Certificate authentication for transport layer security

By introducing the PQC certificate exchange mechanism during the TLS handshake process, the management challenges of traditional certificates and PQC certificate exchange in 5G/6G scenarios of the TLS protocol are solved, improving the security and reliability of TLS connections and ensuring the protection of data transmission.

CN122437665APending Publication Date: 2026-07-21NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2026-01-19
Publication Date
2026-07-21

Smart Images

  • Figure CN122437665A_ABST
    Figure CN122437665A_ABST
Patent Text Reader

Abstract

Example embodiments of the present disclosure relate to certificate authentication for transport layer security (TLS). In one method, a first device receives information of a capability of a second device. The capability indicates that the second device supports exchange of a first certificate, the first certificate being related to a second certificate. The first device performs a procedure for establishing a transport layer security (TLS) connection based on the second certificate. The first device performs exchange of the first certificate with the second device. In this way, certificate authentication for TLS can be implemented. Security of a connection between a consumer and a producer of the TLS connection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The various example embodiments disclosed herein relate generally to the telecommunications field, and more specifically to methods, apparatuses, devices, and computer-readable storage media for certificate authentication for Transport Layer Security (TLS). Background Technology

[0002] With the development of internet technology, data security has become increasingly important. As more sensitive information is shared and stored online, ensuring data protection from unauthorized access and tampering is crucial. The growing reliance on digital platforms used for communication, business, and services makes data protection a top priority for maintaining privacy, trust, and compliance.

[0003] Network encryption protocols are technologies used to protect data transmitted over a network. These protocols ensure that information remains confidential, intact, and authentic during transmission, preventing unauthorized access, tampering, or eavesdropping. These protocols are crucial for protecting communications on the internet, especially when sensitive data such as passwords, personal information, and financial transactions are involved. Summary of the Invention

[0004] In a first aspect of this disclosure, a first apparatus is provided. The first apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus to: receive information about the capabilities of a second apparatus, wherein the capabilities indicate that the second apparatus supports the exchange of a first certificate, the first certificate being associated with a second certificate; and perform a process for establishing a Transport Layer Security (TLS) connection based on the second certificate; and perform the exchange of the first certificate with the second apparatus.

[0005] In a second aspect of this disclosure, a second apparatus is provided. The second apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus to: send information about the capabilities of the second apparatus, wherein the capabilities indicate that the second apparatus supports the exchange of a first certificate, the first certificate being associated with a second certificate; and perform a process for establishing a Transport Layer Security (TLS) connection based on the second certificate; and perform the exchange of the first certificate with a first apparatus.

[0006] In a third aspect of this disclosure, a third apparatus is provided. The third apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the third apparatus to: receive an identifier of a second apparatus from a first apparatus; and send to the first apparatus an Internet Protocol (IP) address and information about the capabilities of the second apparatus, wherein the capabilities indicate that the second apparatus supports the exchange of a first certificate, the first certificate being associated with the second certificate.

[0007] In a fourth aspect of this disclosure, a fourth apparatus is provided. The fourth apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the fourth apparatus to: receive a discovery request for a second apparatus from a first apparatus; and send a response to the discovery request to the first apparatus, the response including protocol subset information of the second apparatus and information about the capabilities of the second apparatus, wherein the capabilities indicate that the second apparatus supports the exchange of a first certificate, the first certificate being associated with the second certificate.

[0008] In a fifth aspect of this disclosure, a method is provided. The method includes: receiving information about the capabilities of a second device, wherein the capabilities indicate that the second device supports the exchange of a first certificate, the first certificate being associated with a second certificate; performing a connection establishment procedure for Transport Layer Security (TLS) based on the second certificate; and performing the exchange of the first certificate with the second device.

[0009] In a sixth aspect of this disclosure, a method is provided. The method includes: transmitting information about the capabilities of a second device, wherein the capabilities indicate that the second device supports the exchange of a first certificate, the first certificate being associated with a second certificate; performing a process for establishing a Transport Layer Security (TLS) connection based on the second certificate; and performing the exchange of the first certificate with the first device.

[0010] In a seventh aspect of this disclosure, a method is provided. The method includes: receiving an identifier of a second device from a first device; and sending an Internet Protocol (IP) address and information about the capabilities of the second device to the first device, wherein the capabilities indicate that the second device supports the exchange of a first certificate, which is associated with the second certificate.

[0011] In an eighth aspect of this disclosure, a method is provided. The method includes: receiving a discovery request for a second device from a first device; and sending a response to the discovery request to the first device, the response including protocol subset information of the second device and information on the capabilities of the second device, wherein the capabilities indicate that the second device supports the exchange of a first certificate, the first certificate being associated with the second certificate.

[0012] In a ninth aspect of this disclosure, a first apparatus is provided. The first apparatus includes: a unit for receiving information about the capabilities of a second apparatus, wherein the capabilities indicate that the second apparatus supports the exchange of a first certificate, the first certificate being associated with a second certificate; a unit for performing a process for establishing a Transport Layer Security (TLS) connection based on the second certificate; and a unit for performing the exchange of the first certificate with the second apparatus.

[0013] In a tenth aspect of this disclosure, a second apparatus is provided. The second apparatus includes: a unit for transmitting information about the capabilities of the second apparatus, wherein the capabilities indicate that the second apparatus supports the exchange of a first certificate, the first certificate being associated with a second certificate; a unit for performing a process for establishing a Transport Layer Security (TLS) connection based on the second certificate; and a unit for performing the exchange of the first certificate with the first apparatus.

[0014] In the eleventh aspect of this disclosure, a third apparatus is provided. The third apparatus includes: a unit for receiving an identifier of a second apparatus from a first apparatus; and a unit for sending an Internet Protocol (IP) address and information about the capabilities of the second apparatus to the first apparatus, wherein the capabilities indicate that the second apparatus supports the exchange of a first certificate, the first certificate being associated with the second certificate.

[0015] In a twelfth aspect of this disclosure, a fourth apparatus is provided. The fourth apparatus includes: a unit for receiving a discovery request for a second apparatus from a first apparatus; and a unit for sending a response to the discovery request to the first apparatus, the response including protocol subset information of the second apparatus and information on the capabilities of the second apparatus, wherein the capabilities indicate that the second apparatus supports the exchange of a first certificate, the first certificate being associated with the second certificate.

[0016] In a thirteenth aspect of this disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon for causing a device to at least execute the method according to the fifth aspect.

[0017] In a fourteenth aspect of this disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon for causing a device to at least execute the method according to a sixth aspect.

[0018] In a fifteenth aspect of this disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon for causing a device to at least execute the method according to a seventh aspect.

[0019] In a sixteenth aspect of this disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon for causing a device to at least perform the method according to an eighth aspect.

[0020] It should be understood that the summary portion is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0021] Some example implementation schemes will now be described with reference to the accompanying drawings, in which: Figure 1An example communication environment in which an example implementation of this disclosure may be carried out is shown; Figure 2A The signaling flow for certificate authentication for TLS according to some embodiments of this disclosure is shown; Figure 2B The signaling flow for certificate authentication for TLS according to some embodiments of this disclosure is shown; Figure 2C The signaling flow for certificate authentication for TLS according to some embodiments of this disclosure is shown; Figure 3 Example signaling flows for certificate authentication for TLS according to some embodiments of this disclosure are shown; Figure 4 Example signaling flows for certificate authentication for TLS according to some embodiments of this disclosure are shown; Figure 5 Example signaling flows for certificate authentication for TLS according to some embodiments of this disclosure are shown; Figure 6 Example signaling flows for certificate authentication for TLS according to some embodiments of this disclosure are shown; Figure 7 A flowchart is shown showing a method implemented at a first device according to some example embodiments of the present disclosure; Figure 8 A flowchart is shown illustrating a method implemented at a second device according to some example embodiments of the present disclosure; Figure 9 A flowchart is shown of a method implemented at a third device according to some example embodiments of the present disclosure; Figure 10 A flowchart is shown of a method implemented at a fourth device according to some example embodiments of the present disclosure; Figure 11 A simplified block diagram of an apparatus suitable for implementing an example embodiment of this disclosure is shown; and Figure 12 A block diagram of an example computer-readable medium according to some example embodiments of the present disclosure is shown.

[0022] Throughout the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Detailed Implementation

[0023] The principles of this disclosure will now be described with reference to some example embodiments. It should be understood that these embodiments are described for illustrative purposes only and to assist those skilled in the art in understanding and implementing this disclosure, without imposing any limitation on the scope of this disclosure. The embodiments described herein can be implemented in various ways other than those described below.

[0024] In the following description and claims, unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0025] References to "an embodiment," "an embodiment," "an example embodiment," etc., in this disclosure indicate that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment needs to include that particular feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same embodiment. Additionally, when a particular feature, structure, or characteristic is described in connection with an embodiment, whether explicitly stated or not, it is assumed that its influence on such feature, structure, or characteristic in conjunction with other embodiments is within the knowledge of those skilled in the art.

[0026] It should be understood that although various elements may be described herein using prefixes such as “first,” “second,” etc., these elements should not be limited by these terms. These terms are used only to distinguish one element from another, and they do not restrict the order of the terms. For example, without departing from the scope of the example embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.

[0027] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements is connected by “and” or “or”, means at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.

[0028] As used herein, unless explicitly stated otherwise, the execution step “in response to A” does not indicate that the step is performed immediately after “A” occurs and may include one or more intermediate steps.

[0029] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments. As used herein, the singular forms “a,” “an,” and “the” are also intended to include the plural forms unless the context clearly indicates otherwise. It will be further understood that the terms “comprising,” “including,” “having,” “having,” “including,” and / or “containing” as used herein specify the presence of the stated features, elements, and / or components, etc., but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0030] As used in this application, the term "circuit system" may refer to one or more of the following: (a) Hardware circuit implementation only (such as implementation in analog and / or digital circuits only), and (b) A combination of hardware circuitry and software, such as (if applicable): (i) A combination of analog and / or digital hardware circuitry with software / firmware, and (ii) Any part of a hardware processor having software (including digital signal processor(s) working together to enable a device (such as a mobile phone or server) to perform various functions), software, and memory), and (c) One or more hardware circuits and / or one or more processors, such as one or more microprocessors or a portion thereof, that require software (e.g., firmware) to operate, but the software may not be present when operation is not required.

[0031] This limitation of "circuit" applies to all uses of the term in this application, including in any claim. As another example, as used in this application, the term "circuit" also covers implementations of hardware circuitry or processors (or processors) or a portion thereof and their accompanying software and / or firmware. For example, and if applicable to a particular claim element, the term "circuit" also covers baseband integrated circuits or processor integrated circuits for use in mobile devices or servers, cellular network devices or other computing or networking devices.

[0032] As used herein, the term "communication network" refers to a network that conforms to any suitable communication standard, such as New Radio (NR), Long Term Evolution (LTE), LTE-A Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed ​​Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), etc. Furthermore, communication between terminal devices and network devices in a communication network can be performed according to any suitable generated communication protocol, including but not limited to first-generation (1G), second-generation (2G), 2.5G, 2.75G, third-generation (3G), fourth-generation (4G), 4.5G, fifth-generation (5G), 5.5G, sixth-generation (6G) communication protocols and / or any other currently known or future-developed protocols. Embodiments of this disclosure can be applied to a variety of communication systems. Given the rapid development in communications, there will naturally be future types of communication technologies and systems that can implement this disclosure. The scope of this disclosure should not be limited to the aforementioned systems only.

[0033] As used herein, the term "network device" refers to a node in a communications network through which terminal devices access the network and receive services. Network devices can refer to base stations (BS) or access points (APs), such as Node B (NodeB or NB), evolved Node B (eNodeB or eNB), NR NB (also known as gNB), Remote Radio Unit (RRU), Radio Head (RH), Remote Radio Head (RRH), repeater, Integrated Access and Backhaul (IAB) node, low-power node (such as femtoseconds, picoseconds), non-terrestrial network (NTN) or non-terrestrial network equipment (such as satellite network equipment, low Earth orbit (LEO) satellites, and geostationary Earth orbit (GEO) satellites), spacecraft network equipment, etc., depending on the terminology and technology applied. In some example implementations, the Radio Access Network (RAN) split architecture includes a centralized unit (CU) and a distributed unit (DU) at the IAB donor node. An IAB node includes a mobile terminal (IAB-MT) portion that behaves like a UE toward its parent node, and the DU portion of the IAB node behaves like a base station toward the next-hop IAB node.

[0034] The term "terminal device" refers to any terminal device capable of wireless communication. As an example and not a limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices can include, but are not limited to, mobile phones, cellular phones, smartphones, Voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), gaming terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEEs), laptop devices (LMEs), USB dongles, smart devices, wireless customer premises equipment (CPEs), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in the context of industrial and / or automated processing chains), consumer electronics devices, devices operating on commercial and / or industrial wireless networks, etc. The terminal device may also correspond to the mobile terminal (MT) portion of an IAB node (e.g., a relay node). In the following description, the terms "terminal device," "communication device," "terminal," "user equipment," and "UE" are used interchangeably.

[0035] As used herein, the terms “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” can refer to any resource used to perform communication, such as communication between a terminal device and a network device, including resources in the time domain, frequency domain, spatial domain, code domain, or any other combination of time, frequency, spatial, and / or code domain resources used to enable communication. In the following, unless explicitly stated otherwise, resources in both the frequency and time domains will be used as examples of transmission resources used to describe some exemplary embodiments of this disclosure. It should be noted that the exemplary embodiments of this disclosure are equally applicable to other resources in other domains.

[0036] Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS) are protocols designed to provide secure communication over a network. To authenticate one party (e.g., a client) in a TLS or DTLS connection, a connection to the other party (e.g., a server) is established using an authentication message created after the TLS session is established. This allows both the client and server to prove ownership of the attached identity at any time after the connection is authenticated.

[0037] The completion of the handshake between the client and server indicates that authentication can be derived from one party and sent to the other for verification. An endpoint can be reliable for multiple identities. An endpoint may not have a single certificate including all identities. An endpoint can authenticate additional identities over a single connection. Additionally, after a connection is established, an endpoint can authenticate in response to events in higher-level protocols. Endpoints can also integrate more context, such as context from the application.

[0038] In a TLS connection, the other party may want to authenticate each other using both their associated legacy certificates and PQC certificates. This is known as hybrid authentication; however, it is necessary to investigate whether the TLS counterpart supports the technology for exchanging the associated legacy and PQC certificates. Since many certificates are exchanged in 5G / 6G scenarios, measures may be needed where consumers and producers can perform PQC certificate exchange after legacy certificate exchange. Some use cases could be bidirectional TLS (mTLS) exchange between the following: consumer network function - producer network function (Security Control Plane / Security Edge Protection Proxy (SEPP)), SEPP-SEPP N32f connection, or SEPP-SEPP N32f connection.

[0039] The TLS protocol may not allow multiple certificates to be provided by the other party during the TLS handshake. A second certificate may be allowed to be exchanged by the application layer after the TLS handshake. This second certificate may not be exchanged by the TLS stack. In some example implementations, certificate exchange after the TLS handshake can be completed without affecting the TLS state machine. The ability to exchange a second certificate can be negotiated out-of-band (e.g., N32 exchange).

[0040] Figure 1 An example communication environment 100 is shown in which an example embodiment of the present disclosure may be implemented. Communication environment 100A relates to a plurality of communication devices, including a first device 110 and a second device 120 communicating with each other. Additionally, communication environment 100 may relate to a third device 130 capable of bidirectional communication with the first device 110. Furthermore, communication environment 100 may relate to a fourth device 140. The fourth device 140 may communicate with both the first device 110 and the second device 120.

[0041] In some example implementations, the first device 110 may be an implementation of one side of a security protocol for the network. In this case, the second device 120 may be an implementation of the other side of the security protocol for the network. Furthermore, for the purposes of discussion, the first device 110 may be referred to as a consumer of the certificate authentication process for TLS. Additionally, the second device 120 may be referred to as a producer of the certificate authentication process for TLS.

[0042] For example, the first device 110 can be implemented as a device operating as a Security Edge Protection Agent (SEPP). The second device 120 can be implemented as a device operating as another SEPP.

[0043] In some example implementations, the first device 110 may be implemented as a device that implements a network function (also referred to as a "consumer network function" or "NFc" for the purposes of discussion), and the second device 120 may be implemented as a device that implements another network function (also referred to as a "producer network function" or "NFp" for the purposes of discussion). In this case, the third device 130 may provide Domain Name System (DNS) services.

[0044] Alternatively, in some examples, the first device 110 may be implemented as NFc, the second device 120 may be implemented as NFp, and the fourth device 140 may be implemented as a device implementing Network Repository Function (NRF). For the purposes of discussion, a device implementing NRF may also be referred to as "NRF".

[0045] It should be understood that Figure 1The number of devices and their connections shown is for illustrative purposes only and does not impose any limitations. Communication environment 100 may include any suitable number of devices configured to implement the example embodiments of this disclosure. Although not shown, it should be understood that one or more additional devices may be located in communication environment 100.

[0046] In the following description, for illustrative purposes, some example implementations are depicted in which the first device 110 operates as a consumer of the TLS certificate authentication process, and the second device 120 operates as a producer of the TLS certificate authentication process. However, in some example implementations, the operations described for the consumer may be implemented at the second device 120 or other devices, and the operations described for the producer may be implemented at the first device 110 or other devices.

[0047] Communication in communication environment 100 can be implemented according to any suitable communication protocol, including but not limited to cellular communication protocols, wireless local area network communication protocols (such as IEEE 802.11), and / or any other currently known or future-developed protocols. Furthermore, communication can utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple Input Multiple Output (MIMO), Orthogonal Frequency Division Multiple Access (OFDM), Discrete Fourier Transform Extended OFDM (DFT-s-OFDM), and / or any other currently known or future-developed technologies.

[0048] According to some example implementations of this disclosure, a solution for certificate authentication for TLS is provided. In this solution, information about the capabilities of the producer in the certificate authentication process for TLS can be received by the consumer of the process. This capability indicates that the producer supports certificate exchange. The certificate is associated with another certificate. The process for establishing a TLS connection can be performed based on the other certificate. Additionally, certificate exchange is performed between the consumer and the producer.

[0049] The exemplary embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0050] refer to Figure 2A This illustrates a signaling flow 200A for certificate authentication for TLS according to some embodiments of this disclosure. Signaling flow 200A relates to... Figure 1 The first device 110 and the second device 120 are described. For discussion purposes, reference will be made to... Figure 1The signaling flow 200A is discussed. In some example implementations, the first device 110 may be implemented as a device operating as a SEPP (also referred to as "SEPP" for the purposes of discussion), and the second device 120 may be implemented as another SEPP. In some example implementations, the first device 110 and the second device 120 may be implemented as network devices implementing network functions. Additionally, the first device 110 may be an implementation of a consumer of a certificate authentication process for TLS, and the second device 120 may be an implementation of a producer of that process.

[0051] During operation, the second device 120 sends (2010) information about its capabilities to the first device 110. This capability indicates that the second device 120 supports certificate exchange (referred to as the "first certificate"). The first certificate is associated with another certificate (referred to as the "second certificate"). The first and second certificates can be used for authentication. For example, at least one of the first device 110 and the second device 120 can determine whether the first certificate and the second certificate are associated. If it is determined that the first certificate and the second certificate are associated, authentication can be determined to be successful, and the connection between the first device 110 and the second device 120 can be determined to be secure. If it is determined that the first certificate and the second certificate are not associated, authentication can be determined to be unsuccessful, and the connection between the first device 110 and the second device 120 can be determined to be insecure.

[0052] Accordingly, the first device 110 receives (2020) capability information of the second device 120 from the second device 120. In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate.

[0053] Specifically, the first device 110 can send a request to the second device regarding the capabilities of the second device. Correspondingly, the second device 120 can receive the request from the first device 110. The second device 120 can then send a response to the request to the first device 120. This response may include information about the capabilities of the second device. The first device 110 can then receive the response from the second device 120 accordingly.

[0054] Subsequently, the first device 110 performs (2030) the process for establishing a TLS connection based on the second certificate. The second device 120 performs (2040) the process for establishing a TLS connection based on the second certificate. The TLS connection can be established between the first device 110 and the second device 120.

[0055] Additionally, the first device 110 and the second device 120 perform (2050) the exchange of the first certificate. The second device 120 and the first device 110 perform (2060) the exchange of the first certificate.

[0056] Additionally, at least one of the processes for establishing a TLS connection based on the second certificate or for exchanging the first certificate can be triggered by the first device 110 or the second device 120.

[0057] In some example implementations, in order to exchange a first certificate between the first device 110 and the second device 120, the first device 110 may send a request for the first certificate of the second device 120 to the second device 120. Accordingly, the second device 120 may receive the request from the first device 110. Then, the second device 120 may send its first certificate to the first device 110, and the first device 110 may receive the first certificate of the second device 120 accordingly.

[0058] Additionally, the second device 120 can send a request for a first certificate for the first device 110 to the first device 110. Accordingly, the first device 110 can receive the request from the second device 120. Then, the first device 110 can send its first certificate to the second device 120, and the second device 120 can receive the first certificate from the first device 110 accordingly.

[0059] In some example implementations, the exchange of a second certificate between the first device 110 and the second device 120 can be performed. In this case, the first device 110 can send a request for a second certificate for the second device 120 to the second device 120. Accordingly, the second device 120 can receive the request from the first device 110. Then, the second device 120 can send its second certificate to the first device 110, and the first device 110 can receive the second certificate from the second device 120 accordingly.

[0060] Additionally, the second device 120 can send a request for a second certificate for the first device 110 to the first device 110. Accordingly, the first device 110 can receive the request from the second device 120. Then, the first device 110 can send its second certificate to the second device 120, and the second device 120 can receive the second certificate from the first device 110 accordingly.

[0061] It should be noted that the process initiated by the first device 110 mentioned herein is for illustrative purposes only and does not imply any limitation. The exemplary embodiments of this disclosure are not limited herein. In some exemplary embodiments, the process may be initiated by the second device 120.

[0062] In this way, information about the capabilities of the second device 120 can be directly sent to the first device 110. A TLS connection can be established between the first device 110 and the second device 120. Furthermore, authentication of the connection's security can be performed based on the exchange of a first certificate between the first device 110 and the second device 120. Therefore, TLS certificate authentication can be implemented, thereby improving the security of the connection between the first device 110 and the second device 120.

[0063] refer to Figure 2B This illustrates a signaling flow 200B for certificate authentication for TLS according to some embodiments of this disclosure. Signaling flow 200B relates to... Figure 1 The first device 110, the second device 120, and the third device 130 are described. For discussion purposes, reference will be made to... Figure 1 Discuss signaling flow 200B. In some example implementations, the first device 110 and the second device 120 can be implemented as network devices implementing network functions, and the third device can be associated with a DNS service. Additionally, the first device 110 can be an implementation of a consumer of a certificate authentication process for TLS (e.g., NFC), and the second device 120 can be an implementation of a producer of that process (e.g., NFp). The third device 130 can be an implementation of a third party (e.g., a device associated with a DNS service) of the certificate authentication process for TLS.

[0064] During operation, the third device 130 sends (2110) an Internet Protocol (IP) address and information about the capabilities of the second device 120 to the first device 110. This capability indicates that the second device 120 supports certificate exchange (referred to as the "first certificate"). Accordingly, the first device 110 receives (2120) the IP address and information from the third device 130. The first certificate is associated with another certificate (referred to as the "second certificate"). In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate. The first and second certificates can be used for authentication.

[0065] For example, at least one of the first device 110 and the second device 120 can determine whether the first certificate and the second certificate are related. If it is determined that the first certificate and the second certificate are related, authentication can be determined to be successful, and the connection between the first device 110 and the second device 120 can be determined to be secure. If it is determined that the first certificate and the second certificate are not related, authentication can be determined to be unsuccessful, and the connection between the first device 110 and the second device 120 can be determined to be insecure.

[0066] Subsequently, the first device 110 performs (2130) the process for establishing a TLS connection based on the second certificate. Specifically, the first device 110 may perform the process for establishing a TLS connection based on the second certificate and exchange a first certificate with the second device 120 based on the IP address. The second device 120 performs (2140) the process for establishing a TLS connection based on the second certificate. The TLS connection can exist between the first device 110 and the second device 120.

[0067] Additionally, the first device 110 and the second device 120 perform (2150) the exchange of the first certificate. The second device 120 and the first device 110 perform (2160) the exchange of the first certificate.

[0068] Additionally, at least one of the processes for establishing a TLS connection based on the second certificate or for exchanging the first certificate can be triggered by the first device 110 or the second device 120.

[0069] exist Figure 2B In the example, the exchange process of the first certificate and the second certificate between the first device 110 and the second device 120 is similar to that described above. Figure 2A The process discussed in the implementation plan will not be repeated here.

[0070] like Figure 2B As shown, before receiving the IP address and information from the second device 120, the first device 110 may send (2090) the identifier of the second device 120 to the third device 130. Accordingly, the third device 130 receives (2100) the identifier from the first device 110. The identifier may include the fully qualified domain name (FQDN) of the second device 120. In this case, the third device 130 may determine the IP address of the second device 120 based on its FQDN via a DNS service.

[0071] Additionally, as shown in the figure, before the third device 130 sends (2110) information about its IP address and the capabilities of the second device 120, the second device 120 may send (2070) information about its capabilities to the third device 130. Accordingly, the third device 130 may receive (2080) information from the second device 120.

[0072] It should be noted that the process initiated by the first device 110 mentioned herein is for illustrative purposes only and does not imply any limitation. The exemplary embodiments of this disclosure are not limited herein. In some exemplary embodiments, the process may be initiated by the second device 120.

[0073] In this way, the first device 110 can obtain information about the capabilities of the second device 120 by requesting the third device 130. A TLS connection can be established between the first device 110 and the second device 120. Furthermore, authentication of the connection's security can be performed based on the exchange of a first certificate between the first device 110 and the second device 120. Therefore, TLS certificate authentication can be implemented, thereby improving the security of the connection between the first device 110 and the second device 120.

[0074] refer to Figure 2C , Figure 2C Signaling flow 200C for certificate authentication for TLS is illustrated according to some embodiments of this disclosure. Signaling flow 200C involves Figure 1 The first device 110, the second device 120, and the fourth device 140 are described. For discussion purposes, reference will be made to... Figure 1 The signaling flow 200C is discussed. In some example implementations, the first device 110 and the second device 120 can be implemented as network devices implementing network functions, and the fourth device 140 can be implemented as a network device implementing an NRF (also referred to as "NRF" for the purposes of discussion). Additionally, the first device 110 can be an implementation of a consumer of a certificate authentication process for TLS (e.g., NFC), and the second device 120 can be an implementation of a producer of that process (e.g., NFp). The fourth device 140 can be an implementation of a third party (e.g., a device implementing an NRF) of the certificate authentication process for TLS.

[0075] In operation, the first device 110 may send (2170) a discovery request for the second device 120 to the fourth device 140. Accordingly, the fourth device 140 receives (2180) a discovery request from the first device 110. The discovery request may include an identifier of the second device 120. In some example embodiments, the first device 110 may send to the fourth device 140 information about a subset of its protocols and its capabilities. The capabilities of the first device 110 may indicate that it supports the exchange of a first certificate.

[0076] Subsequently, the fourth device 140 sends (2210) a response to the discovery request to the first device 110. This response includes information about a subset of the protocol of the second device 120 (also referred to as the “NF protocol subset” for the purposes of discussion) and information about the capabilities of the second device 120. This capability indicates that the second device 120 supports certificate exchange (referred to as the “first certificate”). Accordingly, the first device 110 receives (2220) a response from the fourth device 140. The first certificate is associated with another certificate (referred to as the “second certificate”). In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate. In some other example implementations, the second certificate may include a post-quantum computing (PQC) certificate.

[0077] The first certificate and the second certificate can be used for authentication. For example, at least one of the first device 110 and the second device 120 can determine whether the first certificate and the second certificate are related. If it is determined that the first certificate and the second certificate are related, authentication can be determined to be successful, and the connection between the first device 110 and the second device 120 can be determined to be secure. If it is determined that the first certificate and the second certificate are not related, authentication can be determined to be unsuccessful, and the connection between the first device 110 and the second device 120 can be determined to be insecure.

[0078] In some example implementations, the first device 110 may send a message to the second device 120 containing information about the capabilities of the first device 110. This capability may indicate that the first device 110 supports the exchange of a first certificate. In this case, the second certificate may include a post-quantum computing (PQC) certificate.

[0079] Subsequently, the first device 110 performs (2230) the process for establishing a TLS connection based on the second certificate. Specifically, the first device 110 may perform the process for establishing a TLS connection based on the second certificate, and exchange a first certificate with the second device 120 based on a subset of protocol information. The second device 120 performs (2240) the process for establishing a TLS connection based on the second certificate. The TLS connection can exist between the first device 110 and the second device 120.

[0080] Additionally, the first device 110 and the second device 120 perform (2250) the exchange of the first certificate. The second device 120 and the first device 110 perform (2260) the exchange of the first certificate.

[0081] Additionally, at least one of the processes for establishing a TLS connection based on the second certificate or for exchanging the first certificate can be triggered by the first device 110 or the second device 120.

[0082] exist Figure 2CIn the example, the exchange process of the first certificate and the second certificate between the first device 110 and the second device 120 is similar to that described in the reference above. Figure 2A The process of discussing the implementation plan will not be repeated here.

[0083] like Figure 2B As shown, before the fourth device 140 sends (2210) a response to the discovery request to the first device 110, the second device 120 may send (2190) protocol subset information and capability information of the second device 140 to the fourth device 140. For example, the second device 120 may register with the fourth device 140.

[0084] It should be noted that the process initiated by the first device 110 mentioned herein is for illustrative purposes only and does not imply any limitation. The exemplary embodiments of this disclosure are not limited herein. In some exemplary embodiments, the process may be initiated by the second device 120.

[0085] In this way, the first device 110 can obtain information about the capabilities of the second device 120 by requesting the fourth device 130. A TLS connection can be established between the first device 110 and the second device 120. Furthermore, authentication of the connection's security can be performed based on the exchange of a first certificate between the first device 110 and the second device 120. Therefore, TLS certificate authentication can be implemented, thereby improving the security of the connection between the first device 110 and the second device 120.

[0086] In some example implementations, consumers can directly request information about the producer's capabilities. (See reference) Figure 3 , Figure 3 Example signaling flow 300 for certificate authentication for TLS according to some embodiments of this disclosure is shown. Regarding Figure 3 The example implementations discussed can be considered as references. Figure 2A The implementation of the example implementation scheme discussed.

[0087] Signaling flow 300 relates to devices operating as SEPP (also referred to as "SEPP" for the purposes of discussion) 310 and SEPP 320. SEPP 310 may include a consumer (or client) of signaling flow 300 (also referred to as "SEPPc"), and SEPP 320 may include a producer (or server) of signaling flow 300 (also referred to as "SEPPp"). SEPP 310 may be... Figure 1 The first device 110 is implemented, and SEPP 320 can be Figure 1 The implementation of the second device 120.

[0088] Negotiation between SEPP 310 and SEPP 320 can be conducted via the N32-f interface. SEPPc 310 can learn via capability exchange messages that SEPPp supports legacy certificate exchange, and then learns of PQC certificate exchange. SEPPc can then exchange PQC certificates after legacy certificates. The other party must support this. Certificates and PQC certificates can be related. Otherwise, a guarantee that both certificates belong to the same entity is not required.

[0089] In some example implementations, there can be two TLS connections between SEPP 310 and SEPP 320. The first connection can be referred to as N32c (control message), and the second connection can be referred to as N32f (data connection). The N32c connection can be used for capability negotiation for the N32f connection. Once N32c is negotiated, N32f can be created, and data transmission can begin on N32f. SEPPc can learn about the relevant certificates and PQC certificate exchange supported by SEPPp on N32f via capability exchange messages communicated in N32c.

[0090] In some implementation examples, SEPPc may learn via capability exchange messages that SEPPp supports regular certificate exchange and subsequently PQC certificate exchange. SEPPc can then exchange the PQC certificate after the regular certificate. The regular certificate and the PQC certificate can be related. Alternatively, if the regular certificate and the PQC certificate are not related, authentication may fail, meaning the two certificates may belong to different entities.

[0091] like Figure 3 As shown, at 3010, a TLS connection for N32c can be established between SEPP 310 and SEPP 320. For example, the TLS connection can be established based on a DNS service or a protocol for network connectivity defined in the Request for Comments (RFC). Then, at 3020, via the TLS connection, SEPP 310 can initiate capability negotiation for the ability to exchange associated regular certificates and PQC certificates. Specifically, SEPP 310 can send a request for information about the capabilities of SEPP 320. This capability can instruct SEPP 320 to support the exchange of certificates (referred to as the "first certificate"). The first certificate can be associated with another certificate (referred to as the "second certificate"). The first certificate can be a PQC certificate, and the second certificate can be a regular certificate.

[0092] Subsequently, SEPP 320 can send a response to the request to SEPP 310. The response may include information about the capabilities of SEPP 320, such as an indication that NFp 420 supports the exchange of PQC certificates. The first and second certificates can be used for authentication in the following steps. The authentication process is similar to the reference above. Figure 2AThe process discussed in the implementation plan will not be repeated here.

[0093] At 3040, SEPP 310 and SEPP 320 can perform a procedure for establishing a TLS connection (e.g., an mTLS connection) between SEPP 310 and SEPP 320 based on a second certificate.

[0094] At 3050, SEPP 310 and SEPP 320 can perform the authentication process for the PQC certificate. For example, SEPP 310 and SEPP 320 can run the authentication process. Specifically, SEPP 310 and SEPP 320 can exchange first certificates (i.e., PQC certificates) with each other. For example, SEPPc can request SEPPp's PQC certificate (also known as the "PQC server certificate"). If SEPPp receives a request from SEPPc, SEPPp can also request SEPPc's PQC certificate (also known as the "PQC client certificate"). In some example implementations, the PQC server certificate can be sent by SEPPp to SEPPc, and similarly, SEPPc can also send the PQC client certificate to SEPPp.

[0095] Alternatively or additionally, at 3060, SEPP 320 (i.e., the server) can initiate the PQC certificate authentication process. For example, SEPPp can begin PQC certificate exchange.

[0096] It should be noted that the process initiated by SEPP 310 mentioned herein is for illustrative purposes only and does not imply any limitation. The exemplary embodiments of this disclosure are not limited herein. In some exemplary embodiments, the process may be initiated by SEPP 320.

[0097] In this way, SEPP 310 can directly request information about the capabilities of SEPP 320. Connections between SEPP 310 and SEPP 320 can be established and authenticated based on the exchange of PQC certificates. Therefore, TLS certificate authentication can be implemented, improving the security of the connection between SEPP 310 and SEPP 320.

[0098] In some example implementations, consumers can request information about the producer's capabilities via a third party (e.g., a device associated with the DNS service).

[0099] refer to Figure 4 This illustrates an example signaling flow 400 for certificate authentication for TLS according to some embodiments of this disclosure. Regarding... Figure 4 The example implementations discussed can be considered as references. Figure 2B The implementation of the example implementation scheme discussed.

[0100] Signaling flow 400 relates to devices operating as network functions (also referred to as "consumer network functions" or "NFc" for the purposes of discussion) 410, devices operating as network functions (also referred to as "producer network functions" or "NFp" for the purposes of discussion) 420, and devices related to DNS services (also referred to as "DNS" 430 for the purposes of discussion). NFc 410 may be... Figure 1 The implementation of the first device 110, NFp 420 can be Figure 1 The second device 120 is implemented, and DNS 430 can be Figure 1 The third device 130 is implemented. In some example implementations, NFc 410 can be implemented as SEPPPc (i.e., client), and NFp 420 can be implemented as SEPPPp (i.e., server).

[0101] The discovery process between SEPPc and SEPPp (or NFc and NFp) can be performed by DNS based on the FQDN of SEPPp. In this case, Dynamic DNS (DDNS) can be used to update DNS records that include the PQC certificate capability of the network function. The entity managing the network function can act as a DDNS client to trigger the update of the DNS record. In this case, the NFc (or SEPPc) can query the DNS and obtain the relevant PQC certificate indication and general certificate indication from the response.

[0102] Relevant PQC certificate indicators and regular certificate indicators can help SEPPPc or NFC recognize another SEPPPc capability. Exchange of regular and PQC certificates can be performed. If the server wants, it can discover the NFC capability that supports the exchange of regular and PQC certificates.

[0103] As shown in the diagram, at 4010, NFc 410 can query DNS 430 for information about NFp 420, for example, via a Service Record (SRV). For instance, NFc 410 can send the identifier of NFp 420 to DNS 430. This identifier can be implemented as an FQDN. Then, at 4020, DNS 430 can send a response to NFc 410. The response can include the IP address of NFp 420 and information about the capabilities of NFp 420, such as an indication that NFp 420 supports the exchange of PQC certificates. In some example implementations, NFp 420 can register with DNS 420. For example, NFp 420 can send information about its capabilities to DNS 430.

[0104] At 4030, NFc 410 and NFp 420 can establish an mTLS connection between themselves. Subsequently, at 4040, NFc 410 and NFp 420 can perform the PQC certificate authentication process. For example, NFc 410 and NFp 420 can run the authentication process. Specifically, NFc 410 and NFp 420 can exchange first certificates (i.e., PQC certificates) with each other. For example, NFc 410 can request NFp 420's PQC certificate (also known as the "PQC server certificate"). If NFp 420 receives a request from NFc 410, NFp 420 can also request NFc 410's PQC certificate (also known as the "PQC client certificate"). In some example implementations, the PQC server certificate can be sent by NFp 420 to NFc 410, and similarly, NFc 410 can also send the PQC client certificate to NFp 420.

[0105] Alternatively or additionally, at 4050, NFp 420 (i.e., the server) can initiate the PQC certificate authentication process. For example, NFp 420 can begin PQC certificate exchange.

[0106] It should be noted that the procedures initiated by NFc 410 mentioned herein are for illustrative purposes only and do not imply any limitation. The exemplary embodiments of this disclosure are not limited herein. In some exemplary embodiments, the procedures may be initiated by NFp 420.

[0107] In this way, NFc 410 can request information about the capabilities of NFp 420 via DNS 430. The connection between NFc 410 and NFp 420 can be established and authenticated based on the exchange of PQC certificates. Therefore, TLS certificate authentication can be implemented, improving the security of the connection between NFc 410 and NFp 420.

[0108] In some example implementations, consumers can request information about the producer's capabilities via a device that implements network functions (e.g., NRF).

[0109] refer to Figure 5 This illustrates an example signaling flow 500 for certificate authentication for TLS according to some embodiments of this disclosure. Regarding... Figure 5 The example implementations discussed can be considered as references. Figure 2C The implementation of the example implementation scheme discussed.

[0110] Signaling flow 500 relates to a device operating as a network function (also referred to as a "consumer network function" or "NFc" for the purposes of discussion) 510, a device operating as a network function (also referred to as a "producer network function" or "NFp" for the purposes of discussion) 520, and a device operating as an NRF (also referred to as "NRF") 530. NFc 510 may be... Figure 1 The implementation of the first device 110, NFp 520 can be Figure 1 The second device 120 is implemented, and the NRF 530 can be Figure 1 The third device 130 is implemented. In some example implementations, NFc 510 can be implemented as SEPPPc (i.e., client), and NFp 520 can be implemented as SEPPPp (i.e., server).

[0111] NFc 510 can register a subset of the NF protocol with NRF 530, along with instructions supporting the exchange of related conventional and PQC certificates. NFp 520 can also register a subset of the NF protocol with NRF 530, along with instructions supporting the exchange of related conventional and PQC certificates. NFc 510 can attempt to send a discovery request to NRF 530 containing NFp 520, and NRF 530 can respond with the subset of the NF protocol from NFp 520, along with instructions supporting both conventional and PQC certificate exchange.

[0112] NFc 510 can discover NFp 520 via NRF 530 and knows that NFp 520 supports the exchange of both regular certificates and PQC certificates. Regular certificates and PQC certificates are related to each other. NFc 510 can then exchange PQC certificates after regular certificates. In the case of mTLS, NFp 520 can also discover that NFc 510 supports both regular and PQC certificates.

[0113] For example, based on a PQC certificate request, NFp 520 can trigger a PQC certificate request for the client. Alternatively or additionally, based on a PQC certificate request, NFp 520 can check the capabilities of NFc 510 against NRF 530 and then trigger a PQC certificate request to NFc 510.

[0114] NFc 510 and NFp 520 can establish a traditional two-way TLS connection and exchange certificates. NFc 510 can request a PQC server certificate. If NFp 520 receives the request, it can request a PQC client certificate from NFc 510. In parallel, the PQC server certificate can be sent from NFp 520 to NFc 510, and similarly, NFc 510 can also send the PQC client certificate to NFp 520.

[0115] As shown in the figure, at point 5010, NFc 510 can send a registration message to NRF 530, such as the Nnrf_MNManagement_Register message. The Nnrf_MNManagement_Register message can include a subset of the NF protocol of NFc 510 and an indication that NFc 510 supports exchanging relevant general certificates and PQC certificates.

[0116] At point 5020, NFp 520 can send registration messages to NRF 530, such as the Nnrf_MNManagement_Register message. The Nnrf_MNManagement_Register message can include a subset of the NF protocol of NFp 520 and an indication that NFp 520 supports exchanging relevant general certificates and PQC certificates.

[0117] At 5030, NFc 510 can send a discovery request, such as an Nnrf_NFDiscovery_request message, to NRF 530. The Nnrf_NFDiscovery_request message may include information about NFp 520, such as the identifier of NFp 520. Subsequently, at 5040, NRF 530 can send a response to the Nnrf_NFDiscovery_request message to NFc 510. The response may include a subset of the NF protocol of NFp 520 and an indication that NFp 520 supports the exchange of relevant general certificates and PQC certificates. In some example implementations, the indication that NFp 520 supports the exchange of relevant general certificates and PQC certificates may be added as part of a Certificate-Based Certificate Authentication (CCA) token.

[0118] Then, at 5050, NFc 510 and NFp 520 can establish a procedure for establishing a TLS connection (e.g., an mTLS connection) between NFc 510 and NFp 520.

[0119] At 5060, NFc 510 can transmit the PQC certificate request for the server certificate of NFp 520 to NFp 520. At 5070, NFp 520 can send the PQC certificate request for the client certificate of NFc 510 to NFc 510.

[0120] Accordingly, NFp 520 can send a PQC certificate response to NC 510 requesting a PQC certificate for the server certificate. The response may include the PQC certificate of NFp 520. Additionally, NFc 210 can send a PQC certificate response to NFp 520 requesting a PQC certificate for the client certificate. The response may include the PQC certificate of NFc 510.

[0121] It should be noted that the procedures initiated by NFc 510 mentioned herein are for illustrative purposes only and do not imply any limitation. The exemplary embodiments of this disclosure are not limited herein. In some exemplary embodiments, the procedures may be initiated by NFp 520.

[0122] In this way, NFc 510 can request information about the capabilities of NFp 520 via NRF 530. The connection between NFc 510 and NFp 520 can be established and authenticated based on the exchange of PQC certificates. Therefore, TLS certificate authentication can be implemented, improving the security of the connection between NFc 510 and NFp 520.

[0123] refer to Figure 6 This illustrates an example signaling flow 600 for certificate authentication for TLS according to some embodiments of this disclosure. Regarding... Figure 6 The example implementations discussed can be considered as references. Figure 2C The implementation of the example implementation scheme discussed.

[0124] Signaling flow 600 relates to a device operating as a network function (also referred to as a "consumer network function" or "NFc" for the purposes of discussion) 610, a device operating as a network function (also referred to as a "producer network function" or "NFp" for the purposes of discussion) 620, and a device operating as an NRF (also referred to as "NRF") 630. NFc 610 may be... Figure 1 The implementation of the first device 110, NFp 620 can be Figure 1 The second device 120 is implemented, and the NRF 630 can be Figure 1 The third device 130 is implemented. In some example implementations, NFc 610 can be implemented as SEPPPc (i.e., client), and NFp 620 can be implemented as SEPPPp (i.e., server).

[0125] NFc 610 can send messages (e.g., client greetings) with indications supporting both PQC and regular certificates. Therefore, NFc 610 and NFp 620 can perform TLS handshakes utilizing both PQC and regular certificates. During this process, the PQC certificate may include indications linked to a regular certificate, which can trigger verification using the regular certificate.

[0126] NFc 610 can register a subset of its NF protocols and instructions supporting general certificate exchange and PQC certificate exchange with NRF 630. NFp 620 can also register a subset of its NF protocols and instructions supporting general certificate exchange and PQC certificate exchange with NRF 630. NFc 610 can send a discovery request with NFp 620 to NRF 630, and NRF 630 can respond with a subset of NF protocols from NFp 620 and instructions supporting general certificate exchange and PQC certificate exchange.

[0127] As shown in the figure, at 6010, NFc 610 can send a registration message, such as the Nnrf_MNManagement_Register message, to NRF 630. The Nnrf_MNManagement_Register message can include a subset of the NF protocol of NFc 610 and an indication that NFc 610 supports exchanging relevant general certificates and PQC certificates.

[0128] At 6020, NFp 620 can send registration messages to NRF 630, such as the Nnrf_MNManagement_Register message. The Nnrf_MNManagement_Register message can include a subset of the NF protocol of NFp 620 and an indication that NFp 620 supports exchanging relevant general certificates and PQC certificates.

[0129] At 6030, NFc 610 can send a discovery message, such as the Nnrf_NFDiscovery_request message, to NRF 630. The Nnrf_NFDiscovery_request message may include information about NFp 620, such as the identifier of NFp 620. Subsequently, at 6040, NRF 630 can send a response to the Nnrf_NFDiscovery_request message in response to NFc 610. The response may include a subset of the NF protocol of NFp 620 and an indication that NFp 620 supports exchanging relevant general certificates and PQC certificates.

[0130] Then, at 6050, NFc 610 can send a client greeting message to NFp 620, including indications of support for both PQC and regular certificates. Subsequently, at 6060, NFc 610 and NFp 620 can perform a TLS handshake process utilizing the PQC certificate. For example, at 6060, a TLS connection between NFc 610 and NFp 620 can be established based on the PQC certificate.

[0131] At 6070, NFc 610 and NFp 620 can perform a TLS handshake process using a regular certificate. The handshake at 6070 can be performed at the application layer. For example, at 6070, a TLS connection between NFc 610 and NFp 620 can be established based on a regular certificate. The PQC certificate and the regular certificate can be associated.

[0132] It should be noted that the procedures initiated by NFc 610 mentioned herein are for illustrative purposes only and do not imply any limitation. The exemplary embodiments of this disclosure are not limited herein. In some exemplary embodiments, the procedures may be initiated by NFp 620.

[0133] In this way, NFc 610 can request information about the capabilities of NFp 620 via NRF 630. Before establishing a connection between NFc 610 and NFp 620, both can be authenticated based on the exchange of PQC certificates. Therefore, TLS certificate authentication can be implemented, improving the security of the connection between NFc 610 and NFp 620.

[0134] Figure 7 A flowchart of an example method 700 implemented at a first device according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 700 is described by the angle of the first device 110 in the middle.

[0135] At box 710, the first device 110 receives information about the capabilities of the second device. This capability indicates that the second device supports the exchange of the first certificate, which is associated with the second certificate.

[0136] At box 720, the first device 110 performs the process for establishing a Transport Layer Security (TLS) connection based on the second certificate.

[0137] In frame 730, the first device 110 and the second device perform the exchange of the first certificate.

[0138] In some example implementations, the first device 110 may send a request for a first certificate for the second device to the second device. The first device 110 may also receive the first certificate from the second device.

[0139] In some example implementations, the first device 110 may receive a request for a first certificate for the first device from the second device. The first device 110 may then send the first certificate of the first device to the second device.

[0140] In some example implementations, the first device 110 may send a request for a second certificate for the second device to the second device. The first device 110 may also receive the second certificate from the second device.

[0141] In some example implementations, the first device 110 may receive a request for a second certificate for the first device from the second device. The first device 110 may then send the second certificate of the first device to the second device.

[0142] In some example implementations, the first device 110 may send a request to the second device regarding the capabilities of the second device. The first device 110 may receive a response to the request from the second device. The response may include information about the capabilities of the second device.

[0143] In some example implementations, the first device 110 may send the identifier of the second device to the third device. The first device 110 may receive the Internet Protocol (IP) address and information about the capabilities of the second device from the third device.

[0144] In some example implementations, the first device 110 may perform the process for establishing a TLS connection based on a second certificate, and perform the exchange of the first certificate with the second device based on the IP address.

[0145] In some example implementations, the identifier may include a fully qualified domain name (FQDN), and the third device is associated with the Domain Name System (DNS) service.

[0146] In some example implementations, the first device 110 may send a discovery request for the second device to a fourth device. The first device 110 may receive a response to the discovery request from the fourth device. The response may include a subset of protocol information of the second device and information about the capabilities of the second device.

[0147] In some example implementations, the first device 110 may perform the process for establishing a TLS connection based on a second certificate, and perform the exchange of the first certificate with the second device based on a subset of protocol information of the second device.

[0148] In some example implementations, the fourth device may include a network device that implements a network repository function (NRF).

[0149] In some example implementations, the first device 110 may send a subset of protocol information and information about the capabilities of the first device to the fourth device. The capabilities of the first device may indicate that the first device supports the exchange of a first certificate, which is associated with a second certificate.

[0150] In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate.

[0151] In some example implementations, the first device 110 may send a message to the second device containing information about the capabilities of the first device. This capability may instruct the first device to support the exchange of a first certificate, which is associated with a second certificate.

[0152] In some example implementations, the second certificate may include a post-quantum computing (PQC) certificate.

[0153] In some example implementations, at least one of the process for establishing a TLS connection based on a second certificate or the exchange of a first certificate may be triggered by either the first device or the second device.

[0154] In some example implementations, a first certificate and a second certificate can be used for authentication.

[0155] In some example implementations, the first device may include a network device that implements a network function or a Security Edge Protection Agent (SEPP), and the second device may include another network device that implements another network function or another SEPP.

[0156] Figure 8 A flowchart of an example method 800 implemented at a second device according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 800 is described by the angle of the second device 120 in the middle.

[0157] At box 810, the second device 120 sends information about its capabilities. This capability indicates that the second device supports the exchange of the first certificate, which is related to the second certificate. At box 820, the second device 120 performs the process for establishing a Transport Layer Security (TLS) connection based on the second certificate.

[0158] In frame 830, the second device 120 performs the exchange of the first certificate with the first device.

[0159] In some example implementations, the second device 120 may receive a request for a first certificate for the second device from the first device. The second device 120 may then send the first certificate of the second device to the first device.

[0160] In some example implementations, the second device 120 may send a request for a first certificate for the first device to the first device. The second device 120 may also receive the first certificate from the first device.

[0161] In some example implementations, the second device 120 may receive a request for a second certificate for the second device from the first device. The second device 120 may then send the second certificate of the second device to the first device.

[0162] In some example implementations, the second device 120 may send a request for a second certificate for the first device to the first device. The second device 120 may also receive the second certificate from the first device.

[0163] In some example implementations, the second device 120 may receive a request for the capabilities of the second device from the first device. The second device 120 may send a response to the request to the first device, which includes information about the capabilities of the second device.

[0164] In some example implementations, the second device 120 may send a subset of protocol information and information about the capabilities of the second device to the fourth device.

[0165] In some example implementations, the fourth device may include a network device that implements a network repository function (NRF).

[0166] In some example implementations, the second certificate may include a post-quantum computing (PQC) certificate.

[0167] In some example implementations, the second device 120 may receive a message from the first device that includes information about the capabilities of the first device. This capability may indicate that the first device supports the exchange of a first certificate, which is associated with a second certificate.

[0168] In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate.

[0169] In some example implementations, at least one of the process for establishing a TLS connection based on a second certificate or the exchange of a first certificate may be triggered by either the first device or the second device.

[0170] In some example implementations, a first certificate and a second certificate can be used for authentication.

[0171] In some example implementations, the first device may include a network device that implements a network function or a Security Edge Protection Agent (SEPP), and the second device may include another network device that implements another network function or another SEPP.

[0172] Figure 9 A flowchart of an example method 900 implemented at a third device according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 900 is described by the angle of the third device 130 in the middle.

[0173] In box 910, the third device 130 receives the identifier of the second device from the first device.

[0174] At box 920, the third device 130 sends an Internet Protocol (IP) address and information about the capabilities of the second device to the first device. This capability indicates that the second device supports the exchange of the first certificate, which is associated with the second certificate.

[0175] In some example implementations, the identifier may include a fully qualified domain name (FQDN).

[0176] In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate.

[0177] In some example implementations, the first device may include a network device that implements a network function or a Security Edge Protection Agent (SEPP), the third device may be associated with a Domain Name System (DNS) service, and the second device may include another network device that implements another network function or another SEPP.

[0178] Figure 10 A flowchart of an example method 1000 implemented at a fourth device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 1 Method 1000 is described by the angle of the fourth device 140 in the middle.

[0179] In box 1010, the fourth device 140 receives a discovery request for the second device from the first device.

[0180] At box 1020, the fourth device 140 sends a response to the discovery request to the first device. This response includes information about a subset of the second device's protocols and information about the capabilities of the second device. This capability indicates that the second device supports the exchange of a first certificate, which is associated with the second certificate.

[0181] In some example implementations, the fourth device 140 may receive protocol subset information and capability information of the first device from the first device. The capabilities of the first device may indicate that the first device supports the exchange of a first certificate, which is associated with a second certificate.

[0182] In some example implementations, the fourth device 140 may receive information about a subset of the second device's protocols and the capabilities of the second device. This capability may indicate that the second device supports the exchange of a first certificate associated with the second certificate.

[0183] In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate. The second certificate may also include a post-quantum computing (PQC) certificate.

[0184] In some example implementations, the first device may include a network device that implements a network function or a Security Edge Protection Agent (SEPP), the second device may include another network device that implements another network function or another SEPP, and the fourth device may include a network device that implements a Network Repository Function (NRF).

[0185] In some example implementations, a first device capable of performing any method 700 (e.g., Figure 1 The first device 110 may include components for performing the corresponding operation of method 700. The device may be implemented in any suitable form. For example, the device may be implemented in a circuit or software module. The first device may be implemented as or included in... Figure 1 In the first device 110.

[0186] In some example implementations, the first device may include components for receiving information about the capabilities of the second device. This capability may indicate that the second device supports the exchange of a first certificate, which is associated with the second certificate. The first device may include: units for performing a process for establishing a Transport Layer Security (TLS) connection based on the second certificate; and units for performing the exchange of the first certificate with the second device.

[0187] In some example implementations, the first device may further include: a unit for sending a request to the second device for a first certificate of the second device; and a unit for receiving the first certificate of the second device from the second device.

[0188] In some example implementations, the first device may further include: a unit for receiving a request for a first certificate for the first device from the second device; and a unit for sending the first certificate of the first device to the second device.

[0189] In some example implementations, the first device may further include: a unit for sending a request to the second device for a second certificate of the second device; and a unit for receiving the second certificate of the second device from the second device.

[0190] In some example implementations, the first device may further include: a unit for receiving a request for a second certificate for the first device from the second device; and a unit for sending the second certificate of the first device to the second device.

[0191] In some example implementations, the first device may further include: a unit for sending a request to the second device for the capabilities of the second device; and a unit for receiving a response to the request from the second device, the response including information about the capabilities of the second device.

[0192] In some example implementations, the first device may further include: a unit for sending an identifier of the second device to a third device; and a unit for receiving an Internet Protocol (IP) address and information about the capabilities of the second device from the third device.

[0193] In some example implementations, the first device may further include: a unit for performing a process for establishing a TLS connection based on a second certificate and for exchanging the first certificate with the second device based on an IP address.

[0194] In some example implementations, the identifier may include a fully qualified domain name (FQDN), and the third device may be associated with a Domain Name System (DNS) service.

[0195] In some example implementations, the first device may further include: a unit for sending a discovery request to the fourth device for the second device; and a unit for receiving a response to the discovery request from the fourth device, the response including a subset of protocol information of the second device and information about the capabilities of the second device.

[0196] In some example implementations, the first device may further include: a unit for performing a process for establishing a TLS connection based on a second certificate and for exchanging a first certificate with the second device based on a subset of protocol information of the second device.

[0197] In some example implementations, the fourth device may include a network device that implements a network repository function (NRF).

[0198] In some example implementations, the first device may further include a unit for sending protocol subset information of the first device and information about the capabilities of the first device to the fourth device. The capabilities of the first device may indicate that the first device supports the exchange of a first certificate, which is associated with a second certificate.

[0199] In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate.

[0200] In some example implementations, the first device may further include a unit for sending a message to the second device containing information about the capabilities of the first device. This capability may instruct the first device to support the exchange of a first certificate, which is associated with a second certificate.

[0201] In some example implementations, the second certificate may include a post-quantum computing (PQC) certificate.

[0202] In some example implementations, at least one of the process for establishing a TLS connection based on a second certificate or the exchange of a first certificate may be triggered by either the first device or the second device.

[0203] In some example implementations, a first certificate and a second certificate can be used for authentication.

[0204] In some example implementations, the first device may include a network device that implements a network function or a Security Edge Protection Agent (SEPP), and the second device may include another network device that implements another network function or another SEPP.

[0205] In some example implementations, a second device capable of performing any of the methods in method 800 (e.g., Figure 1 The second device 120 may include components for performing the corresponding operation of method 800. This device may be implemented in any suitable form. For example, it may be implemented in a circuit or software module. The second device may be implemented as or included in... Figure 1 The second device 120 in the middle.

[0206] In some example implementations, the second device may include components for sending information about the capabilities of the second device. This capability may indicate that the second device supports the exchange of a first certificate, which is associated with the second certificate. The second device may include: units for performing a process for establishing a Transport Layer Security (TLS) connection based on the second certificate; and units for performing the exchange of the first certificate with the first device.

[0207] In some example implementations, the second device may further include: a unit for receiving a request for a first certificate for the second device from the first device; and a unit for sending the first certificate of the second device to the first device.

[0208] In some example implementations, the second device may further include: a unit for sending a request to the first device for a first certificate of the first device; and a unit for receiving the first certificate of the first device from the first device.

[0209] In some example implementations, the second device may further include: a unit for receiving a request for a second certificate for the second device from the first device; and a unit for sending the second certificate of the second device to the first device.

[0210] In some example implementations, the second device may further include: a unit for sending a request to the first device for a second certificate for the first device; and a unit for receiving the second certificate of the first device from the first device.

[0211] In some example implementations, the second device may further include: a unit for receiving a request for the capabilities of the second device from the first device; and a unit for sending a response to the request to the first device, the response including information about the capabilities of the second device.

[0212] In some example implementations, the second device may further include a unit for transmitting protocol subset information of the second device and information about the capabilities of the second device to the fourth device.

[0213] In some example implementations, the fourth device may include a network device that implements a network repository function (NRF).

[0214] In some example implementations, the second certificate may include a post-quantum computing (PQC) certificate.

[0215] In some example implementations, the second device may further include a unit for receiving a message from the first device that includes information about the capabilities of the first device. This capability may indicate that the first device supports the exchange of a first certificate, which is associated with a second certificate.

[0216] In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate.

[0217] In some example implementations, at least one of the exchange of a TLS connection based on a second certificate or a first certificate is triggered by a first device or a second device.

[0218] In some example implementations, a first certificate and a second certificate are used for authentication.

[0219] In some example implementations, the first device may include a network device that implements a network function or a Security Edge Protection Agent (SEPP), and the second device may include another network device that implements another network function or another SEPP.

[0220] In some example implementations, a third device capable of performing any of the methods in method 900 (e.g., Figure 1The third device 130 may include components for performing the corresponding operation of method 900. This device may be implemented in any suitable form. For example, it may be implemented in a circuit or software module. The third device may be implemented as or included in... Figure 1 The third device 130 in the middle.

[0221] In some example implementations, the third device may include: a unit for receiving an identifier of the second device from the first device; and a unit for sending an Internet Protocol (IP) address and information about the capabilities of the second device to the first device. This capability may indicate that the second device supports the exchange of a first certificate, which is associated with the second certificate.

[0222] In some example implementations, the identifier may include a fully qualified domain name (FQDN).

[0223] In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate.

[0224] In some example implementations, the first device may include a network device that implements a network function or a Security Edge Protection Proxy (SEPP), the third device is associated with a Domain Name System (DNS) service, and the second device may include another network device that implements another network function or another SEPP.

[0225] In some example implementations, a fourth device capable of performing any of the methods in method 1000 (e.g., Figure 1 The fourth device 140 may include components for performing the corresponding operation of method 1000. This device may be implemented in any suitable form. For example, it may be implemented in a circuit or software module. The fourth device may be implemented as or included in... Figure 1 The fourth device 140 in the middle.

[0226] In some example implementations, the fourth device may include: a unit for receiving a discovery request for the second device from the first device; and a unit for sending a response to the discovery request to the first device, the response including a subset of protocol information of the second device and information about the capabilities of the second device. This capability may indicate that the second device supports the exchange of a first certificate, which is associated with the second certificate.

[0227] In some example implementations, the fourth device may further include a unit for receiving protocol subset information of the first device and information about the capabilities of the first device from the first device. The capabilities of the first device may indicate that the first device supports the exchange of a first certificate, which is associated with a second certificate.

[0228] In some example implementations, the fourth device may further include a unit for receiving protocol subset information of the second device and information about the capabilities of the second device. This capability may indicate that the second device supports the exchange of a first certificate, which is associated with the second certificate.

[0229] In some example implementations, the first certificate may include a post-quantum computing (PQC) certificate. The second certificate may also include a post-quantum computing (PQC) certificate.

[0230] In some example implementations, the first device may include a network device that implements a network function or a Security Edge Protection Agent (SEPP), the second device may include another network device that implements another network function or another SEPP, and the fourth device may include a network device that implements a Network Repository Function (NRF).

[0231] Figure 11 This is a simplified block diagram of device 1100 suitable for implementing example embodiments of the present disclosure. Device 1100 can be provided to implement a communication device, such as... Figure 1 The first device 110, the second device 120, the third device 130, and the fourth device 140 are shown. As shown, the device 1100 includes one or more processors 1110, one or more memories 1120 coupled to the processors 1110, and one or more communication modules 1140 coupled to the processors 1110.

[0232] Communication module 1140 is used for bidirectional communication. Communication module 1140 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interface can represent any interface necessary for communication with other network elements. In some example embodiments, communication module 1140 may include at least one antenna.

[0233] As a non-limiting example, processor 1110 can be any type suitable for a local technology network and can include one or more of the following: general-purpose computer, special-purpose computer, microprocessor, digital signal processor (DSP), and processor based on a multi-core processor architecture. Device 1100 can have multiple processors, such as application-specific integrated circuit chips that are time-dependent on a clock that synchronizes with the main processor.

[0234] Memory 1120 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 1124, electrically programmable read-only memory (EPROM), flash memory, hard disk, compact disc (CD), digital video disc (DVD), optical disc, laser disc, and other magnetic and / or optical storage. Examples of volatile memories include, but are not limited to, random access memory (RAM) 1122 and other volatile memories that will not persist for the duration of a power outage.

[0235] Computer program 1130 includes computer-executable instructions that are executed by an associated processor 1110. The instructions of program 1130 may include instructions for performing operations / actions of some example embodiments of this disclosure. Program 1130 may be stored in memory (e.g., ROM 1124). Processor 1110 can perform any suitable actions and processes by loading program 1130 into RAM 1122.

[0236] The exemplary implementation of this disclosure can be achieved through program 1130, enabling device 1100 to perform as described in the reference. Figures 2A to 10 Any process discussed in this disclosure. Example embodiments of this disclosure may also be implemented by hardware or by a combination of software and hardware.

[0237] In some example embodiments, program 1130 may be tangibly contained in a computer-readable medium, which may be included in device 1100 (such as in memory 1120) or in other storage devices accessible by device 1100. Device 1100 may load program 1130 from the computer-readable medium into RAM 1122 for execution. In some example embodiments, the computer-readable medium may include any type of non-transitory storage medium, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. As used herein, the term "non-transitory" refers to a limitation of the medium itself (i.e., tangible, not tactile), rather than a limitation of the persistence of data storage (e.g., RAM versus ROM).

[0238] Figure 12 An example of a computer-readable medium 1200 is shown, which may be in the form of a CD, DVD, or other optical storage disc. The computer-readable medium 1200 has a program 1130 stored thereon.

[0239] Generally, various embodiments of this disclosure can be implemented in hardware or special-purpose circuitry, software, logic, or any combination thereof. Some aspects can be implemented in hardware, and others can be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device. Although various aspects of embodiments of this disclosure are shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that the blocks, apparatuses, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, special-purpose circuitry or logic, general-purpose hardware, or controllers or other computing devices, or some combination thereof, as non-limiting examples.

[0240] Some example embodiments of this disclosure also provide at least one computer program product tangibly stored on a computer-readable medium, such as a non-transitory computer-readable medium. The computer program product includes computer-executable instructions that execute in a device on a target physical or virtual processor, such as those included in a program module, to perform any of the methods described above. Typically, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc., that perform a specific task or implement a specific abstract data type. In various embodiments, the functionality of a program module can be combined or split among program modules as needed. The machine-executable instructions for a program module can execute within a local or distributed device. In a distributed device, a program module can reside on both local and remote storage media.

[0241] Program code used to perform the methods of this disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that, when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a stand-alone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0242] In the context of this disclosure, computer program code or related data may be carried by any suitable carrier wave to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carrier waves include signals, computer-readable media, etc.

[0243] Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination thereof. More specific examples of computer-readable storage media will include electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable optical disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0244] Furthermore, although the operations are described in a specific order, this should not be construed as requiring that such operations be performed in the specific order shown or sequentially, or requiring that all the operations shown be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated otherwise, certain features described in the context of a single embodiment may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated otherwise, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0245] Although this disclosure has been described in language specific to structural features and / or methodological actions, it should be understood that the disclosure as defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms for implementing the claims.

[0246] Furthermore, the various implementations of this disclosure can be described with reference to the following terms, and their features can be combined in any reasonable manner.

[0247] Clause 1. A first means for communication, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first means to: receive information about the capabilities of a second means, wherein the capabilities indicate that the second means supports the exchange of a first certificate, the first certificate being associated with a second certificate; perform a process for establishing a transport layer security (TLS) connection based on the second certificate; and perform the exchange of the first certificate with the second means.

[0248] Clause 2. The first device according to Clause 1, wherein the instructions, when executed by the at least one processor, further cause the first device to: send a request for a first certificate for the second device to the second device; and receive the first certificate of the second device from the second device.

[0249] Clause 3. The first device according to Clause 1, wherein the instructions, when executed by the at least one processor, further cause the first device to: receive a request for a first certificate for the first device from the second device; and send the first certificate of the first device to the second device.

[0250] Clause 4. The first device according to Clause 1, wherein the instructions, when executed by the at least one processor, further cause the first device to: send a request to the second device for a second certificate for the second device; and receive the second certificate of the second device from the second device.

[0251] Clause 5. The first device according to Clause 1, wherein the instructions, when executed by the at least one processor, further cause the first device to: receive a request for a second certificate for the first device from the second device; and send the second certificate of the first device to the second device.

[0252] Clause 6. A first device according to any one of Clauses 1 to 5, wherein the instructions, when executed by the at least one processor, further cause the first device to: send a request to the second device for the capabilities of the second device; and receive a response from the second device to the request, the response including the information about the capabilities of the second device.

[0253] Clause 7. The first device according to any one of Clauses 1 to 5, wherein the instructions, when executed by the at least one processor, further cause the first device to: send the identifier of the second device to the third device; and receive from the third device the Internet Protocol (IP) address and the information of the capabilities of the second device.

[0254] Clause 8. The first apparatus according to Clause 7, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: perform a process for establishing the TLS connection based on the second certificate, and perform the exchange of the first certificate with the second apparatus based on the IP address.

[0255] Clause 9. The first device as described in Clause 7, wherein the identifier includes a fully qualified domain name (FQDN), and the third device is associated with the Domain Name System (DNS) service.

[0256] Clause 10. A first device according to any one of Clauses 1 to 5, wherein the instructions, when executed by the at least one processor, further cause the first device to: send a discovery request for the second device to a fourth device; and receive a response to the discovery request from the fourth device, the response including protocol subset information of the second device and the information on the capabilities of the second device.

[0257] Clause 11. The first apparatus according to Clause 10, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: perform the process for establishing the TLS connection based on the second certificate, and perform the exchange of the first certificate with the second apparatus based on the protocol subset information of the second apparatus.

[0258] Clause 12. The first apparatus as described in Clause 10, wherein the fourth apparatus includes a network device that implements the Network Repository Function (NRF).

[0259] Clause 13. The first device according to Clause 10, wherein the instructions, when executed by the at least one processor, further cause the first device to: send to the fourth device protocol subset information of the first device and information about the capabilities of the first device, wherein the capabilities of the first device indicate that the first device supports the exchange of a first certificate, which is associated with a second certificate.

[0260] Clause 14. The first device according to Clause 10, wherein the instructions, when executed by the at least one processor, further cause the first device to: send a message to the second device including information about the capabilities of the first device, wherein the capabilities indicate that the first device supports the exchange of a first certificate, which is associated with a second certificate.

[0261] Clause 15. The first device according to any one of Clauses 1-5, wherein the first certificate includes a post-quantum computing (PQC) certificate.

[0262] Clause 16. The first apparatus according to any one of Clauses 1 to 5, wherein at least one of the process for establishing the TLS connection based on the second certificate or the exchange of the first certificate is triggered by the first apparatus or the second apparatus.

[0263] Clause 17. The first device according to any one of Clauses 1 to 5, wherein the first certificate and the second certificate are used for authentication.

[0264] Clause 18. The first device according to any one of Clauses 1 to 5, wherein the first device includes a network device that implements a network function or a Security Edge Protection Agent (SEPP), and the second device includes another network device that implements another network function or another SEPP.

Claims

1. A first device for communication, comprising: At least one processor; as well as At least one memory stores instructions that, when executed by the at least one processor, cause the first device to: Receive information about the capabilities of the second device, wherein the capabilities indicate that the second device supports the exchange of the first certificate, which is associated with the second certificate; The process for establishing a Transport Layer Security (TLS) connection is performed based on the second certificate; as well as The exchange of the first certificate is performed with the second device.

2. The first apparatus of claim 1, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: Send a request for a first certificate for the second device to the second device; and Receive the first certificate from the second device.

3. The first apparatus of claim 1, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: Receive a request for a first certificate for the first device from the second device; and Send the first certificate of the first device to the second device.

4. The first apparatus of claim 1, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: Send a request for a second certificate for the second device to the second device; and Receive the second certificate from the second device.

5. The first apparatus of claim 1, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: Receive a request for a second certificate for the first device from the second device; and Send the second certificate of the first device to the second device.

6. The first apparatus of claim 1, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: Send a request for the capabilities of the second device to the second device; and Receive a response to the request from the second device, the response including the information about the capabilities of the second device.

7. The first apparatus of claim 1, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: Send the identifier of the second device to the third device; and The third device receives the Internet Protocol (IP) address and the information of the capabilities of the second device.

8. The first apparatus of claim 7, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: The process for establishing the TLS connection is performed based on the second certificate, and the exchange of the first certificate is performed with the second device based on the IP address.

9. The first apparatus of claim 1, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: Send a discovery request for the second device to the fourth device; and The fourth device receives a response to the discovery request, the response including a subset of protocol information of the second device and information about the capabilities of the second device.

10. The first device of claim 1, wherein the first certificate comprises a post-quantum computing (PQC) certificate.