption technique to the first ciphertext value and the first PQC private key. Similarly, HN 103 may decrypt the second ciphertext value by applying a second PQC decryption technique to the second ciphertext value and the second PQC private key. HN 103 may generate plaintext by combining the first portion of plaintext with the second portion of plaintext. Finally, HN 103 may register UE 101 with HN 103 based on the generated plaintext.

[0311] In another embodiment, UE 101 may be registered with HN 103 using hybrid key encryption. Specifically, UE 101 may generate an intermediate ciphertext value based on a home network public key and plaintext using a first post-quantum cryptography (PQC) technique. Specifically, UE 101 may generate the intermediate ciphertext value by applying a first PQC encryption technique to the plaintext and the home network public key based on the first PQC technique.

[0312] In the next step, UE 101 may generate a ciphertext value based on the intermediate ciphertext value and the HN 103 public key based on the second PQC. Specifically, HN 103 may generate the ciphertext value by applying the second PQC encryption technique to the intermediate ciphertext value and the home network public key based on the second PQC. Finally, UE 101 may send a registration request for registering UE 101 to HN 103 along with the ciphertext value, thereby registering UE 101 with home network 103.

[0313] HN 103 may receive the registration request. In response to receiving the registration request, HN 103 may generate an intermediate ciphertext value based on the ciphertext value and the home network private key based on the second PQC. Specifically, HN 103 may generate the intermediate ciphertext value by applying the second PQC decryption technique to the ciphertext value and the home network private key based on the second PQC. HN 103 may generate plaintext based on the intermediate ciphertext value and the home network private key based on the first PQC. Specifically, HN 103 may generate the plaintext value by applying the first PQC decryption technique to the intermediate ciphertext value and the home network private key based on the first PQC. In the next step, HN 103 may register UE 101 with HN 103 based on the generated plaintext.

[0314] Figure 2B A detailed block diagram 200b of the UE 101 shown in FIG. 1 is shown according to some embodiments of the present disclosure.

[0315] In an embodiment, UE 101 may include an interface 203, a memory 201, and a central processing unit (also referred to as a "CPU" or "one or more processors"). In some embodiments, memory 201 may be communicatively coupled to one or more processors 205. Memory 201 stores instructions executable by one or more processors 205. One or more processors 205 may include at least one data processor for executing program components for carrying out user or system-generated requests. One or more processors 205 may perform one or more functions of UE 101, including registering UE 101 with HN 103 using hybrid key exchange or hybrid key encryption. Memory 201 may store instructions executable by one or more processors 205 that, when executed, cause one or more processors 205 to register UE 101 with HN 103. Interface 203 may be coupled to one or more processors 205. For example, one or more processors 205 may communicate with HN 103, as shown in FIG1 .

[0316] In an embodiment, the one or more processors 205 may include one or more modules or hardware units, such as, but not limited to, a generating unit 215 and a sending unit 217. In some embodiments, the one or more modules or units may be software modules that may be stored in the memory 201. The one or more modules or hardware units may be configured to perform various operations of the present disclosure to register the UE 101 with the HN 103 using hybrid key exchange or hybrid key encryption.

[0317] Figure 2C A detailed block diagram of the HN 103 shown in FIG. 1 is shown, according to some embodiments of the present disclosure.

[0318] In an embodiment, some functions of HN 103 may be performed by HN 103 itself. In an embodiment, HN 103 may include an interface 207, a memory 209, and a central processing unit (also referred to as a "CPU" or "one or more processors"). In some embodiments, memory 209 may be communicatively coupled to one or more processors 211. Memory 209 stores instructions executable by one or more processors 211. One or more processors 211 may include at least one data processor for executing program components for executing user or system-generated requests. One or more processors 211 may perform one or more functions of HN 103 for registering UE 101 with HN 103 using hybrid key exchange or hybrid key encryption. Memory 209 may store instructions executable by one or more processors 211 that, when executed, cause one or more processors 211 to register UE 101 with HN 103 using hybrid key exchange or hybrid key encryption.

[0319] In an embodiment, the one or more processors 211 may include one or more modules or hardware units, such as, but not limited to, a receiving unit 217, a generating unit 219, and a registering unit 221. In some embodiments, the one or more modules or units may be software modules that may be stored in the memory 209. The one or more modules or hardware units may be configured to perform various operations of the present disclosure to register the UE 101 with the HN 103 using hybrid key exchange or hybrid key encryption.

[0320] Figure 2D A detailed block diagram 200d of the UE 101 shown in FIG. 1 is shown according to some embodiments of the present disclosure.

[0321] In an embodiment, the UE 101 may include an interface 203, a memory 201, and a central processing unit (also referred to as a "CPU" or "one or more processors"). In some embodiments, the memory 201 may be communicatively coupled to the one or more processors 205. The memory 201 stores instructions executable by the one or more processors 205. The one or more processors 205 may include at least one data processor for executing program components for executing user or system generated requests. The one or more processors 205 may perform one or more functions of the UE 101 for registering the UE 101 with the HN 103 using hybrid key exchange or hybrid key encryption. The memory 201 may store instructions executable by the one or more processors 205, which when executed may cause the one or more processors 205 to register the UE 101 with the HN 103. The interface 203 may be coupled to the one or more processors 205. For example, the one or more processors 205 may communicate with the HN 103, such as Figure 2A shown.

[0322] In an embodiment, the one or more processors 205 may include one or more modules or hardware units, such as, but not limited to, a splitting unit 223, a generating unit 225, and a sending unit 227. In some embodiments, the one or more modules or units may be software modules that may be stored in the memory 201. The one or more modules or hardware units may be configured to perform various operations of the present disclosure to register the UE 101 with the HN 103 using hybrid key exchange or hybrid key encryption.

[0323] Figure 2E A detailed block diagram 200e of the HN 103 shown in FIG. 1 is shown, according to some embodiments of the present disclosure.

[0324] In an embodiment, some functions of HN 103 may be performed by HN 103 itself. In an embodiment, HN 103 may include an interface 207, a memory 209, and a central processing unit (also referred to as a "CPU" or "one or more processors"). In some embodiments, memory 209 may be communicatively coupled to one or more processors 211. Memory 209 stores instructions executable by one or more processors 211. One or more processors 211 may include at least one data processor for executing program components for executing user or system-generated requests. One or more processors 211 may perform one or more functions of HN 103 for registering UE 101 with HN 103 using hybrid key exchange or hybrid key encryption. Memory 209 may store instructions executable by one or more processors 211 that, when executed, cause one or more processors 211 to register UE 101 with HN 103 using hybrid key exchange or hybrid key encryption.

[0325] In an embodiment, the one or more processors 211 may include one or more modules or hardware units, such as, but not limited to, a receiving unit 229, a generating unit 231, and a registering unit 233. In some embodiments, the one or more modules or units may be software modules that may be stored in the memory 209. The one or more modules or hardware units may be configured to perform various operations of the present disclosure to register the UE 101 with the HN 103 using hybrid key exchange or hybrid key encryption.

[0326] Figure 2F A flow chart illustrating hybrid SUPI hiding at the UE 101 using legacy and PQC based shared key generation according to some embodiments of the present disclosure is shown.

[0327] Figure 2F Hiding a hybrid SUPI is depicted. Here, a hybrid combination of classical and PQC algorithms can be used, rather than relying on elliptic curve-based public key cryptography (which is not quantum-safe) or postquantum-safe cryptography algorithms (which are not well-tested). In step 1 of the hybrid SUPI hiding process at UE 101, UE 101 can generate a temporary public and private key pair based on an elliptic curve. In step 2, UE 101 can generate a shared key (S1) using elliptic curve-based Diffie-Hellman key agreement. This takes the EC-based UE private key and the HN 103 public key and generates the shared key (S1). In step 2b, UE 101 can generate the shared key (S2) using a PQC-based key encapsulation method. Here, the PQC key encapsulation method receives the PQC-based HN 103 public key as input and can generate an output comprising the shared key (S2) and the encrypted shared key. In step 3 (Hybrid Shared Secret Generation Function), a hybrid shared secret (s) is generated using shared secret (s1) and shared secret (s2). This hybrid shared secret generation can use simple concatenation, where shared secret "s" can be generated using the simple concatenation of "s1" and "s2"; for example, s = s1||s2. The hybrid shared secret can also be generated using an XOR operation; for example, s = s1 XOR s2. Another way to generate the hybrid shared secret can be using the HMAC function, where s1 and s2 are inputs and s is the output. After generating the shared secret, in step 4, UE 101 can receive the shared secret as input and generate multiple keys similar to the ECIES scheme, such as the ICB, MAC key, and AES encryption key. In step 5, UE 101 can use symmetric key encryption to conceal the SUPI. Furthermore, in step 6, UE 101 can use the HMAC function to derive a MAC tag corresponding to the encrypted SUPI, which is required to provide integrity. In summary, embodiments herein provide a hybrid-based shared key generation for SUCI hiding using an elliptic curve-based algorithm and a post quantum safe cryptographic algorithm.

[0328] In addition, after SUPI concealment at UE 101, the solution output may be sent to HN 103. Typically, the solution output may include the encrypted SUPI and other parameters required for smooth de-concealment of SUPI at the HN 103 end.

[0329] Figure 2G A block diagram illustrating the output of a modified scheme based on hybrid SUPI hiding using traditional and PQC based shared key generation according to some embodiments of the present disclosure is shown.

[0330] like Figure 2G As shown, a new hiding scheme using traditional + PQC-based shared key generation is proposed. In the proposed SUPI hiding scheme, UE 101 can also generate an encrypted shared key as an output corresponding to the shared key (s2). Furthermore, to obtain the same shared key (s2) on the HN 103 side, the encrypted shared key can be included in the scheme output along with the EC-based UE public key, ciphertext, and MAC tag.

[0331] Figure 2H A flow chart is shown for hybrid SUCI de-concealment at the UE 101 using legacy and PQC based shared key generation according to some embodiments of the present disclosure. Figure 2H The process of decrypting a hybrid SUPI is depicted. Instead of relying on elliptic curve-based public key cryptography (which is not quantum-safe) or post-quantum-safe cryptography algorithms (which are not well-tested), a hybrid combination of classical and PQC algorithms can be used. After receiving the SUCI from UE 101, HN 103 can retrieve its associated EC-based UE public key, encrypted shared key, ciphertext, and MAC tag. In step 1a, HN 103 can generate a shared key (S1) using elliptic curve-based Diffie-Hellman key agreement. This takes the EC-based UE public key and the HN 103 private key and generates the shared key (S1). In step 1b, HN 103 can use the PQC decapsulation method, which takes the PQC-based HN 103 private key and the encrypted shared key as input and retrieves the shared key (S2) as output. In step 3 (hybrid shared key generation function), the shared key (S1) and the shared key (S2) are used to generate a hybrid shared key. This hybrid shared secret can be generated using simple concatenation, where the shared secret "s" can be generated using the simple concatenation of "s1" and "s2"; for example, s = s1 || s2. The hybrid shared secret can also be generated using an XOR operation; for example, s = s1 XOR s2. Another way to generate the hybrid shared secret is to use an HMAC function, where s1 and s2 are input and s is the output. Here, by using the PQC decapsulation method and ECDH-based key agreement for shared secret generation at HN 103, the embodiments herein make SUCI decryption secure. Furthermore, the generated shared secret can be used in step 3 (key derivation). In step 3, a KDF takes the shared secret as input and generates multiple keys similar to SUCI decryption. In step 4, HN 103 can decrypt the SUCI using symmetric key decryption and verify the integrity of the received SUCI using an HMAC function. In summary, the embodiments herein combine the elliptic curve-based process of the ECIES scheme with a post-quantum-safe cryptographic algorithm for SUCI decryption.

[0332] Figure 2I A sequence diagram illustrating hybrid SUPI hiding and de-hiding using conventional and PQC based shared key generation according to some embodiments of the present disclosure is shown. Figure 2I As shown, during SIM provisioning, as shown in step 1 (S1), UE 101 is initially provisioned with an EC-based public key and a PQC-based HN 103 public key. Later, when UE 101 wishes to initiate SUPI hiding, UE 101 may generate an EC-based public-private key pair, as shown in step 2 (S2), and generate a shared key (s1) using ECDH key negotiation, as shown in step 3 (S3). To perform PQC-based key encapsulation for shared key generation (s2), embodiments herein use a combined shared key generation and a KDF for multi-key generation. Later, SUPI encryption and MAC tag generation are performed using AES encryption and an HMAC function, as shown in steps 4 (S4) and 5 (S5). All of these steps are part of SUPI hiding. After SUPI hiding is complete, UE 101 creates the scheme output, as shown in step 6 (S6), which may include the encrypted shared key, ciphertext, and MAC tag. The ciphertext includes the hidden SUPI, and the MAC tag includes the MAC of the hidden SUPI. The scheme output is transmitted from UE 101 to HN 103 as part of a SUCI packet. After receiving the SUCI, HN 103 initiates the SUCI de-hiding process. Furthermore, HN 103 can generate a shared secret using ECDH key agreement for s1, PQC key decapsulation for s2, combined shared generation of s, and a KDF for multi-key generation, as shown in step 7 (S7). HN 103 then verifies the integrity of the SUCI packet using an HMAC function and completes SUCI hiding using an AES decryption function, as shown in steps 8 (S8) and 9 (S9). The hybrid use of the SUPI hiding algorithm and the SUCI hiding algorithm makes them quantum-safe and highly reliable.

[0333] Figure 3A 1 shows a flow chart of hybrid SUPI hiding at UE 101 using PQC and PQC-based shared key generation according to some embodiments of the present disclosure. Figure 3A As shown, hybrid SUPI concealment is depicted. Here, a hybrid combination of multiple PQC algorithms can be used, rather than relying solely on a single post-quantum-safe cryptography algorithm (which may not be well-tested or secure). In steps 1a and 1b, UE 101 can use a PQC-based key encapsulation method to generate a shared key (s1) and a shared key (s2). The PQC key encapsulation method used in these two steps can use different PQC algorithms. The PQC key encapsulation method includes receiving PQC-based HN 103 public keys 1 and 2 as inputs and can generate outputs including shared keys (s1), shared keys (s2), and encrypted shared keys (es1) and encrypted shared keys (es2). In step 2 (hybrid shared key generation function), a hybrid shared key (s) is generated using shared keys (s1) and (s2). This hybrid shared key generation function can use a simple concatenation, where shared key "s" can be generated using a simple concatenation of "s1" and "s2," for example, s = s1||s2. A hybrid shared secret can also be generated using an XOR operation; for example, s = s1 XOR s2. Another approach to generating a hybrid shared secret can use an HMAC function, where s1 and s2 are inputs and s is output. After generating the shared secret, in step 3, UE 101 can receive the shared secret as input and generate multiple keys similar to the ECIES scheme, such as the ICB, MAC key, and AES encryption key. In step 4, UE 101 can use symmetric key encryption to conceal the SUPI. Furthermore, in step 5, UE 101 can use the HMAC function to derive a MAC tag corresponding to the encrypted SUPI, which is required to provide integrity. In summary, embodiments herein provide hybrid-based shared secret generation for concealing SUCI using multiple post-quantum-safe cryptographic algorithms. Furthermore, after SUPI concealment at UE 101, the scheme output can be sent to HN 103. Typically, the scheme output can include the encrypted SUPI and other parameters required for smooth de-concealment of the SUCI at HN 103.

[0334] Figure 3B A block diagram illustrating the output of a modified scheme for hybrid SUPI hiding based on the use of PQC and PQC-based shared key generation according to some embodiments of the present disclosure is shown. Figure 3B A new hybrid-based SUPI hiding and de-hiding scheme using PQC and PQC-based shared key generation is proposed. In the proposed SUPI hiding, the UE 101 can generate multiple encrypted shared keys as outputs corresponding to the multiple shared keys. Furthermore, to obtain the same shared keys at the HN 103, the encrypted shared key (es1) and the encrypted shared key (es2) can be included in the scheme output along with the ciphertext and MAC tag.

[0335] Figure 3C 1 shows a flow chart of hybrid SUCI de-concealment at UE 101 using PQC and PQC-based shared key generation according to some embodiments of the present disclosure. Figure 3C As shown, after receiving the SUCI from UE 101, HN 103 can retrieve the encrypted shared secret, ciphertext, and MAC tag associated with it. At steps 1a and 1b, HN 103 can use the PQC decapsulation method, which takes the PQC-based HN 103 private key-1, the private key-1, and the encrypted shared secret (es1) and encrypted shared secret (es2) as inputs and retrieves the shared secret (s1) and shared secret (s2) as outputs. In step 2 (hybrid shared secret generation function), a hybrid shared secret (s) is generated using the shared secret (s1) and the shared secret (s2). This hybrid shared secret generation function can use simple concatenation, where the shared secret "s" can be generated using the simple concatenation of "s1" and "s2"; for example, s = s1 || s2. The hybrid shared secret can also be generated using an XOR operation; for example, s = s1 XOR s2. Another way to generate the hybrid shared secret is to use the HMAC function, where s1 and s2 are inputs and s is the output. Furthermore, the generated shared key can be used for key derivation in step 3. In step 3, the KDF takes the shared key as input and can generate multiple keys similar to those used for SUCI 5 hiding. In step 4, the HN 103 can decrypt the SUCI using symmetric key decryption and verify the integrity of the received SUCI using an HMAC function. In summary, embodiments herein combine multiple post-quantum secure cryptographic algorithms for SUCI dehiding.

[0336] Figure 3D A sequence diagram illustrating hybrid SUPI hiding and de-hiding using PQC and PQC-based shared key generation according to some embodiments of the present disclosure is shown. Figure 3D As shown, during SIM provisioning, as shown in step 1 (S1), the HN 103 public key, based on multiple PQCs, may be initially provisioned to the UE 101. Later, when the UE 101 wishes to initiate SUPI hiding, it performs PQC-based key encapsulation to generate a shared key (S1) and a shared key (S2), and uses the combined shared key generation, as shown in step 2 (S2), and a KDF for multi-key generation, as shown in step 3 (S3). It then encrypts the SUPI and MAC tag using AES encryption and an HMAC function, as shown in steps 4 (S4) and 5 (S5). These steps are part of SUPI hiding. After completing SUPI hiding, the UE 101 creates a solution output, which may include multiple encrypted shared keys, a ciphertext, and a MAC tag. Here, the ciphertext includes the hidden SUPI and the MAC tag, which includes the MAC of the hidden SUPI. As shown in step 6 (S6), the solution output is transmitted from the UE 101 to the HN 103 as part of a SUCI packet. After receiving the SUCI, HN 103 initiates the SUCI de-hiding process. Furthermore, HN 103 may use PQC key decapsulation to generate a shared secret, as shown in step 7 (S7), and use the combined shared secret generation and KDF for multi-key generation, as shown in step 8 (S8). Subsequently, HN 103 verifies the integrity of the SUCI packet using an HMAC function and completes SUCI hiding using an AES decryption function, as shown in step 9 (S9). The use of multiple PQC algorithms in SUCI hiding and SUCI de-hiding makes them both quantum-safe and more reliable.

[0337] Figure 4A A flow chart illustrating hybrid SUPI hiding at the UE 101 using legacy and PQC based shared key encryption according to some embodiments of the present disclosure is shown. Figure 4A The process of performing hybrid SUPI hiding is depicted. Here, a hybrid combination of classical algorithms and PQC algorithms can be used for SUPI encryption and decryption, rather than relying on elliptic curve-based public key cryptography (which is not quantum-safe) or post-quantum-safe cryptography algorithms (which are not well-tested).

[0338] In step 1, UE 101 generates a temporary public and private key pair based on an elliptic curve. In step 2, UE 101 generates a shared key (S1) using elliptic curve Diffie-Hellman key negotiation. This takes the EC-based UE private key and the HN 103 public key and generates the shared key. After generating the shared key, in step 3, UE 101 receives the shared key as input and can use a key distribution function (KDF) to generate multiple keys similar to the ECIES scheme, such as the ICB, MAC key, and AES encryption key. In step 4, UE 101 can use symmetric key encryption to conceal the SUPI and generate intermediate ciphertext. In step 5, UE 101 can encrypt the intermediate ciphertext using asymmetric key encryption based on the PQC algorithm. PQC-based encryption takes the PQC-based HN 103 public key and the intermediate ciphertext as input and generates the concealed SUPI as output. Furthermore, in step 6, UE 101 can use the HMAC function to derive a MAC tag corresponding to the encrypted SUPI, which is required to provide integrity. In summary, embodiments herein provide hybrid encryption for SUCI hiding using ECIES and post-quantum secure cryptography.

[0339] In addition, after SUPI hiding at UE 101, a solution output may be sent to HN 103. Typically, the solution output may include the encrypted SUPI and other parameters required for smooth de-hiding of SUPI at HN 103. In the proposed SUPI hiding, the solution output will include the EC-based UE public key, ciphertext, and MAC tag, similar to the classic ECIES-based SUPI hiding.

[0340] Figure 4B A flow chart illustrating hybrid SUCI de-concealment at the UE 101 using traditional and PQC based shared key decryption according to some embodiments of the present disclosure is shown. Figure 4B The process of hybrid SUPI de-hiding is depicted. Here, after receiving SUCI from UE 101, HN 103 can retrieve its associated EC-based UE public key, ciphertext, and MAC tag. In step 1, HN 103 can generate a shared key using elliptic curve-based Diffie-Hellman key negotiation. This takes the EC-based UE public key and the HN 103 private key and generates the shared key. Furthermore, the generated shared key can be used for key derivation in step 3. In step 2, a KDF takes the shared key as input and can generate multiple keys, similar to SUPI hiding. In step 4, HN 103 can initiate SUCI decryption using asymmetric key decryption. HN 103 uses PQC-based decryption, which takes the HN 103 private key and ciphertext and generates intermediate ciphertext. HN 103 can de-hidden the intermediate ciphertext using symmetric key decryption. In step 5, HN 103 verifies the integrity of the received SUCI using the HMAC function. In summary, embodiments herein combine the elliptic curve-based procedure of the ECIES scheme with post-quantum-secure cryptographic algorithms in SUCI decryption.

[0341] Figure 4C A sequence diagram illustrating hybrid SUPI hiding and de-hiding using conventional and PQC based shared key encryption and decryption according to some embodiments of the present disclosure is shown.

[0342] like Figure 4C As shown, during SIM provisioning, as shown in step 1 (S1), a multi-ECC-based public key and a PQC-based HN 103 public key may be initially provisioned to UE 101. Later, when UE 101 wishes to initiate SUPI hiding, UE 101 performs PQC-based key encapsulation to generate a shared key (s1) and a shared key (s2), using the HN 103 public key and the UEEC private key, as shown in step 2 (S2). At step 3 (S3), UE 101 uses a KDF to generate an encryption key and a MAC key, ICB, from the shared key. It then encrypts the SUPI using AES and may generate an intermediate ciphertext value, as shown in step 4 (S4). At step 5 (S5), UE 101 may encrypt the intermediate ciphertext value using PQC-based encryption. At step 6 (S6), UE 101 may generate a MAC tag for the encrypted SUPI using HMAC. These steps are part of SUPI hiding. After SUPI concealment is complete, UE 101 creates a solution output, which includes multiple encrypted shared keys, a ciphertext, and a MAC tag. Here, the ciphertext includes the hidden SUPI and a MAC tag, which includes the MAC address of the hidden SUPI. As shown in step 7, the solution output is transmitted from UE 101 to HN 103 as part of a SUCI packet (S7). Upon receiving the SUCI, HN 103 initiates the SUCI de-hiding process. Furthermore, HN 103 can decapsulate the SUCI using the PQC key to generate a shared secret, as shown in step 7 (S7). In step 8, HN 103 can generate a shared secret key using the HN 103 EC private key and the UE EC-based public key. In step 9, HN 103 can use a KDF to generate a decryption key, a MAC key, and an ICB from the shared key. HN 103 can decrypt the SUPI using PQC-based decapsulation, as shown in step 10, and can decrypt the intermediate ciphertext using the decrypted key with AES. At step 11 ( S11 ), the HN 103 may verify the ciphertext value.

[0343] Figure 5A A flow chart illustrating hybrid SUPI concealment at the UE 101 using PQC and PQC-based ciphering in a parallel manner according to some embodiments of the present disclosure is shown. Figure 5A The process of performing hybrid SUPI concealment is depicted. Here, a hybrid combination of multiple PQC algorithms can be used, rather than relying solely on a single post-quantum-safe cryptography algorithm (which may not be well-tested or secure). At step 1a, UE 101 can use PQC-based encryption algorithm 1. Here, the PQC-based encryption takes plaintext-1 (half of the SUPI) and the PQC-based public key of HN 103 as input, and generates ciphertext-1 as output. Similarly, at step 1b, UE 101 can use PQC-based encryption algorithm 2. Here, the PQC-based encryption takes plaintext-2 (the other half of the SUPI) and the PQC-based public key of HN 103 as input, and generates ciphertext-2 as output. In summary, embodiments herein provide hybrid encryption-based SUPI concealment using multiple post-quantum-safe cryptography algorithms in parallel. Furthermore, after SUPI concealment at UE 101, the scheme output can be sent to HN 103. Typically, the scheme output may include the encrypted SUPI and other parameters required for smooth de-concealment of the SUCI at the HN 103 end.

[0344] Figure 5B FIG2 is a block diagram illustrating the output of a modified scheme for hybrid SUPI hiding based on using PQC and PQC-based shared key encryption in a parallel manner according to some embodiments of the present disclosure. Figure 5B As shown, a new hybrid-based SUPI hiding and de-hiding scheme using PQC-based + PQC-based encryption is proposed. In the proposed SUPI hiding, ciphertext-1 and ciphertext-2 need to be sent in the scheme output.

[0345] Figure 5C A flow chart of hybrid SUCI de-concealment at the HN 103 using PQC and PQC-based decryption in a parallel manner is shown. Figure 5C The process of hybrid SUCI de-hiding at HN 103 is depicted. Here, a hybrid combination of multiple PQC algorithms can be used, rather than relying solely on a single post-quantum-safe cryptography algorithm (which may not be well-tested or secure). At step 1a, HN 103 can use PQC-based encryption algorithm 1. Here, the PQC-based encryption takes ciphertext-1 and the PQC-based public key of HN 103 as input and produces plaintext-1 (the first half of the SUPI) as output. Similarly, at step 1b, HN 103 can use PQC-based encryption algorithm 2. Here, the PQC-based encryption takes ciphertext-2 and the PQC-based public key of HN 103 as input and produces plaintext-2 (the second half of the SUPI) as output. In summary, embodiments herein provide hybrid encryption-based SUCI hiding using multiple post-quantum-safe cryptography algorithms in parallel.

[0346] Figure 6A A flow chart illustrating hybrid SUPI concealment at the UE 101 using PQC and PQC-based ciphering in a sequential manner according to some embodiments of the present disclosure is shown. Figure 6A The process of hybrid SUPI hiding is described. Here, a hybrid combination of multiple PQC algorithms can be used, rather than relying solely on a single post-quantum-safe cryptographic algorithm (which may not be well-tested or secure). At step 1 of hybrid SUPI hiding at UE 101, UE 101 may use PQC-based encryption algorithm 1. Here, the PQC-based encryption takes the plaintext (SUPI) and the PQC-based HN 103 public key as input and generates the resulting intermediate ciphertext as output. At step 2, UE 101 uses another PQC-based encryption algorithm 2. Here, the PQC-based encryption takes the intermediate ciphertext and the PQC-based HN 103 public key as input and generates the final ciphertext, or hidden SUPI. In summary, embodiments herein provide hybrid-based encryption for SUPI hiding using multiple post-quantum-safe cryptographic algorithms by performing hiding and de-hiding in a sequential manner. Furthermore, after SUPI hiding at UE 101, the scheme output may be sent to HN 103. Typically, the scheme output may include the encrypted SUPI and other parameters required for smooth de-concealment of the SUCI at the HN 103 end.

[0347] Figure 6B FIG2 shows a block diagram of a modified scheme output based on hybrid SUPI hiding using PQC and PQC-based encryption according to some embodiments of the present disclosure. Figure 6B As shown, a new hybrid-based SUPI hiding and de-hiding scheme using PQC and PQC-based encryption is proposed. In the proposed SUPI hiding, the ciphertext needs to be sent together with the scheme output.

[0348] Figure 6C 1 shows a flow chart of hybrid SUPI de-concealment at the HN 103 using PQC and PQC-based decryption in a sequential manner according to some embodiments of the present disclosure. Figure 6C , which depicts hybrid SUPI de-hiding. Here, a hybrid combination of multiple PQC algorithms can be used, rather than relying solely on a single post-quantum-safe cryptography algorithm (which may not be well-tested or secure). At step 1 of hybrid SUPI de-hiding at HN 103, HN 103 can use PQC-based Algorithm 2. Here, the PQC decryption process takes the ciphertext and the PQC-based HN 103 public key-2 as input and produces the resulting intermediate ciphertext as output. At step 2, UE 101 uses another PQC-based encryption algorithm 1. Here, PQC decryption takes the intermediate ciphertext and the PQC-based HN 103 public key-1 as input and produces plaintext SUPI. In summary, embodiments herein provide hybrid-based encryption for SUCI hiding using multiple post-quantum-safe cryptography algorithms by performing hiding and de-hiding in a sequential manner.

[0349] Figure 6D illustrates a sequence diagram for hybrid SUPI hiding and de-hiding using PQC and PQC-based shared key encryption and decryption, according to some embodiments of the present disclosure. As shown in Figure 6D , during SIM provisioning (step 1 (S1)), UE 101 may initially be provisioned with multiple first PQC-based HN 103 public keys and a second PQC-based HN 103 public key. Later, when UE 101 wishes to initiate SUPI hiding, UE 101 may encrypt the SUPI using the PQC-based HN 103 public key and generate an intermediate ciphertext (step 2 (S2)). At step 3 (S3), UE 101 may encrypt the intermediate ciphertext using the PQC-based HN 103 public key and generate a final ciphertext. The final ciphertext may be sent to HN 103 (step 4 (S4)). HN 103 may decrypt the ciphertext using the first PQC-based HN 103 public key and generate an intermediate ciphertext (step 5 (S5)). At step 6 (S6), the HN 103 may decrypt the intermediate ciphertext using the HN 103 public key based on the PQC and may generate the SUPI or plaintext.

[0350] Figure 7A Shown is a flow chart illustrating a method 700a for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key exchange according to some embodiments of the present disclosure.

[0351] like Figure 7A As shown, method 700a may include one or more steps. Method 700a may be described in the general context of computer-executable instructions. Generally, computer-executable instructions may include routines, programs, objects, components, data structures, procedures, modules, and functions that perform specific functions or implement specific abstract data types.

[0352] The order in which method 700a is described is not intended to be construed as limiting, and any number of the described method blocks can be combined in any order to implement the method. Additionally, individual blocks can be deleted from the method without departing from the scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or a combination thereof.

[0353] At block 702, method 700a includes generating a temporary public key and a temporary private key based on elliptic curve (EC) key generation technology. The operations of block 702 may be performed by Figure 2B is executed by the processor 205 (specifically, it can be executed by the generation unit 215).

[0354] At block 704, method 700a includes generating a first temporary shared key based on a temporary private key and an elliptic curve (EC) based home network public key. The operations of block 704 may be performed by Figure 2B is executed by the processor 205 (specifically, it can be executed by the generation unit 215).

[0355] At block 706, method 700a includes generating a second temporary shared key and an encrypted shared key based on a post-quantum cryptography (PQC) based public key associated with home network 103. The operations of block 706 may be performed by Figure 2B is executed by the processor 205 (specifically, it can be executed by the generation unit 215).

[0356] At block 708, method 700a includes generating a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key. The operations of block 708 may be performed by Figure 2B is executed by the processor 205 (specifically, it can be executed by the generation unit 215).

[0357] At block 710, method 700a includes generating a ciphertext value and a message authentication code (MAC) tag value based on at least a temporary mixed shared key. The operations of block 710 may be performed by Figure 2B is executed by the processor 205 (specifically, it can be executed by the generation unit 215).

[0358] At block 712, method 700a includes sending a registration request for registering UE 101 with the home network, along with the temporary public key, the encrypted shared key, the ciphertext value, and the MAC tag value. The operations of block 712 may be performed by Figure 2B The processor 205 executes the above operation (specifically, the sending unit 217 executes the above operation).

[0359] Figure 7B Shown is a flow chart illustrating a method 700b for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key exchange according to some embodiments of the present disclosure.

[0360] like Figure 7B As shown, method 700b may include one or more steps. Method 700b may be described in the general context of computer-executable instructions. Generally, computer-executable instructions may include routines, programs, objects, components, data structures, procedures, modules, and functions that perform specific functions or implement specific abstract data types.

[0361] The order in which method 700b is described is not intended to be construed as limiting, and any number of the described method blocks may be combined in any order to implement the method. Additionally, individual blocks may be deleted from the method without departing from the scope of the subject matter described herein. Furthermore, the method may be implemented in any suitable hardware, software, firmware, or a combination thereof.

[0362] At block 714, method 700b includes receiving a registration request from UE 101, wherein the registration request includes a temporary public key, an encrypted shared key, a ciphertext value, and a message authentication code (MAC) tag value. The operations of block 714 may be performed by Figure 2C The processor 211 executes the above operation (specifically, the receiving unit 219 executes the above operation).

[0363] At block 716, method 700b includes generating a first temporary shared key based on at least the temporary public key and an Elliptic Curve Cryptography (ECC)-based public key associated with home network 103. The operations of block 716 may be performed by Figure 2C is executed by the processor 211 (specifically, it can be executed by the generation unit 221).

[0364] At block 718, method 700b includes generating a second temporary shared key based on the encrypted shared key and a post-quantum cryptography (PQC) based private key associated with home network 103. The operations of block 718 may be performed by Figure 2C is executed by the processor 211 (specifically, it can be executed by the generation unit 221).

[0365] At block 720, method 700b includes generating a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key. The operations of block 710 may be performed by Figure 2C is executed by the processor 211 (specifically, it can be executed by the generation unit 221).

[0366] At block 722, method 700b includes generating a temporary decryption key and a temporary MAC key based on at least the temporary hybrid shared key. The operations of block 722 may be performed by Figure 2C is executed by the processor 211 (specifically, it can be executed by the generation unit 221).

[0367] At block 724, method 700b includes generating plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key. The operations of block 724 may be performed by Figure 2C is executed by the processor 211 (specifically, it can be executed by the generation unit 221).

[0368] At block 726, method 700b includes registering UE 101 with the home network based on the generated plaintext. The operations of block 726 may be performed by Figure 2C The processor 211 executes the above operation (specifically, the registration unit 221 executes the above operation).

[0369] Figure 7C Shown is a flow chart illustrating a method 700c for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key exchange according to some embodiments of the present disclosure.

[0370] like Figure 7C As shown, method 700c may include one or more steps. Method 700c may be described in the general context of computer-executable instructions. Generally, computer-executable instructions may include routines, programs, objects, components, data structures, procedures, modules, and functions that perform specific functions or implement specific abstract data types.

[0371] The order in which method 700c is described is not intended to be construed as limiting, and any number of the described method blocks can be combined in any order to implement the method. Additionally, individual blocks can be deleted from the method without departing from the scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or a combination thereof.

[0372] At block 728, method 700c includes generating a first temporary shared key and a first encrypted shared key based on a home network public key based on a first post-quantum cryptography (PQC). The operations of block 728 may be performed by Figure 2B is executed by the processor 205 (specifically, it can be executed by the generation unit 215).

[0373] At block 730, method 700c includes generating a second temporary shared key and a second encrypted shared key based on the home network public key based on the second PQC. The operations of block 730 may be performed by Figure 2B is executed by the processor 205 (specifically, it can be executed by the generation unit 215).

[0374] At block 732, method 700c includes generating a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key. The operations of block 734 may be performed by Figure 2B is executed by the processor 205 (specifically, it can be executed by the generation unit 215).

[0375] At block 734, method 700c includes generating a ciphertext value and a message authentication code (MAC) tag value based on at least the temporary mixed shared key. The operations of block 736 may be performed by Figure 2B is executed by the processor 205 (specifically, it can be executed by the generation unit 215).

[0376] At block 736, method 700c includes sending a registration request for registering UE 101 with the home network, along with the first encryption shared key, the second encryption shared key, the ciphertext value, and the MAC tag value. The operations of block 736 may be performed by Figure 2B The processor 205 executes the above operation (specifically, the sending unit 217 executes the above operation).

[0377] Figure 7D Shown is a flow chart illustrating a method 700d for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key exchange according to some embodiments of the present disclosure.

[0378] like Figure 7D As shown, method 700d may include one or more steps. Method 700d may be described in the general context of computer-executable instructions. Generally, computer-executable instructions may include routines, programs, objects, components, data structures, procedures, modules, and functions that perform specific functions or implement specific abstract data types.

[0379] The order in which method 700d is described is not intended to be construed as limiting, and any number of the described method blocks can be combined in any order to implement the method. Additionally, individual blocks can be deleted from the method without departing from the scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or a combination thereof.

[0380] At block 738, method 700d includes receiving a registration request from the UE, wherein the registration request includes a temporary public key, an encrypted shared key, a ciphertext value, and a message authentication code (MAC) tag value. The operations of block 738 may be performed by Figure 2C The processor 211 executes the above operation (specifically, the receiving unit 219 executes the above operation).

[0381] At block 740, method 700d includes generating a first temporary shared key based on the first encryption shared key and a first post-quantum cryptography (PQC) based private key associated with home network 103. The operations of block 740 may be performed by Figure 2C is executed by the processor 211 (specifically, it can be executed by the generation unit 221).

[0382] At block 742, method 700d includes generating a second temporary shared key based on the second encryption shared key and a second PQC-based private key associated with home network 103. The operations of block 742 may be performed by Figure 2C is executed by the processor 211 (specifically, it can be executed by the generation unit 221).

[0383] At block 744, method 700d includes generating a temporary hybrid shared key based on the first encrypted shared key and the second encrypted shared key. The operations of block 744 may be performed by Figure 2C is executed by the processor 211 (specifically, it can be executed by the generation unit 221).

[0384] At block 746, method 700d includes generating a temporary decryption key and a temporary MAC key based on at least the temporary hybrid shared key. The operations of block 746 may be performed by Figure 2C is executed by the processor 211 (specifically, it can be executed by the generation unit 221).

[0385] At block 748, method 700d includes generating plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key. The operations of block 748 may be performed by Figure 2C is executed by the processor 211 (specifically, it can be executed by the generation unit 221).

[0386] At block 750, method 700d includes registering UE 101 with home network 103 based on the generated plaintext. The operations of block 750 may be performed by Figure 2C The processor 211 executes the above operation (specifically, the registration unit 223 executes the above operation).

[0387] Figure 8A Shown is a flow chart illustrating a method 800a for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure.

[0388] At block 802, method 800a includes generating a temporary public key and a temporary private key based at least on an elliptic curve (EC) key generation technique. The operations of block 802 may be performed by Figure 2B The processor 205 (specifically, the generating unit 215) executes the above.

[0389] At block 804, method 800a includes generating a temporary shared key based on the temporary private key and the EC-based home network public key. The operations of block 804 may be performed by Figure 2B The processor 205 (specifically, the generating unit 215) executes the above.

[0390] At block 806, method 800a includes generating a temporary encryption key and a temporary message authentication code (MAC) key based on at least the temporary hybrid shared key. The operations of block 806 may be performed by Figure 2B The processor 205 (specifically, the generating unit 215) executes the above.

[0391] At block 808, method 800a includes generating an intermediate ciphertext value by performing symmetric encryption of the plaintext based on the temporary encryption key. The operations of block 808 may be performed by Figure 2B The processor 205 (specifically, the generating unit 215) executes the above.

[0392] At block 810, method 800a includes generating a ciphertext value based on an intermediate ciphertext value and a home network public key based on post-quantum cryptography (PQC). The operations of block 810 may be performed by Figure 2B The processor 205 (specifically, the generating unit 215) executes the above.

[0393] At block 812, method 800a includes generating a MAC tag value based on at least the ciphertext value and the temporary MAC tag key. The operations of block 812 may be performed by Figure 2B The processor 205 (specifically, the generating unit 215) executes the above.

[0394] At block 814, method 800a includes sending a registration request to register UE 101 with home network 103, along with the temporary public key, ciphertext value, and MAC tag value. The operations of block 814 may be performed by Figure 2B The processor 205 (specifically, the sending unit 217) executes the above.

[0395] Figure 8B Shown is a flow chart illustrating a method 800b for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure.

[0396] At block 816, method 800b includes receiving a registration request from the UE, wherein the registration request includes a temporary public key, a ciphertext value, and a message authentication code (MAC) tag value. The operations of block 816 may be performed by Figure 2C The processor 211 (specifically, the receiving unit 219) executes the above.

[0397] At block 818, method 800b includes generating a temporary shared key based on the temporary public key and an elliptic curve (EC) based private key associated with home network 103. The operations of block 818 may be performed by Figure 2C The processor 211 (specifically, the generating unit 221) executes the above.

[0398] At block 820, method 800b includes generating a temporary decryption key and a temporary message authentication code (MAC) key based on at least the temporary shared key. The operations of block 820 may be performed by Figure 2C The processor 211 (specifically, the generating unit 221) executes the above.

[0399] At block 822, method 800a includes generating an intermediate ciphertext value by applying post-quantum cryptography (PQC) decryption to the ciphertext value based on the PQC-based home network public key. The operations of block 822 may be performed by Figure 2C The processor 211 (specifically, the generating unit 221) executes the above.

[0400] At block 824, method 800b includes generating plaintext by performing symmetric decryption of the intermediate ciphertext value based on at least the temporary decryption key. The operations of block 824 may be performed by Figure 2C The processor 211 (specifically, the generating unit 221) executes the above.

[0401] At block 826, method 800b includes registering UE 101 with the home network based on the generated plaintext. The operations of block 826 may be performed by Figure 2C The processor 205 (specifically, the registration unit 223) executes the above operation.

[0402] Figure 8C Shown is a flow chart illustrating a method 800c for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure.

[0403] At block 828, method 800c includes splitting the plaintext into a first portion and a second portion. The operations of block 828 may be performed by Figure 2D The processor 205 (specifically, the splitting unit 225) executes.

[0404] At block 830, method 800c includes generating a first ciphertext value based on a first post-quantum cryptography (PQC) based public key associated with home network 103. The operations of block 830 may be performed by Figure 2D The processor 205 (specifically, the generating unit 227) executes the above.

[0405] At block 832, method 800c includes generating a second ciphertext value based on a second PQC-based public key associated with home network 103. The operations of block 832 may be performed by Figure 2D The processor 205 (specifically, the generating unit 227) executes the above.

[0406] At block 834, method 800c includes sending a registration request to register UE 101 with home network 103, along with the first ciphertext value and the second ciphertext value. The operations of block 834 may be performed by Figure 2D The processor 205 (specifically, the sending unit 229) executes the above.

[0407] Figure 8D Shown is a flow chart illustrating a method 800d for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure.

[0408] At block 836, method 800d includes receiving a registration request from UE 101, wherein the registration request includes the first ciphertext value and the second ciphertext value. The operations of block 836 may be performed by Figure 2E The processor 211 (specifically, the receiving unit 231) executes the above.

[0409] At block 838, method 800d includes generating a first portion of plaintext by decrypting a first ciphertext value based on a first post-quantum cryptography (PQC) private key associated with home network 103. The operations of block 838 may be performed by Figure 2E The processor 211 (specifically, the generating unit 233) executes the above.

[0410] At block 840, method 800d includes generating a second portion of plaintext by decrypting the second ciphertext value based on a second PQC private key associated with home network 103. The operations of block 840 may be performed by Figure 2E The processor 211 (specifically, the generating unit 233) executes the above.

[0411] At block 842, method 800d includes generating plaintext by combining the first portion and the second portion of the plaintext. The operations of block 842 may be performed by Figure 2E The processor 211 (specifically, the generating unit 233) executes the above.

[0412] At block 844, method 800d includes registering UE 101 with home network 103 based on the generated plaintext. The operations of block 844 may be performed by Figure 2E The processor 211 (specifically, the registration unit 235) executes the above.

[0413] Figure 8E Shown is a flow chart illustrating a method 800e for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure.

[0414] At block 846, method 800e includes generating an intermediate ciphertext value based on the home network public key and the plaintext based on the first post-quantum cryptography (PQC). The operation of block 846 may be performed by Figure 2B The processor 205 (specifically, the generating unit 215) executes the above.

[0415] At block 848, method 800e includes generating a ciphertext value based on the intermediate ciphertext value and the home network public key based on the second PQC. The operations of block 848 may be performed by Figure 2B The processor 205 (specifically, the generating unit 215) executes the above.

[0416] At block 850, method 800e includes sending a registration request along with the cryptographic value to HN 103 for registering UE 101 with home network 103. The operations of block 850 may be performed by Figure 2B The processor 205 (specifically, the sending unit 217) executes the above.

[0417] Figure 8F Shown is a flow chart illustrating a method 800f for registering a user equipment (UE) 101 with a home network (HN) 103 using hybrid key encryption according to some embodiments of the present disclosure.

[0418] At block 852, method 800f includes receiving a registration request, wherein the registration request includes a ciphertext value. The operations of block 852 may be performed by Figure 2E The processor 211 (specifically, the receiving unit 231) executes the above.

[0419] At block 854, method 800f includes generating an intermediate ciphertext value based on the ciphertext value and the home network private key based on the second PQC. The operations of block 854 may be performed by Figure 2E The processor 211 (specifically, the generating unit 233) executes the above.

[0420] At block 856, method 800f includes generating plaintext based on the intermediate ciphertext value and the home network private key based on the first PQC. The operations of block 856 may be performed by Figure 2E The processor 211 (specifically, the generating unit 233) executes the above.

[0421] At block 858, method 800f includes registering UE 101 with home network 103 based on the generated plaintext. The operations of block 858 may be performed by Figure 2E The processor 211 (specifically, the registration unit 235) executes.

[0422] Advantages of the present disclosure

[0423] In an embodiment, the present disclosure provides shared key generation that combines with traditional ECC and PQC algorithms to derive a shared key. This key performs SUPI concealment for primary authentication between the UE and the HN. Furthermore, the present disclosure provides a hybrid encryption method that allows for minimal modifications to current 3GPP specifications to support hybrid security. Thus, the present disclosure prevents "store now, decrypt later" attacks.

[0424] In an embodiment, the present disclosure generates a hybrid shared key that can be used to hide SUPI. This shared key provides security against quantum threats and has a high security guarantee. This hybrid shared key can also be used to encrypt data between the UE and the network, and is not limited to SUPI.

[0425] Unless expressly stated otherwise, the terms "include," "comprising," "having," and variations thereof mean "including but not limited to." An enumerated listing of items does not imply that any or all of the items are mutually exclusive, unless expressly stated otherwise. The terms "a," "an," and "the" mean "one or more," unless expressly stated otherwise.

[0426] In alternative embodiments, certain operations may be performed, modified, or removed in a different order. Furthermore, steps may be added to the above logic and still conform to the described embodiments. Furthermore, the operations described herein may occur sequentially, or certain operations may be processed in parallel. Furthermore, operations may be performed by a single processing unit or by distributed processing units.

[0427] Finally, the language used in the specification is primarily selected for readability and instructional purposes and may not be selected to describe or limit the subject matter of the present invention. Accordingly, it is intended that the scope of the present invention be limited not by this detailed description, but rather by any claims that issue based on the application herein. Accordingly, the disclosure of the embodiments of the present invention is intended to illustrate, not to limit, the scope of the invention, which is set forth in the appended claims.

[0428]

Claims

1. A method (700a) performed by a user equipment (UE) for registering the UE with a home network (HN) (103) using hybrid key exchange, the method (700a) comprising: Generate (702) a temporary public key and a temporary private key based on elliptic curve (EC) key generation technology; generating (704) a first temporary shared key based on the temporary private key and an elliptic curve (EC) based home network public key; generating (706) a second temporary shared key and an encrypted shared key based on post-quantum cryptography (PQC) based on a public key associated with the home network; generating (708) a temporary mixed shared key based on the first temporary shared key and the second temporary shared key; generating (710) a ciphertext value and a message authentication code (MAC) tag value based on at least the temporary mixed shared key; as well as A registration request is sent (712) for registering the UE (101) with the home network (103), along with the temporary public key, the encrypted shared key, the ciphertext value, and the MAC tag value.

2. The method according to claim 1, wherein: Generating the first temporary shared key includes generating the first temporary shared key by applying elliptic curve cryptography (ECC) technology to the temporary private key and the EC-based home network public key, and Generating the second temporary shared key and the encrypted shared key includes generating the second temporary shared key and the encrypted shared key by applying a PQC Key Encapsulation Mechanism (KEM) technique to a PQC-based public key associated with the home network (103).

3. The method according to claim 1, wherein Generating a ciphertext value and a MAC tag value based on at least the temporary mixed shared key includes: generating a temporary encryption key and a temporary MAC key based on at least the temporary mixed shared key; generating a ciphertext value by performing symmetric encryption of the plaintext based on the temporary encryption key; and The MAC tag value is generated by applying a MAC function to the temporary MAC key and the ciphertext value.

4. The method according to claim 1, further comprising: Data to be sent from the UE (101) to the HN (103) is encrypted using the generated temporary hybrid shared key.

5. The method according to claim 1, further comprising: A security profile is created in the UE (101) and the HN (103), wherein the security profile is created by: creating a PQC-based profile using one or more PQC parameters for encryption, decryption, encapsulation, and decapsulation of identities and data sent from the UE (101) to the HN (103); and A hybrid profile is created using one or more hybrid parameters for encryption, decryption, encapsulation, and decapsulation of identities and data sent from the UE (101) to the HN (103).

6. The method according to claim 5, further comprising: Before sending data from the UE (101) to the HN (103), a primary authentication is performed at the UE (101) using the one or more PQC parameters and the one or more hybrid parameters.

7. A method for registering a user equipment (UE) (101) performed by a home network (HN) (103), the method comprising: receiving a registration request from the UE, wherein the registration request includes a temporary public key, an encrypted shared key, a ciphertext value, and a message authentication code (MAC) tag value; generating a first temporary shared key based on at least the temporary public key and an Elliptic Curve Cryptography (ECC) based public key associated with the home network (103); generating a second temporary shared key based on the encrypted shared key and a post-quantum cryptography (PQC) based private key associated with the home network (103); generating a temporary hybrid shared key based on the first temporary shared key and the second temporary shared key; generating a temporary decryption key and a temporary MAC key based on at least the temporary mixed shared key; generating plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key; and The UE (101) is registered with the home network (103) based on the generated plaintext.

8. The method according to claim 7, in, Generating the first temporary shared key includes generating the first temporary shared key by applying elliptic curve cryptography (ECC) techniques to the temporary public key and the ECC-based home network public key, and The generating of the second temporary shared key comprises generating the second temporary shared key by applying a PQC key decapsulation mechanism (KDM) technique to the encrypted shared key and a PQC-based public key associated with the home network (103).

9. A user equipment (UE) for registering the UE with a home network (HN) (103) using hybrid key exchange, the UE comprising: transceiver; and The controller is configured as: Generate temporary public key and temporary private key based on elliptic curve (EC) key generation technology, Generate a first temporary shared key based on the temporary private key and the home network public key based on the elliptic curve (EC), generating a second temporary shared key and an encrypted shared key based on post-quantum cryptography (PQC) based on a public key associated with the home network, generating a temporary mixed shared key based on the first temporary shared key and the second temporary shared key, generating a ciphertext value and a message authentication code (MAC) tag value based on at least the ephemeral mixed shared key, and A registration request is sent for registering the UE (101) with a home network (103), along with a temporary public key, an encrypted shared key, a ciphertext value, and a MAC tag value.

10. The UE according to claim 9, wherein: The controller is also configured to: generating a first temporary shared key by applying elliptic curve cryptography (ECC) techniques to the temporary private key and the EC-based home network public key, and The second temporary shared key and the encrypted shared key are generated by applying a PQC Key Encapsulation Mechanism (KEM) technique to a PQC-based public key associated with the home network (103).

11. The UE according to claim 9, wherein: The controller is also configured to: generating a temporary encryption key and a temporary MAC key based on at least the temporary mixed shared key, Generate a ciphertext value by performing symmetric encryption of the plaintext based on the temporary encryption key. Generate a MAC tag value by applying a MAC function to the temporary MAC key and the ciphertext value, and Data to be sent from the UE (101) to the HN (103) is encrypted using the generated temporary hybrid shared key.

12. The UE according to claim 9, wherein: The controller is also configured to: A security profile is created in a UE (101) and a HN (103), wherein the security profile is created by: creating a PQC-based profile using one or more PQC parameters for encryption, decryption, encapsulation, and decapsulation of an identity and data sent from the UE (101) to the HN (103), and creating a hybrid profile using one or more hybrid parameters for encryption, decryption, encapsulation, and decapsulation of an identity and data sent from the UE (101) to the HN (103).

13. The UE according to claim 9, wherein: The controller is also configured to: Before sending data from the UE (101) to the HN (103), a primary authentication is performed at the UE (101) using the one or more PQC parameters and the one or more hybrid parameters.

14. A home network (HN) (103) for registering a user equipment (UE) (101), the home network comprising: transceiver; and The controller is configured as: Receive a registration request from the UE, where the registration request includes a temporary public key, an encrypted shared key, a ciphertext value, and a message authentication code (MAC) tag value, generating a first temporary shared key based on at least the temporary public key and an Elliptic Curve Cryptography (ECC) based public key associated with the home network (103), generating a second temporary shared key based on the encrypted shared key and a post-quantum cryptography (PQC) based private key associated with the home network (103), generating a temporary mixed shared key based on the first temporary shared key and the second temporary shared key, generating a temporary decryption key and a temporary MAC key based on at least the temporary mixed shared key, generating plaintext by performing symmetric decryption of the ciphertext value based on at least the temporary decryption key, and The UE (101) is registered with the home network (103) based on the generated plaintext.

15. The home network according to claim 14, wherein: The controller is also configured to: generating a first temporary shared key by applying elliptic curve cryptography (ECC) techniques to the temporary public key and the ECC-based home network public key, and A second temporary shared key is generated by applying a PQC Key Decapsulation Mechanism (KDM) technique to the encrypted shared key and a PQC-based public key associated with the home network (103).