Mobile access authentication and key agreement method against quantum attacks and electronic device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-25
- Publication Date
- 2026-08-11
AI Technical Summary
[0004]因此,针对现有移动通信接入认证协议在量子计算攻击模型下面临的安全性不足问题,亟须一种兼顾抗量子安全性、用户隐私保护以及系统效率的新型接入认证方案
[0017]本申请提供一种抗量子攻击的移动接入认证与密钥协商方法,所述方法包括:接收服务网络发送的消息;其中,所述消息包括密文、用户标识以及服务网络身份标识;基于本地保存的后量子私钥解封装所述密文以得到临时共享密钥;根据所述用户标识确定目标用户永久标识符,并在数据库中查找所述目标用户永久标识符对应的永久密钥;根据预先生成的随机数、所述永久密钥、所述临时共享密钥和所述服务网络身份标识生成认证令牌和哈希期望响应值;将认证向量发送给所述服务网络,以使所述服务网络对用户设备进行移动接入认证并发送响应值;其中,所述认证向量包括所述随机数、所述认证令牌和所述哈希期望响应值;将所述响应值与本地计算得到的期望响应值进行比较,若所述响应值与所述期望响应值相等,则完成对用户设备的移动接入认证,生成锚密钥,并将所述目标用户永久标识符和所述锚密钥发送给服务网络。通过在归属网络侧独立执行后量子密钥封装机制的密钥生成过程,专门生成符合密钥封装机制(Key Encapsulation Mechanism,KEM)规范要求的公私钥对,并将该公钥作为接入认证阶段的独立安全参数提供给用户终端使用,从而在协议层面实现传统密钥体系与后量子密钥体系的明确分离,避免了现有技术中密钥混用所带来的安全隐患,使后量子机制能够以可实施、可验证的方式嵌入移动接入认证流程,提升认证协议在量子计算攻击模型下的整体安全性;通过在接入认证初始阶段由用户终端通过执行密钥封装算法生成一次性的临时共享密钥,并利用该临时共享密钥的随机性、唯一性和不可预测性作为认证过程中的核心新鲜性因子,使其直接参与后续认证参数生成,保证认证过程中密钥协商阶段具备抗量子攻击能力,将原本依赖状态同步实现的新鲜性保障转化为依赖一次性后量子共享密钥实现的新鲜性保障,有效消除序列号同步依赖,降低可链接性攻击与隐私泄露风险;通过复用接入认证初始阶段通过密钥封装机制生成的临时共享密钥,并将其统一引入身份保护、认证向量生成以及会话密钥派生过程,能够有效避免了重复调用后量子算法,而且在保持抗量子安全能力和前向安全能力的同时,显著降低了协议整体的计算复杂度与通信开销,从而更适合在未来移动通信系统中实际部署。
Smart Images

Figure CN122554088A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of mobile communication technology, and in particular to a quantum-resistant mobile access authentication and key negotiation method and electronic device. Background Technology
[0002] With the large-scale commercialization of fifth-generation mobile communication systems, the 5G Authentication and Key Agreement (5G-AKA), standardized by the 3rd Generation Partnership Project (3GPP), has become the core mechanism for user access authentication and key negotiation in current cellular mobile communication systems. Building upon the 4G Authentication and Key Agreement protocol, 5G-AKA introduces a privacy protection mechanism for the user's permanent identity. By encrypting the user's permanent identity to generate a user privacy identifier, it effectively reduces the risk of passive eavesdropping and tracking of the user's identity in the wireless link.
[0003] However, the 5G-AKA protocol primarily relies on public-key cryptography algorithms based on elliptic curve cryptography for user identity protection and some security functions. Its security is built upon traditional mathematical problems such as the discrete logarithm problem. With the development of quantum computing technology, quantum attacks based on Shor's algorithm can theoretically threaten these public-key cryptography algorithms, meaning that once a practical quantum computer becomes available, the currently widely used 5G-AKA protocol will be completely destroyed.
[0004] Therefore, in view of the insufficient security of existing mobile communication access authentication protocols under quantum computing attack models, there is an urgent need for a new access authentication scheme that takes into account quantum security, user privacy protection, and system efficiency. Summary of the Invention
[0005] In view of this, embodiments of the present invention provide a quantum-resistant mobile access authentication and key negotiation method and electronic device to eliminate or improve one or more defects existing in the prior art.
[0006] One aspect of the present invention provides a first mobile access authentication and key negotiation method resistant to quantum attacks, performed by a home network, the method comprising: Receive a message sent by the service network; wherein the message includes ciphertext, a user identifier, and a service network identity identifier; The ciphertext is decapsulated using the locally stored post-quantum private key to obtain a temporary shared key; a permanent identifier for the target user is determined based on the user identifier, and the permanent key corresponding to the permanent identifier for the target user is searched in the database; an authentication token and a hash expected response value are generated based on a pre-generated random number, the permanent key, the temporary shared key, and the service network identity; the authentication vector is sent to the service network so that the service network performs mobile access authentication on the user equipment and sends a response value; wherein, the authentication vector includes the random number, the authentication token, and the hash expected response value; The response value is compared with the expected response value calculated locally. If the response value is equal to the expected response value, the mobile access authentication of the user equipment is completed, an anchor key is generated, and the target user permanent identifier and the anchor key are sent to the service network.
[0007] In some embodiments of the present invention, prior to receiving the message sent by the receiving service network, the method further includes: Generate post-quantum public and private keys based on the post-quantum key encapsulation algorithm; The post-quantum public key is sent to the user equipment.
[0008] In some embodiments of the present invention, the service network is configured to perform the following: The system receives and saves the authentication vector sent by the home network, and sends the random number and the authentication token to the user equipment, so that the user equipment performs mobile access authentication for the home network and generates a response value. If a response value is received from the user equipment, the target hash value obtained by calculating the response value and the random number is compared with the locally stored expected hash response value. If the target hash value is equal to the expected hash response value, the response value is sent to the home network.
[0009] In some embodiments of the invention, the service network is also configured to perform the following: If a failure message is received from the user equipment, the protocol is terminated.
[0010] In some embodiments of the present invention, determining the target user's permanent identifier based on the user identifier includes: If the user identifier is a permanent user identifier, then the permanent user identifier is determined as the target user's permanent identifier; If the user identifier is a hidden user identifier, then the hidden user identifier is decrypted based on the temporary shared key to obtain the target user permanent identifier corresponding to the hidden user identifier.
[0011] Another aspect of the present invention provides a second mobile access authentication and key negotiation method resistant to quantum attacks, executed by a user equipment, the method comprising: Obtain the post-quantum public key generated by the home network, and generate ciphertext and temporary shared key based on the post-quantum public key; if a globally unique temporary identifier has been allocated locally, send the ciphertext and the globally unique temporary identifier to the service network so that the service network sends the ciphertext and the target user's permanent identifier to the home network and sends the random number and authentication token generated by the home network and the service network identity identifier of the service network. An anonymous key is calculated based on the locally stored permanent key and the random number. The anonymous key and the authentication token are used to obtain the home network authentication value. The desired home network authentication value is calculated based on the permanent key, the random number, the temporary shared key, and the service network identity identifier. The home network authentication value is compared with the expected home network authentication value. If the home network authentication value is equal to the expected home network authentication value, a response value and an anchor key are calculated, and the response value is sent to the service network.
[0012] In some embodiments of the present invention, it further includes: If a globally unique temporary identifier is not assigned locally, a user-hidden identifier is obtained by encrypting the temporary shared key, and the ciphertext and the user-hidden identifier are sent to the service network.
[0013] In some embodiments of the present invention, the service network is configured to perform the following: If the received message from the user equipment is the ciphertext and the globally unique temporary identifier, then the target user permanent identifier corresponding to the globally unique temporary identifier is found based on the globally unique temporary identifier, and the ciphertext, the target user permanent identifier, and the local service network identity identifier are sent to the home network. If the received message from the user equipment contains the ciphertext and the user-hidden identifier, then the ciphertext, the user-hidden identifier, and the serving network identity identifier are directly sent to the home network.
[0014] A third aspect of this application provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the first mobile access authentication and key negotiation method resistant to quantum attacks, and / or, a second mobile access authentication and key negotiation method resistant to quantum attacks.
[0015] A fourth aspect of this application provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the first mobile access authentication and key negotiation method resistant to quantum attacks, and / or a second mobile access authentication and key negotiation method resistant to quantum attacks.
[0016] The fifth aspect of this application provides a computer program product comprising a computer program that, when executed by a processor, implements the first mobile access authentication and key negotiation method resistant to quantum attacks, and / or a second mobile access authentication and key negotiation method resistant to quantum attacks.
[0017] This application provides a quantum-resistant mobile access authentication and key negotiation method. The method includes: receiving a message sent by a serving network; wherein the message includes ciphertext, a user identifier, and a serving network identity identifier; decapsulating the ciphertext based on a locally stored post-quantum private key to obtain a temporary shared key; determining a target user permanent identifier based on the user identifier and searching for the permanent key corresponding to the target user permanent identifier in a database; generating an authentication token and a hash expected response value based on a pre-generated random number, the permanent key, the temporary shared key, and the serving network identity identifier; sending an authentication vector to the serving network so that the serving network performs mobile access authentication on the user equipment and sends a response value; wherein the authentication vector includes the random number, the authentication token, and the hash expected response value; comparing the response value with a locally calculated expected response value; if the response value is equal to the expected response value, then completing the mobile access authentication of the user equipment, generating an anchor key, and sending the target user permanent identifier and the anchor key to the serving network. By independently executing the key generation process of the post-quantum key encapsulation mechanism on the home network side, a key encapsulation mechanism is specifically generated. The public-private key pair required by the KEM (Knowledge, Mechanism, and Authentication) specification is used, and the public key is provided to the user terminal as an independent security parameter during the access authentication phase. This achieves a clear separation between the traditional key system and the post-quantum key system at the protocol level, avoiding the security risks caused by key mixing in existing technologies. This allows the post-quantum mechanism to be embedded into the mobile access authentication process in a feasible and verifiable manner, improving the overall security of the authentication protocol under quantum computing attack models. Furthermore, in the initial stage of access authentication, the user terminal generates a one-time temporary shared key by executing a key encapsulation algorithm. The randomness, uniqueness, and unpredictability of this temporary shared key serve as the core freshness factor in the authentication process, allowing it to directly participate in... The generation of subsequent authentication parameters ensures that the key negotiation phase during authentication is resistant to quantum attacks. The freshness guarantee, which originally relied on state synchronization, is now achieved by relying on a one-time post-quantum shared key. This effectively eliminates the dependency on sequence number synchronization and reduces the risk of linkability attacks and privacy leaks. By reusing the temporary shared key generated through the key encapsulation mechanism in the initial stage of access authentication and uniformly introducing it into the identity protection, authentication vector generation, and session key derivation processes, the repeated invocation of the post-quantum algorithm can be effectively avoided. Moreover, while maintaining quantum security and forward security capabilities, the overall computational complexity and communication overhead of the protocol are significantly reduced, making it more suitable for practical deployment in future mobile communication systems.
[0018] Additional advantages, objectives, and features of this application will be set forth in part in the description which follows, and will in part become apparent to those skilled in the art upon review of the following description, or may be learned by practice of the application. The objectives and other advantages of this application can be realized and obtained by means of the structures specifically pointed out in the specification and drawings.
[0019] Those skilled in the art will understand that the purposes and advantages that can be achieved with this application are not limited to those specifically described above, and that the above and other purposes that this application can achieve will be more clearly understood from the following detailed description. Attached Figure Description
[0020] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, do not constitute a limitation thereof. The components in the drawings are not drawn to scale but are merely for illustrating the principles of this application. For ease of illustration and description of certain parts of this application, corresponding portions in the drawings may be enlarged, i.e., may appear larger relative to other components in an exemplary device actually manufactured according to this application. In the drawings: Figure 1 This is a flowchart illustrating a first mobile access authentication and key negotiation method resistant to quantum attacks according to an embodiment of this application.
[0021] Figure 2 This is a flowchart illustrating a quantum-resistant second mobile access authentication and key negotiation method according to an embodiment of this application.
[0022] Figure 3 This is a schematic diagram of the mobile network architecture in an application example of this application.
[0023] Figure 4 This is a flowchart illustrating the startup phase in an application example of this application.
[0024] Figure 5 This is a flowchart illustrating the challenge-response phase in an application example of this application. Detailed Implementation
[0025] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the embodiments and accompanying drawings. Here, the illustrative embodiments and their descriptions are used to explain this application, but are not intended to limit it.
[0026] It should also be noted that, in order to avoid obscuring this application with unnecessary details, only the structures and / or processing steps closely related to the solution according to this application are shown in the accompanying drawings, while other details that are not closely related to this application are omitted.
[0027] It should be emphasized that the term "including / comprises" as used herein refers to the presence of a feature, element, step, or component, but does not exclude the presence or addition of one or more other features, elements, steps, or components.
[0028] It should also be noted that, unless otherwise specified, the term "connection" in this article can refer not only to a direct connection, but also to an indirect connection involving an intermediary.
[0029] In the following description, embodiments of the present application will be illustrated with reference to the accompanying drawings. In the drawings, the same reference numerals represent the same or similar parts, or the same or similar steps.
[0030] Currently, existing solutions typically incorporate post-quantum cryptography algorithms into the 5G-AKA authentication architecture for access authentication. These solutions generally maintain the basic authentication process between the user terminal, serving network, and home network unchanged, enhancing system security against quantum computing attacks by introducing post-quantum public-key cryptography algorithms or post-quantum key encapsulation mechanisms during the access authentication phase. In practice, existing long-term public-private key pairs on the home network side are usually reused as input parameters for the post-quantum cryptography algorithm. The user terminal performs encapsulation or encryption operations based on this public key, and the generated ciphertext or shared information is forwarded to the home network through the serving network to complete the authentication process. To prevent replay attacks and maintain compatibility with the existing 5G-AKA mechanism, these solutions generally retain the sequence number synchronization mechanism as the primary means of ensuring authentication freshness. Furthermore, to ensure that the authentication protocol meets forward security requirements after introducing post-quantum cryptography algorithms, some solutions typically generate a new post-quantum public-private key on the home network side after completing one post-quantum key negotiation during the authentication phase. The user terminal then negotiates an additional temporary key with the network side to achieve forward security.
[0031] Although existing research has attempted to introduce post-quantum cryptography algorithms into mobile communication authentication protocols, certain shortcomings remain. 1) Current schemes, when introducing post-quantum key encapsulation mechanisms, directly utilize the existing public and private keys on the home network side to perform encapsulation and decapsulation operations for the post-quantum algorithm, without distinguishing the key generation mechanism required by the post-quantum algorithm. 2) Current schemes typically retain the Sequence Number (SQN) synchronization mechanism as a means to prevent replay attacks. However, this mechanism is insufficient to fundamentally resist linkability attacks, potentially leading to user privacy leaks. 3) While ensuring post-quantum security and forward security, current schemes repeatedly call the post-quantum cryptography algorithm during the authentication process to enhance security, resulting in a significant increase in computational complexity and communication overhead. This is unfavorable for resource-constrained user terminals and fails to meet the low-latency requirements of mobile communication systems.
[0032] Therefore, to address the security shortcomings of existing mobile communication access authentication protocols under quantum computing attack models, embodiments of this application provide a first mobile access authentication and key negotiation method resistant to quantum attacks, a second mobile access authentication and key negotiation method resistant to quantum attacks, an electronic device, a computer-readable storage medium, and a computer program product, respectively, to improve the quantum attack resistance of authentication protocols, reduce the risk of linkability attacks and privacy leaks, and enhance the forward security of session keys while ensuring quantum security.
[0033] The following examples will provide a detailed description.
[0034] Based on this, embodiments of this application provide a first mobile access authentication and key negotiation method resistant to quantum attacks that can be executed by the home network, see [link to relevant documentation]. Figure 1 The method specifically includes the following: Step 100: Receive a message sent by the service network; wherein the message includes ciphertext, user identifier, and service network identity identifier.
[0035] Specifically, the ciphertext C and user identifier received by the Home Network (HN) from the Serving Network (SN) are generated by the User Equipment (UE). The user identifier can be a Subscription Permanent Identifier (SUPI) or a Subscription Concealed Identifier (SUCI).
[0036] Step 200: Decapsulate the ciphertext based on the locally stored post-quantum private key to obtain a temporary shared key; determine the target user's permanent identifier based on the user identifier, and search for the permanent key corresponding to the target user's permanent identifier in the database; generate an authentication token and a hash expected response value based on a pre-generated random number, the permanent key, the temporary shared key, and the service network identity identifier; send the authentication vector to the service network so that the service network performs mobile access authentication on the user equipment and sends a response value; wherein, the authentication vector includes the random number, the authentication token, and the hash expected response value.
[0037] It should also be noted that HN uses the quantum private key after use. After performing the decapsulation algorithm on the ciphertext C, a temporary shared key Ks is obtained, and the permanent identifier of the target user is determined. HN generates a random number R, based on the permanent key K pre-shared with the UE and the serving network identity identifier sent by SN. The temporary shared key Ks generates a series of authentication parameters: an authentication token (AUTN) and a hash of the expected response value. They are sent to the SN along with a random number R as an authentication vector (AV).
[0038] Step 300: Compare the response value with the expected response value calculated locally. If the response value is equal to the expected response value, complete the mobile access authentication for the user equipment, generate an anchor key, and send the target user permanent identifier and the anchor key to the service network.
[0039] It should be noted that HN receives the response value sent by SN. Then, by comparing the response values and the expected response value locally This completes the authentication of the UE. An anchor key will be generated upon successful authentication. Finally, SUPI and the corresponding Once sent to the SN, the entire authentication and key negotiation process is complete.
[0040] As described above, the first mobile access authentication and key negotiation method against quantum attacks provided in this application embodiment generates a public-private key pair that conforms to the KEM specification by independently executing the key generation process of the post-quantum key encapsulation mechanism on the home network side. This public key is then provided to the user terminal as an independent security parameter during the access authentication phase. This achieves a clear separation between the traditional key system and the post-quantum key system at the protocol level, avoiding the security risks caused by key mixing in existing technologies. It enables the post-quantum mechanism to be embedded into the mobile access authentication process in a feasible and verifiable manner, improving the overall security of the authentication protocol under quantum computing attack models. Furthermore, by having the user terminal generate a one-time temporary shared key through the key encapsulation algorithm at the initial stage of access authentication, and utilizing the randomness of this temporary shared key… Uniqueness, distinctiveness, and unpredictability serve as core freshness factors in the authentication process, enabling them to directly participate in the generation of subsequent authentication parameters. This ensures that the key negotiation phase of the authentication process is resistant to quantum attacks, transforming the freshness guarantee that originally relied on state synchronization into a freshness guarantee that relies on a one-time post-quantum shared key. This effectively eliminates the dependency on sequence number synchronization and reduces the risk of linkability attacks and privacy leaks. By reusing the temporary shared key generated through the key encapsulation mechanism in the initial stage of access authentication and uniformly introducing it into the identity protection, authentication vector generation, and session key derivation processes, the repeated invocation of the post-quantum algorithm can be effectively avoided. Moreover, while maintaining quantum security and forward security capabilities, the overall computational complexity and communication overhead of the protocol are significantly reduced, making it more suitable for practical deployment in future mobile communication systems.
[0041] To further enhance the quantum attack resistance of the authentication protocol, reduce the risk of linkability attacks and privacy leaks, and strengthen the forward security of the session key while ensuring quantum security, the first mobile access authentication and key negotiation method against quantum attacks provided in this application embodiment includes the following content before step 100, before receiving the message sent by the service network: Step 010: Generate a post-quantum public key and a post-quantum private key based on the post-quantum key encapsulation algorithm; Step 020: Send the post-quantum public key to the user equipment.
[0042] Specifically, the home network executes the key generation process of the post-quantum key encapsulation mechanism to generate a public-private key pair that conforms to the KEM specification requirements. The public key is then provided to the user terminal as an independent security parameter in the access authentication phase. This achieves a clear separation between the traditional key system and the post-quantum key system at the protocol level, avoiding the security risks caused by key mixing in existing technologies. This enables the post-quantum mechanism to be embedded into the mobile access authentication process in an implementable and verifiable manner.
[0043] To further enhance the quantum attack resistance of the authentication protocol, reduce the risk of linkability attacks and privacy leaks, and strengthen the forward security of the session key while ensuring quantum security, in a quantum attack resistant first mobile access authentication and key negotiation method provided in this application embodiment, in step 100, the service network is used to perform the following: Step 400: Receive and save the authentication vector sent by the home network, and send the random number and the authentication token to the user equipment, so that the user equipment performs mobile access authentication for the home network and generates a response value.
[0044] Step 500: If a response value is received from the user equipment, the target hash value obtained by calculating the response value and the random number is compared with the locally stored expected hash response value. If the target hash value is equal to the expected hash response value, the response value is sent to the home network.
[0045] Specifically, after receiving the authentication vector AV sent by HN, SN will The data is saved, and then R and AUTN are sent to the UE to enable the user equipment to perform mobile access authentication with the home network and generate a response value. The serving network receives the response value sent by the UE user equipment. Then, a 256-bit Secure Hash Algorithm (SHA256) can be used for processing. and R, and the result is compared with The values are compared; if they match, the SN serving network completes the authentication of the UE user equipment; otherwise, the protocol terminates. After successful authentication, the SN serving network sends a message to the HN home network. .
[0046] To further enhance the quantum attack resistance of the authentication protocol, reduce the risk of linkability attacks and privacy leaks, and strengthen the forward security of the session key while ensuring quantum security, in a quantum attack resistant first mobile access authentication and key negotiation method provided in this application embodiment, in step 100, the service network is further configured to perform the following: Step 600: If a failure message is received from the user equipment, the protocol is terminated.
[0047] Specifically, if the SN service network receives a failure message (MAC_Failure) from the UE user equipment, the protocol terminates.
[0048] To further enhance the quantum attack resistance of the authentication protocol, reduce the risk of linkability attacks and privacy leaks, and strengthen the forward security of the session key while ensuring quantum security, in a quantum attack resistant first mobile access authentication and key negotiation method provided in this application embodiment, step 200, which involves determining the target user's permanent identifier based on the user identifier, further includes the following: If the user identifier is a permanent user identifier, then the permanent user identifier is determined as the target user's permanent identifier; If the user identifier is a hidden user identifier, then the hidden user identifier is decrypted based on the temporary shared key to obtain the target user permanent identifier corresponding to the hidden user identifier.
[0049] Specifically, if HN receives SUCI, it uses Ks to decrypt it to obtain SUPI, and then looks up the permanent key K and authentication protocol in the database based on SUPI. The new protocol is used by default here.
[0050] Based on the embodiments and / or application examples of the first mobile access authentication and key negotiation method against quantum attacks performed by the home network described above, this application also provides an embodiment of a second mobile access authentication and key negotiation method against quantum attacks performed by the user equipment. See [link to embodiment]. Figure 2 The quantum-resistant mobile access authentication and key negotiation method specifically includes the following: Step 001: Obtain the post-quantum public key generated by the home network, and generate ciphertext and temporary shared key based on the post-quantum public key; if a globally unique temporary identifier has been allocated locally, send the ciphertext and the globally unique temporary identifier to the service network so that the service network sends the ciphertext and the target user's permanent identifier to the home network, and sends the random number and authentication token generated by the home network and the service network identity identifier of the service network.
[0051] Step 002: Calculate the anonymous key based on the locally stored permanent key and the random number, and use the anonymous key and the authentication token to obtain the home network authentication value; calculate the desired home network authentication value based on the permanent key, the random number, the temporary shared key and the service network identity identifier.
[0052] Step 003: Compare the home network authentication value with the expected home network authentication value. If the home network authentication value is equal to the expected home network authentication value, calculate the response value and the anchor key, and send the response value to the service network.
[0053] Specifically, the UE uses the post-quantum public key on the HN side. The ciphertext C and the temporary shared key Ks are derived and stored. If the current UE has been assigned a globally unique temporary identifier (GUTI), the UE will directly send C and GUTI to the SN. This will cause the serving network to send the ciphertext and the target user's permanent identifier to the home network, as well as the random number and authentication token generated by the home network and the serving network identity identifier of the serving network.
[0054] The UE calculates the anonymous key AK using its local permanent key K and the received R, and then generates the Home Network Authentication Value HNMAC using AK and AUTN. This is based on the identity identifier of the UE using the permanent key K, the received R, the temporary shared key Ks, and the SN. The expected home network authentication value xHNMAC is calculated. Freshness verification and HN authentication are completed by checking HNMAC. If the check passes (i.e., the home network authentication value equals the expected home network authentication value), the UE calculates a response value. and anchor key At the same time Send to SN; if the check fails or the values are not equal, send a failure message MAC_Failure to the service network.
[0055] As described above, the second mobile access authentication and key negotiation method against quantum attacks provided in this application generates a public-private key pair conforming to the KEM specification by independently executing the key generation process of the post-quantum key encapsulation mechanism on the home network side. This public key is then provided to the user terminal as an independent security parameter during the access authentication phase. This achieves a clear separation between the traditional key system and the post-quantum key system at the protocol level, avoiding the security risks caused by key mixing in existing technologies. It enables the post-quantum mechanism to be embedded into the mobile access authentication process in a feasible and verifiable manner, improving the overall security of the authentication protocol under quantum computing attack models. Furthermore, by having the user terminal generate a one-time temporary shared key through the key encapsulation algorithm at the initial stage of access authentication, and utilizing the randomness of this temporary shared key… Uniqueness, distinctiveness, and unpredictability serve as core freshness factors in the authentication process, enabling them to directly participate in the generation of subsequent authentication parameters. This ensures that the key negotiation phase of the authentication process is resistant to quantum attacks, transforming the freshness guarantee that originally relied on state synchronization into a freshness guarantee that relies on a one-time post-quantum shared key. This effectively eliminates the dependency on sequence number synchronization and reduces the risk of linkability attacks and privacy leaks. By reusing the temporary shared key generated through the key encapsulation mechanism in the initial stage of access authentication and uniformly introducing it into the identity protection, authentication vector generation, and session key derivation processes, the repeated invocation of the post-quantum algorithm can be effectively avoided. Moreover, while maintaining quantum security and forward security capabilities, the overall computational complexity and communication overhead of the protocol are significantly reduced, making it more suitable for practical deployment in future mobile communication systems.
[0056] To further enhance the quantum attack resistance of the authentication protocol, reduce the risk of linkability attacks and privacy leaks, and strengthen the forward security of the session key while ensuring quantum security, the quantum attack resistant second mobile access authentication and key negotiation method provided in this application embodiment further includes the following in step 001: If a globally unique temporary identifier is not assigned locally, a user-hidden identifier is obtained by encrypting the temporary shared key, and the ciphertext and the user-hidden identifier are sent to the service network.
[0057] Specifically, if the UE is not assigned a GUTI, the UE will use the temporary shared key Ks to encrypt its own permanent identifier SUPI to obtain SUCI, and then send C and SUCI to the SN.
[0058] To further enhance the quantum attack resistance of the authentication protocol, reduce the risk of linkability attacks and privacy leaks, and strengthen the forward security of the session key while ensuring quantum security, in a quantum attack resistant second mobile access authentication and key negotiation method provided in this application embodiment, in step 001, the service network is used to perform the following: Step 004: If the message received from the user equipment is the ciphertext and the globally unique temporary identifier, then find the target user permanent identifier corresponding to the globally unique temporary identifier, and send the ciphertext, the target user permanent identifier, and the local service network identity identifier to the home network. Step 005: If the message received from the user equipment contains the ciphertext and the user-hidden identifier, then directly send the ciphertext, the user-hidden identifier, and the serving network identity identifier to the home network. Specifically, after receiving a message from the UE, if the received message is a GUTI, the SN will find the corresponding SUPI based on the GUTI, and then combine the C, SUPI, and its own identifier. Send to HN; if SUCI is received, SN will directly send C, SUCI and Send to HN.
[0059] To further illustrate the embodiments of the above-described quantum-resistant first mobile access authentication and key negotiation method and the quantum-resistant second mobile access authentication and key negotiation method, this application also provides a specific application example of a multi-terminal interactive quantum-resistant mobile access authentication and key negotiation method. Specifically, it includes the following: Existing research on the introduction of post-quantum cryptography algorithms generally suffers from problems such as non-standard key usage, strong reliance on sequence number synchronization mechanisms, and high computational and communication overhead, making it difficult to meet the comprehensive requirements of future mobile communication systems for high security, low latency, and lightweight implementation. To address these shortcomings, this study proposes a post-quantum secure access authentication scheme for future mobile communication systems. Unlike existing technologies that merely superimpose post-quantum cryptography algorithms within the 5G-AKA authentication framework, this application example addresses the implementation obstacles arising from the introduction of post-quantum mechanisms in terms of key systems, freshness guarantee methods, and protocol overhead control through targeted protocol reconstruction.
[0060] First, while existing solutions introduce post-quantum key encapsulation mechanisms, they typically reuse the existing public-private key system on the home network side to perform encapsulation and decapsulation operations. However, the key generation and usage methods under traditional public-key cryptography are inconsistent with the key specifications of post-quantum key encapsulation mechanisms. Directly reusing the original key not only makes it difficult to guarantee the standardization of the post-quantum algorithm invocation process but may also lead to confusion in key usage, thereby affecting protocol security and implementation feasibility. Therefore, this application example, without changing the overall authentication architecture and functional entity division of the existing mobile communication network, introduces an authentication mechanism that meets post-quantum security requirements, eliminating the dependence on traditional sequence number synchronization mechanisms. This enhances user identity privacy protection capabilities while resisting quantum computing attacks, and reduces the overall computational complexity and communication overhead of the protocol while ensuring forward security, thereby improving the engineering deployability and practical value in future 6G and other mobile communication systems.
[0061] First, in the application example of this application, the key generation process of the post-quantum key encapsulation mechanism is executed independently on the home network side. A public-private key pair that conforms to the KEM specification is specifically generated, and the public key is provided to the user terminal as an independent security parameter in the access authentication stage. This achieves a clear separation between the traditional key system and the post-quantum key system at the protocol level, avoids the security risks caused by key mixing in the prior art, and enables the post-quantum mechanism to be embedded into the mobile access authentication process in an implementable and verifiable manner.
[0062] Secondly, existing solutions typically still use the SQN synchronization mechanism to ensure authentication freshness and replay protection. However, the SQN mechanism itself relies on the user side and the network side to maintain a synchronized state. In mobile access scenarios, this not only presents problems such as complex synchronization maintenance and difficulty in anomaly recovery, but also allows attackers to exploit state differences and the synchronization process, creating a linkable attack path. This application example does not simply retain the original SQN structure. Instead, at the initial stage of access authentication, the user terminal generates a one-time temporary shared key by executing the KEM encapsulation algorithm. The randomness, uniqueness, and unpredictability of this temporary shared key are used as the core freshness factor in the authentication process, allowing it to directly participate in the generation of subsequent authentication parameters. In this way, this application example transforms the freshness guarantee, which originally relied on state synchronization, into a freshness guarantee relying on a one-time quantum shared key. This eliminates the dependence on SQN synchronization from a mechanistic perspective and effectively cuts off the linkable attack path based on sequence number state exposure.
[0063] Finally, existing solutions, in order to simultaneously satisfy quantum-resistant security and forward security, often call the post-quantum algorithm multiple times during the authentication process, or introduce a new temporary key negotiation process after completing one post-quantum key negotiation. Although such solutions can theoretically enhance security, they significantly increase the computational burden, signaling interaction frequency, and protocol latency on both the terminal and network sides, which is particularly unfavorable for the deployment of mobile communication terminals with strict requirements for resource constraints, low power consumption, and low latency. Therefore, to address the obstacle of maintaining authentication security and session key security while reducing the number of post-quantum algorithm calls, the application example of this application simplifies and restructures the authentication and key negotiation process. It directly reuses the temporary shared key generated by KEM encapsulation in the initial stage of access authentication and uniformly introduces it into the identity protection, authentication vector generation, and session key derivation processes. This allows the shared key generated by a single post-quantum encapsulation to simultaneously perform multiple functions such as identity protection, freshness assurance, and forward security enhancement. As a result, the application example of this application not only avoids repeated calls to the post-quantum algorithm, but also significantly reduces the overall computational complexity and communication overhead of the protocol while maintaining quantum-resistant security and forward security capabilities, making it more suitable for practical deployment in future mobile communication systems.
[0064] The mobile network architecture is broadly divided into three main entities: User Equipment (UE), Home Network (HN), and Serving Network (SN), as detailed below. Figure 3 As shown. User Equipment (UE) typically consists of a Universal Subscriber Identity Module (USIM) and a smartphone or mobile equipment (ME). The USIM stores the 5G network identity permanent identifier (SUPI). To prevent the SUPI from being sent in plaintext over the radio channel, the UE encrypts it into a SUCI using the HN's public key when sending the SUPI to the SN. The Home Network (HN) includes network elements such as Unified Data Management (UDM) and Authentication Credential Repository and Processing Function (ARPF), which store a permanent key K shared with the UE. The Serving Network (SN) exists when the user roams to a base station without a corresponding HN. It is used to provide specific network services to the UE and includes network elements such as Access and Mobility Management Function (AMF) and Security Anchor-Function (SEAF) to provide access and security protection for the UE.
[0065] Regarding the channels between entities, the UE and SN receive messages via a radio channel, which is unprotected due to its open nature. However, the channel between the SN and HN is a 3GPP End-to-Network (e2e) core network interconnection channel. This channel provides confidentiality, integrity, authenticity, and replay protection for message transmission, thus preventing eavesdropping and tampering by attackers. Furthermore, the channel between the SN and HN is entity-bound, while the channel between the UE and SN is not entity-bound.
[0066] The 6th Generation Post-Quantum Authentication and Key Agreement (6G-PQAKA) proposed in this application example includes the following: The flowchart for the startup phase is as follows: Figure 4 As shown: (1) First, the UE uses the post-quantum public key on the HN side. The UE derives the ciphertext C and the temporary shared key Ks, and saves Ks. If the current UE has been assigned a GUTI, the UE will directly send C and GUTI to the SN. If the UE has not been assigned a GUTI, the UE will use the temporary shared key Ks to encrypt its permanent identity identifier SUPI to obtain SUCI, and then send C and SUCI to the SN.
[0067] (2) After receiving a message from the UE, if the received message is a GUTI, the SN will find the corresponding SUPI based on the GUTI, and then use the C, UPI and its own identifier. Send to HN; if SUCI is received, SN will directly send C, SUCI and Send to HN.
[0068] (3) HN after using the quantum private key After decapsulating the ciphertext C, the post-quantum pre-shared key Ks is obtained. If HN receives SUCI, Ks is used to decrypt it to obtain SUPI. Based on SUPI, the permanent key K and authentication protocol are searched in the database. The new protocol is used by default here.
[0069] The flowchart for the challenge and response phase is as follows: Figure 5 As shown: (1) HN generates a random number R, and then, based on the permanent key K pre-shared with the UE, SN sends... And the post-quantum pre-shared key Ks generates a series of authentication parameters, AUTN, and the expected hash response value. They are sent to the SN along with a random number R as an authentication vector AV.
[0070] (2) After receiving the authentication vector AV sent by HN, SN will Save the data, and then send R and AUTN to the UE.
[0071] (3) The UE first calculates the anonymous key AK using its own permanent key K and the received R, and then obtains the home network authentication value HNMAC by XORing AK with AUTN. The identity identifier is determined based on the permanent key K, the received R, the temporary shared key Ks, and the SN. Calculate xHNMAC. By checking HNMAC, freshness verification and HN authentication are completed. If the check passes, the UE will calculate RES* and... At the same time, RES* is sent to SN; if the check fails, MAC_Failure is sent to SN.
[0072] (4) The SN receives the response value sent by the UE. Afterwards, The result of SHA256 encoding of R and The values are compared; if they match, the SN completes the authentication of the UE; otherwise, the protocol terminates. After successful authentication, the SN sends a message to the HN. If the SN receives a MAC_Failure message from the UE, the protocol terminates.
[0073] (5) HN receives the message sent by SN Then, through comparison and This completes the authentication of the UE. An anchor key will be generated upon successful authentication. Finally, SUPI and the corresponding Once sent to the SN, the entire authentication and key negotiation process is complete.
[0074] To further clarify the generation method of each key value in the authentication process of this invention, the relevant cryptographic functions and parameters are defined as follows in the application examples of this application: K represents the long-term symmetric key pre-shared between the User Equipment (UE) and the Home Network (HN); R represents the one-time random challenge value generated by the Home Network (HN); Ks represents the temporary shared key generated by the UE through a post-quantum key encapsulation mechanism and recovered by the Home Network (HN) through decapsulation. The identifier represents the service network SN; H() represents a one-way hash function; KDF() represents a key derivation function; This represents a string concatenation operation; This indicates a bitwise XOR operation; c1, c2, c3, and c4 represent different preset context identifier constants used to distinguish function inputs for different purposes, preventing confusion or reuse attacks between different derived values. Each key value can be generated as follows: (1) The formula for generating the anonymous key AK is: The anonymous key AK is used to mask the authentication value in the home network authentication message to prevent the authentication parameters from being directly parsed during transmission.
[0075] (2) The formula for generating the Home Network Authentication Message (HNMAC) value is: HNMAC relies on a long-term key K, a random challenge value R, a temporary shared key Ks, and a service network identifier. .
[0076] (3) The formula for generating the authentication token AUTN is: After receiving the AUTN, the User Equipment (UE) first calculates the AK based on the locally stored K and the received R, and then recovers the HNMAC through an XOR operation, thereby completing the verification of the home network authentication message.
[0077] (4) Expected response value The formula for generating it is: (5) The user equipment side generates a corresponding response value. Its generation method is the same as Consistency, that is: (6) Expected Hash Response Value The formula for generating it is: (7) Correspondingly, the serving network SN receives the message sent by the user equipment. Then, it can be calculated: By comparison and The consistency of the response values is used to verify the correctness of the user equipment.
[0078] (8) Session anchor key The formula for generating it is: In this invention, the post-quantum temporary shared key between the user equipment (UE) and the home network (HN) is generated through a post-quantum key encapsulation mechanism (KEM). Let... This indicates that the public key is encapsulated in quantum key distribution on the network side. Indicates and The corresponding post-quantum key encapsulated private key, in a preferred embodiment, can be represented as follows: (9) Home network side key generation process: Where lambda represents the safety parameter, The public key is encapsulated in a quantum key distribution for the home network side. The private key is encapsulated in the quantum key distribution for the home network side.
[0079] (10) User equipment side packaging process: Among them, the UE is based on the home network side public key. An encapsulation algorithm is executed to generate ciphertext C and a temporary shared key Ks. The ciphertext C is sent to the home network side, and the temporary shared key Ks is stored locally by the user equipment and used for subsequent identity protection, authentication parameter generation, and session key derivation processes.
[0080] (11) Home network side decapsulation process: Among them, HN is based on post-quantum key encapsulation of private keys. The received ciphertext C is decapsulated using an algorithm to recover a temporary shared key Ks that is consistent with the user equipment side.
[0081] This application also included protocol security analysis experiments in its application examples, as detailed below: 1. Safety Objectives Regarding the new protocol, according to the requirements of the 5G-AKA protocol in the standard, it is mainly divided into authentication, confidentiality and privacy security objectives, as detailed below: (1) Certification 1) Authentication between UE and HN A1 (Weak consistency between UE and HN): At the end of the protocol execution, the user equipment (UE) must reach a weak consistency with the home network (HN), that is, the UE can confirm that the peer of the interaction it has completed is indeed a legitimate HN.
[0082] A2 (Weak consistency between HN and UE): At the end of the protocol execution, the home network HN must reach a weak consistency with the user equipment UE, that is, HN can confirm that the other end of the interaction it has completed is indeed a legitimate UE.
[0083] A3 (UE to) (Non-injective consistency): To ensure that the serving network SN has been authorized by the home network HN, the user equipment UE must specify the serving network identifier. Achieving non-injective consistency with HN means that the UE can confirm that the identity of the service network participating in this authentication process has been correctly incorporated into the authentication context by HN.
[0084] A4 (HN pair) (Non-injective consistency): To prevent the serving network SN from forging authentication requests for UEs that are not actually attached to its base station and requesting authentication from the home network HN, the home network HN must verify the serving network identifier. Achieving non-injective consistency with the UE means that the HN can confirm that the UE's authentication request is indeed associated with the claimed service network.
[0085] A5 (UE to) (Injection consistency): To ensure the session anchor key obtained by the UE and HN. Completely identical, and the same ones will not be created repeatedly. User Equipment (UE) must Achieve injective consistency with HN.
[0086] A6 (HN pair) (Injective consistency): Accordingly, the home network HN must... Achieving single-shot consistency with the UE ensures that both parties have a consistent understanding of the session anchor key, and that each successful protocol execution uniquely corresponds to a key establishment process.
[0087] 2) Authentication between UE and SN A7 (Weak consistency between UE and SN): At the end of the protocol execution, the user equipment (UE) must reach a weak consistency with the serving network (SN), that is, the UE can confirm that the peer it accesses and interacts with is indeed the target serving network (SN).
[0088] A8 (Weak consistency between SN and UE): At the end of the protocol execution, the serving network SN must reach a weak consistency with the user equipment UE, that is, the SN can confirm that the peer it authenticates and serves is indeed a legitimate UE.
[0089] A9 (UE to) (Single-shot consistency): To ensure that the UE and SN are based on the same session anchor key in subsequent security protection. It runs and will not create the same thing repeatedly. User Equipment (UE) must Achieve single-shot consistency with SN.
[0090] A10 (SN pair) (Injective consistency): Accordingly, the serving network SN must... Achieve single-shot consistency with the UE to ensure its reception and use. It maintains consistency with the UE side, and each key establishment uniquely corresponds to one authentication session.
[0091] 3) Authentication between SN and HN A11 (Non-injective consistency of SN with SUPI): To ensure that the user equipment authenticated by the serving network SN has indeed been authorized by the home network HN, the serving network SN must reach non-injective consistency with HN on the user's permanent identifier SUPI, that is, the SN can confirm that the user's identity has been confirmed by HN.
[0092] A12 (SN pair) (Injective consistency): The service network SN must be consistent with the single-shot consistency. Achieve injective consistency with HN to ensure that the session anchor key issued by HN to SN is consistent with the key it actually uses, and that there will be no duplicate keys. The case of being created repeatedly.
[0093] A13 (HN pair) (Injective consistency): The home network HN must be... Achieve injective consistency with the SN to ensure that it is generated and distributed for a specific authentication session. Each key corresponds one-to-one with the key ultimately received and used by the SN.
[0094] (2) Confidentiality: C1 (Confidentiality of long-term key K): Guarantee the confidentiality of long-term key K.
[0095] C2 (anchor key) (Confidentiality): Guarantee the anchor key The confidentiality of the information.
[0096] (3) Privacy: P1 (UE privacy): First, the confidentiality of SUPI needs to be guaranteed.
[0097] P2 (UE indistinguishability): Given two legitimate UE1 and UE2, and the AKA session in which UE1 (or UE2) participates, an active attacker cannot determine whether it is interacting with UE1 or UE2.
[0098] 2. Safety Assumptions Regarding channel security assumptions: For the channel between HN and SN, TS 33.501 defines it as an e2e core network interconnection channel, providing confidentiality, integrity, authenticity, and replay protection for message transmission. This means attackers cannot launch passive or active attacks on this channel, nor can they impersonate one entity to send messages to other entities. Furthermore, this channel is entity-bound. On the other hand, the channel between UE and SN is an open radio channel, allowing attackers complete control over it, enabling both passive and active attacks.
[0099] Security assumptions regarding cryptographic primitives: The cryptographic algorithms f1-f5 and KDF used in the protocol, as well as the post-quantum key encapsulation mechanism KEM, can guarantee the confidentiality and integrity of their input parameters. However, attackers can also use these algorithms to process data within the knowledge set and construct messages.
[0100] Security assumptions regarding protocol entities. In accordance with TS 33.501, we assume that an attacker will not control any entities within the 5G core network (such as SN and HN), and that long-term secrets within these entities (such as the permanent key K, ...) remain confidential. ) and temporary secrets (such as This information will not be leaked to attackers, but attackers can use fake base station attacks to lure honest UEs to connect to their deployed fake base stations. Furthermore, we assume that attackers also cannot obtain the honest UE's protected permanent key K and the anchor key generated after the AKA protocol is completed from the honest UE. .
[0101] 3. Analysis Results To clarify the minimum security assumptions upon which the new protocol proposed in this application's application instance relies to achieve its various security objectives, a formal security analysis of the protocol is performed using Tamarin Prover, and several possible threat scenarios are modeled and analyzed, specifically including: An attacker gains control of multiple User Equipments (UEs) and obtains stored secret parameters, such as the User Permanent Identifier (SUPI) and long-term key K; the attacker gains control of multiple Serving Networks (SNs) and can manipulate the communication process between the Serving Network (SN) and the Home Network (HN); the attacker gains control of multiple Home Networks (HNs) and obtains stored sensitive parameters, such as the long-term key K and the home network's back-end quantum key encapsulation private key. And the user's permanent identifier SUPI.
[0102] Regarding the security objectives of authentication, confidentiality, and privacy mentioned above, the results shown in Table 1 are as follows. Where "kc" indicates that the UE and SN need to confirm the key; "k" indicates that the shared key between the legitimate user equipment and the legitimate home node has not been leaked; "wa" indicates that non-injective consistency is included in the proof of weak consistency; "ch" indicates that the communication link between the legitimate serving node and the legitimate home node has not been compromised; "" indicates that no compromised service nodes exist; "sk" indicates that the private key of the legitimate owner node has not been leaked; "supi" indicates that the user's identity has not been leaked; "-" indicates that the target is not required by the standard; This means that even if all entities are honest nodes, the security objective cannot be met.
[0103] Table 1 Experimental Results Based on the formal analysis above, the new protocol fails to satisfy only one of the aforementioned security objectives: HN's relationship with SN. The single-shot consistency. This property is not satisfied compared to the 5G-AKA protocol because the new protocol sends HN to SN. The authentication process has been changed from the first message in the authentication phase to the last message in the authentication phase. After this change, due to the SN acquisition... The time has already passed since the protocol execution has ended, so this property cannot be satisfied. As can be seen from the preceding description, the inability to satisfy this property is not due to an attacker's attack, but rather to make the protocol design more reasonable, because HN only sends the message to SN after successful authentication. That is more in line with reality.
[0104] 6G-PQAKA can satisfy security attribute A3, while the traditional 5G-AKA protocol cannot. This is because when the serving node generates the message authentication code HNMAC, it uses the long-term key K pre-shared between the UE and HN, along with the identity identifier of the serving network. Add it. User equipment authenticates the service node's identity by verifying HNMAC, thereby improving the protocol's ability to resist spoofing attacks; 6G-PQAKA can satisfy security attribute A5 without key authentication, while 5G-AKA requires key authentication. This is because the user equipment uses HNMAC to verify the security of the session key. Service node identifier in Verification is performed to ensure parameter consistency between user equipment and the home node. In contrast, 5G-AKA lacks [this feature / component]. During the verification process, attackers can tamper with this identifier, causing discrepancies between the user device and the home node. The parameters are inconsistent. Therefore, 5G-AKA requires an additional key verification process.
[0105] 6G-PQAKA satisfies security attribute P2, while 5G-AKA cannot. This is because 6G-PQAKA employs a novel Temporary Shared Key instead of Sequence Number (SQN) mechanism to defend against message replay attacks in the wireless channel. This eliminates the Type II security vulnerability present in 5G-AKA, preventing linkability attacks initiated by proactive attackers and further enhancing user privacy protection.
[0106] 6G-PQAKA Implementation The forward security of 5G-AKA is insufficient, which 5G-AKA cannot provide. The reason lies in the derived... A temporary pre-shared key Ks was introduced. Attackers cannot derive session keys without knowing the subsequent quantum temporary shared key Ks.
[0107] Therefore, the application examples of this application can guarantee the confidentiality, authentication, privacy, and forward security of the session key during the access authentication process under quantum attacks.
[0108] The advantages of this application example are as follows: 1. The protocol offers enhanced security, ensuring the standardization and effectiveness of post-quantum algorithm calls. This application example addresses the issue of non-standard key usage in the post-quantum key encapsulation mechanism of existing quantum-resistant authentication schemes by clearly distinguishing the key system at the protocol design level. Unlike existing schemes that directly reuse the traditional public-private key pair on the home network side to execute the post-quantum algorithm, this application example has the home network side specifically perform the key generation process for the post-quantum key encapsulation mechanism, generating public-private key pairs that conform to the KEM specification. These pairs are then provided to the user terminal as independent security parameters during the access authentication phase. This approach ensures the correct invocation of the post-quantum algorithm during key generation, encapsulation, and decapsulation processes from the protocol source, avoiding potential security vulnerabilities introduced by the mixed use of key systems, thereby significantly improving the overall security of the authentication protocol under quantum computing attack models.
[0109] 2. Introduce a post-quantum key encapsulation mechanism to enhance the authentication protocol's resistance to quantum attacks. The post-quantum key encapsulation mechanism used in this application example is based on mathematically difficult problems currently considered resistant to quantum computing attacks, such as lattice difficulties or other quantum-resistant problems. This makes it difficult for attackers, even with quantum computing capabilities, to recover the encapsulated key or derive the shared key within a feasible timeframe. During the access authentication process in this application example, the user terminal performs a key encapsulation operation based on the post-quantum public key provided by the home network to generate a temporary shared key. The home network then recovers this shared key by performing a decapsulation operation using the corresponding private key. Because the security of this shared key relies on the aforementioned quantum-resistant problem, even if an attacker intercepts the ciphertext information transmitted during the authentication process, it will be difficult to recover the corresponding shared key, thus ensuring that the key negotiation phase of the authentication process is resistant to quantum attacks.
[0110] Furthermore, in the traditional 5G-AKA protocol, the protection of the user's permanent identifier SUPI mainly relies on a public-key encryption mechanism based on elliptic curve cryptography. However, elliptic curve cryptography algorithms are potentially vulnerable to being effectively cracked under quantum computing attack models. This application example generates a temporary shared key Ks during the access authentication process, which can then be used to further protect user identity information. Since Ks originates from a post-quantum key encapsulation mechanism built upon a quantum-resistant difficulty problem, its security does not depend on traditional elliptic curve cryptography. Therefore, it avoids the attack risks against elliptic curve cryptography algorithms in a quantum computing environment, thereby further enhancing the protection of user identity privacy.
[0111] 3. Effectively eliminates serial number synchronization dependency, reducing the risk of linkability attacks and privacy leaks. This application example breaks away from the traditional 5G-AKA protocol's design approach of relying on Sequence Number (SQN) synchronization mechanisms to ensure freshness. In existing solutions, the update and synchronization state of the SQN can be exploited by attackers to launch linkability attacks and infer user behavior patterns. This application example utilizes a post-quantum key encapsulation mechanism to generate a one-time temporary shared key at the initial stage of access authentication. The freshness and unpredictability of this shared key are naturally guaranteed by the randomness of the post-quantum algorithm. By replacing the sequence number with a temporary shared key to perform replay protection and freshness verification functions, this application example achieves effective protection against replay attacks without introducing additional state synchronization overhead, and eliminates linkability attack paths related to the sequence number from a mechanism perspective, significantly enhancing user identity and privacy protection capabilities.
[0112] 4. Reduced computational complexity and communication overhead, making it more suitable for resource-constrained user terminals. To address the issue of existing solutions incurring multiple calls to post-quantum cryptographic algorithms to simultaneously achieve forward security and quantum resistance, leading to a significant increase in system overhead, this application simplifies and restructures the authentication and key negotiation process. Existing solutions typically require multiple generation or updates of post-quantum public and private keys during the authentication process, along with additional negotiation of temporary variables, thus increasing the computational burden and signaling interactions between the terminal and the network. This application directly reuses the temporary shared key generated through KEM encapsulation in the initial stage of access authentication and incorporates it into subsequent authentication vector generation and session key derivation processes, enabling a single call to the post-quantum algorithm to support the entire authentication process. This significantly reduces the number of post-quantum algorithm calls while maintaining security, lowering computational complexity and communication overhead, making it more suitable for implementation in resource-constrained and power-sensitive mobile terminals.
[0113] 5. Enhance the forward security of session keys while ensuring quantum-resistant security. This application example incorporates a temporary shared key generated during the access authentication phase into the session key derivation process, ensuring that the final session key depends on both the long-term key and a one-time random factor. Since the temporary shared key is used only in a single authentication process, even if an attacker obtains the long-term key of the home network or user terminal in the future, they cannot deduce the session key used in historical sessions. This further enhances the forward security of the protocol beyond quantum-resistant security. Compared to existing schemes that achieve forward security solely through repeated calls to the post-quantum algorithm or by introducing additional temporary keys, this application example achieves a better balance between security and efficiency.
[0114] 6. Compatible with existing mobile communication architectures, offering excellent engineering deployability. The application example in this application fully considers the network architecture and functional entity division of existing 5G-AKA and its evolution systems during its design, without making disruptive modifications to the basic interaction mode between user terminals, serving networks, and home networks. By introducing a post-quantum key encapsulation mechanism into the existing authentication process and optimizing and reconstructing key steps, the application example in this application can achieve security upgrades while maintaining the existing system architecture essentially unchanged, reducing the cost of modifying existing network equipment and terminals. Therefore, the application example in this application not only has theoretical security advantages but also strong engineering feasibility and practical application value, making it suitable for promotion and deployment in future 6G and evolved mobile communication systems.
[0115] This application also provides an electronic device, which may include a processor, a memory, a receiver, and a transmitter. The processor is used to execute the quantum-resistant first mobile access authentication and key negotiation method and / or the quantum-resistant second mobile access authentication and key negotiation method mentioned in the above embodiments. The processor and memory can be connected via a bus or other means, taking a bus connection as an example. The receiver can be connected to the processor and memory via wired or wireless means.
[0116] The processor can be a central processing unit (CPU). The processor can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or combinations of the above types of chips.
[0117] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the program instructions / modules corresponding to the quantum-resistant first mobile access authentication and key negotiation method and / or the quantum-resistant second mobile access authentication and key negotiation method in the embodiments of this application. The processor executes various functional applications and data processing by running the non-transitory software programs, instructions, and modules stored in the memory, thereby implementing the quantum-resistant first mobile access authentication and key negotiation method and / or the quantum-resistant second mobile access authentication and key negotiation method in the above method embodiments.
[0118] The memory may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created by the processor, etc. Furthermore, the memory may include high-speed random access memory and non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory may optionally include memory remotely located relative to the processor, which can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0119] The one or more modules are stored in the memory, and when executed by the processor, they execute the first mobile access authentication and key negotiation method and / or the second mobile access authentication and key negotiation method resistant to quantum attacks in the implementation embodiment.
[0120] In some embodiments of this application, the user equipment may include a processor, a memory, and a transceiver unit. The transceiver unit may include a receiver and a transmitter. The processor, memory, receiver, and transmitter may be connected via a bus system. The memory is used to store computer instructions, and the processor is used to execute the computer instructions stored in the memory to control the transceiver unit to send and receive signals.
[0121] As one implementation method, the functions of the receiver and transmitter in this application can be implemented by transceiver circuits or dedicated transceiver chips, and the processor can be implemented by dedicated processing chips, processing circuits or general-purpose chips.
[0122] As another implementation approach, the server provided in this application embodiment can be implemented using a general-purpose computer. That is, the program code implementing the processor, receiver, and transmitter functions is stored in memory, and the general-purpose processor implements the processor, receiver, and transmitter functions by executing the code in memory.
[0123] This application also provides a computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements the steps of the aforementioned quantum-resistant first mobile access authentication and key negotiation method and / or quantum-resistant second mobile access authentication and key negotiation method. The computer-readable storage medium can be a tangible storage medium, such as random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, floppy disk, hard disk, removable storage disk, CD-ROM, or any other form of storage medium known in the art.
[0124] This application also provides a computer program product, specifically comprising a computer program that, when executed by a processor, implements the steps of the first mobile access authentication and key negotiation method and / or the second mobile access authentication and key negotiation method against quantum attacks mentioned in the foregoing embodiments.
[0125] Those skilled in the art will understand that the exemplary components, systems, and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software, or a combination of both. Whether implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application. When implemented in hardware, it can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. The programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave.
[0126] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0127] In this application, features described and / or illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, and / or combined with or in place of features of other embodiments.
[0128] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to the embodiments of this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A quantum-resistant mobile access authentication and key negotiation method, characterized in that, Performed by the home network, including: Receive a message sent by the service network; wherein the message includes ciphertext, a user identifier, and a service network identity identifier; The ciphertext is decapsulated using the locally stored post-quantum private key to obtain a temporary shared key; a permanent identifier for the target user is determined based on the user identifier, and the permanent key corresponding to the permanent identifier for the target user is searched in the database; an authentication token and a hash expected response value are generated based on a pre-generated random number, the permanent key, the temporary shared key, and the service network identity; the authentication vector is sent to the service network so that the service network performs mobile access authentication on the user equipment and sends a response value; wherein, the authentication vector includes the random number, the authentication token, and the hash expected response value; The response value is compared with the expected response value calculated locally. If the response value is equal to the expected response value, the mobile access authentication of the user equipment is completed, an anchor key is generated, and the target user permanent identifier and the anchor key are sent to the service network.
2. The quantum-resistant mobile access authentication and key negotiation method according to claim 1, characterized in that, Before the message sent by the receiving service network, it also includes: Generate post-quantum public and private keys based on the post-quantum key encapsulation algorithm; The post-quantum public key is sent to the user equipment.
3. The quantum-resistant mobile access authentication and key negotiation method according to claim 1, characterized in that, The service network is used to perform the following: The system receives and saves the authentication vector sent by the home network, and sends the random number and the authentication token to the user equipment, so that the user equipment performs mobile access authentication for the home network and generates a response value. If a response value is received from the user equipment, the target hash value obtained by calculating the response value and the random number is compared with the locally stored expected hash response value. If the target hash value is equal to the expected hash response value, the response value is sent to the home network.
4. The quantum-resistant mobile access authentication and key negotiation method according to claim 1, characterized in that, The service network is also used to perform the following: If a failure message is received from the user equipment, the protocol is terminated.
5. The quantum-resistant mobile access authentication and key negotiation method according to claim 1, characterized in that, The step of determining the target user's permanent identifier based on the user identifier includes: If the user identifier is a permanent user identifier, then the permanent user identifier is determined as the target user's permanent identifier; If the user identifier is a hidden user identifier, then the hidden user identifier is decrypted based on the temporary shared key to obtain the target user permanent identifier corresponding to the hidden user identifier.
6. A quantum-resistant mobile access authentication and key negotiation method, characterized in that, Performed by a user equipment, the method includes: Obtain the post-quantum public key generated by the home network, and generate ciphertext and temporary shared key based on the post-quantum public key; if a globally unique temporary identifier has been allocated locally, send the ciphertext and the globally unique temporary identifier to the service network so that the service network sends the ciphertext and the target user's permanent identifier to the home network and sends the random number and authentication token generated by the home network and the service network identity identifier of the service network. An anonymous key is calculated based on the locally stored permanent key and the random number. The anonymous key and the authentication token are used to obtain the home network authentication value. The desired home network authentication value is calculated based on the permanent key, the random number, the temporary shared key, and the service network identity identifier. The home network authentication value is compared with the expected home network authentication value. If the home network authentication value is equal to the expected home network authentication value, a response value and an anchor key are calculated, and the response value is sent to the service network.
7. The quantum-resistant mobile access authentication and key negotiation method according to claim 6, characterized in that, Also includes: If a globally unique temporary identifier is not assigned locally, a user-hidden identifier is obtained by encrypting the temporary shared key, and the ciphertext and the user-hidden identifier are sent to the service network.
8. The quantum-resistant mobile access authentication and key negotiation method according to claim 6, characterized in that, The service network is used to perform the following: If the received message from the user equipment is the ciphertext and the globally unique temporary identifier, then the target user permanent identifier corresponding to the globally unique temporary identifier is found based on the globally unique temporary identifier, and the ciphertext, the target user permanent identifier, and the local service network identity identifier are sent to the home network. If the received message from the user equipment contains the ciphertext and the user-hidden identifier, then the ciphertext, the user-hidden identifier, and the serving network identity identifier are directly sent to the home network.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the quantum-resistant mobile access authentication and key negotiation method as described in any one of claims 1 to 5, and / or implements the quantum-resistant mobile access authentication and key negotiation method as described in any one of claims 6 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the quantum-resistant mobile access authentication and key negotiation method as described in any one of claims 1 to 5, and / or implements the quantum-resistant mobile access authentication and key negotiation method as described in any one of claims 6 to 8.