Methods and systems for primary authentication using hybrid key exchange / hybrid encryption in communication networks

EP4606140A4Pending Publication Date: 2026-01-21SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2024757167
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-02-13
Filing Date
2024-02-13
Publication Date
2026-01-21

AI Technical Summary

Technical Problem

Current wireless communication systems, particularly 5G, are vulnerable to quantum threats due to the use of legacy asymmetric crypto algorithms like Elliptic Curve Diffie-Hellman, which are insecure against quantum computers, and lack support for Post-Quantum Cryptography (PQC) algorithms, necessitating a transition to quantum-resistant methods for secure key establishment and data protection in 6G networks.

Method used

Implementing a hybrid key exchange and hybrid encryption method using Elliptical Curve (EC) and Post-Quantum Cryptography (PQC) algorithms for generating shared keys and encrypting data, enabling SUPI concealment and de-concealment, while supporting both legacy and PQC algorithms to ensure security against quantum threats and minimal modification to existing 3GPP specifications.

Benefits of technology

The hybrid approach provides robust security against quantum attacks, ensuring high-security assurance for SUPI concealment and data encryption, enabling seamless integration with both legacy and quantum-resistant methods, thus enhancing the security of 6G communication networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024001989_22082024_PF_FP
    Figure KR2024001989_22082024_PF_FP
Patent Text Reader

Abstract

The present disclosure relates to a 5G communication system or a 6G communication system for supporting higher data rates beyond a 4G communication system such as long term evolution (LTE). The present disclosure discloses methods for registering a User Equipment (UE) (101) with a Home Network (HN) (103) using hybrid key exchange, the method comprises generating an ephemeral public key and an ephemeral private key and generating a first ephemeral shared key based on the ephemeral private key and an Elliptical Curve (EC) based home network public key. Further, the method comprises generating a second ephemeral shared key and an encrypted shared key based on a Post-Quantum Cryptography based public key. Furthermore, the method comprises generating an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key and generating a cipher-text value and a message authentication code tag value. Finally, the method comprises transmitting a registration request for registering the UE with the home network along with the ephemeral public key, the encrypted shared key, the cipher-text value, and the MAC-tag value.
Need to check novelty before this filing date? Find Prior Art

Description

METHODS AND SYSTEMS FOR PRIMARY AUTHENTICATION USING HYBRID KEY EXCHANGE / HYBRID ENCRYPTION IN COMMUNICATION NETWORKS

[0001] The present disclosure generally relates to wireless communication networks. More particularly, the present disclosure relates to methods and systems / apparatuses for registering a User Equipment (UE) with a Home Network (HN) using hybrid key exchange and hybrid key encryption in communication network (e.g., 6G networks).

[0002] Considering the development of wireless communication from generation to generation, the technologies have been developed mainly for services targeting humans, such as voice calls, multimedia services, and data services. Following the commercialization of 5G (5th-generation) communication systems, it is expected that the number of connected devices will exponentially grow. Increasingly, these will be connected to communication networks. Examples of connected things may include vehicles, robots, drones, home appliances, displays, smart sensors connected to various infrastructures, construction machines, and factory equipment. Mobile devices are expected to evolve in various form-factors, such as augmented reality glasses, virtual reality headsets, and hologram devices. In order to provide various services by connecting hundreds of billions of devices and things in the 6G (6th-generation) era, there have been ongoing efforts to develop improved 6G communication systems. For these reasons, 6G communication systems are referred to as beyond-5G systems.

[0003] 6G communication systems, which are expected to be commercialized around 2030, will have a peak data rate of tera (1,000 giga)-level bps and a radio latency less than 100μsec, and thus will be 50 times as fast as 5G communication systems and have the 1 / 10 radio latency thereof.

[0004] In order to accomplish such a high data rate and an ultra-low latency, it has been considered to implement 6G communication systems in a terahertz band (for example, 95GHz to 3THz bands). It is expected that, due to severer path loss and atmospheric absorption in the terahertz bands than those in mmWave bands introduced in 5G, technologies capable of securing the signal transmission distance (that is, coverage) will become more crucial. It is necessary to develop, as major technologies for securing the coverage, radio frequency (RF) elements, antennas, novel waveforms having a better coverage than orthogonal frequency division multiplexing (OFDM), beamforming and massive multiple input multiple output (MIMO), full dimensional MIMO (FD-MIMO), array antennas, and multiantenna transmission technologies such as large-scale antennas. In addition, there has been ongoing discussion on new technologies for improving the coverage of terahertz-band signals, such as metamaterial-based lenses and antennas, orbital angular momentum (OAM), and reconfigurable intelligent surface (RIS).

[0005] Moreover, in order to improve the spectral efficiency and the overall network performances, the following technologies have been developed for 6G communication systems: a full-duplex technology for enabling an uplink transmission and a downlink transmission to simultaneously use the same frequency resource at the same time; a network technology for utilizing satellites, high-altitude platform stations (HAPS), and the like in an integrated manner; an improved network structure for supporting mobile base stations and the like and enabling network operation optimization and automation and the like; a dynamic spectrum sharing technology via collison avoidance based on a prediction of spectrum usage; an use of artificial intelligence (AI) in wireless communication for improvement of overall network operation by utilizing AI from a designing phase for developing 6G and internalizing end-to-end AI support functions; and a next-generation distributed computing technology for overcoming the limit of UE computing ability through reachable super-high-performance communication and computing resources (such as mobile edge computing (MEC), clouds, and the like) over the network. In addition, through designing new protocols to be used in 6G communication systems, developing mecahnisms for implementing a hardware-based security environment and safe use of data, and developing technologies for maintaining privacy, attempts to strengthen the connectivity between devices, optimize the network, promote softwarization of network entities, and increase the openness of wireless communications are continuing.

[0006] It is expected that research and development of 6G communication systems in hyper-connectivity, including person to machine (P2M) as well as machine to machine (M2M), will allow the next hyper-connected experience. Particularly, it is expected that services such as truly immersive extended reality (XR), high-fidelity mobile hologram, and digital replica could be provided through 6G communication systems. In addition, services such as remote surgery for security and reliability enhancement, industrial automation, and emergency response will be provided through the 6G communication system such that the technologies could be applied in various fields such as industry, medical care, automobiles, and home appliances.

[0007] The present invention has been made to address at least the above problems and / or disadvantages and to provide at least the advantages described below. Accordingly, an aspect of the present invention provides a method and apparatus for primary authentication using hybrid key exchange and hybrid encryption in communication networks.

[0008] In accordance with an aspect of the disclosure, a method performed by a user equipment is provided. The method includes generating (702) an ephemeral public key and an ephemeral private key based on an Elliptical Curve (EC) key generation technique; generating (704) a first ephemeral shared key based on the ephemeral private key and an Elliptical Curve (EC) based a home network public key; generating (706) a second ephemeral shared key and an encrypted shared key based on a Post-Quantum Cryptography (PQC) based on a public key associated with the home network; generating (708) an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key; generating (710) a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key; and transmitting (712) a registration request for registering the UE (101) with the home network (103) along with the ephemeral public key, the encrypted shared key, the cipher-text value, and the MAC-tag value.

[0009] In accordance with an aspect of the disclosure, a method performed by home network is provided. The method includes receiving, from the UE, a registration request, wherein the registration request comprises an ephemeral public key, an encrypted shared key, a cipher-text value, and a message authentication code (MAC) tag value; generating a first ephemeral shared key based at least on the ephemeral public key and an Elliptical Curve Cryptography (ECC) based public key associated with the home network (103); generating a second ephemeral shared key based on the encrypted shared key and a Post-Quantum Cryptography (PQC) based private key associated with the home network (103); generating an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key; generating an ephemeral decryption key and an ephemeral MAC key based at least on the ephemeral hybrid shared key; generating plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key; and register the UE (101) with the home network (103) based on the generated plaintext.

[0010] In accordance with an aspect of the disclosure, a user equipment is provided. The user equipmnet includes a transceiver; and a controller configured to generate an ephemeral public key and an ephemeral private key based on an Elliptical Curve (EC) key generation technique, generate a first ephemeral shared key based on the ephemeral private key and an Elliptical Curve (EC) based a home network public key, generate a second ephemeral shared key and an encrypted shared key based on a Post-Quantum Cryptography (PQC) based on a public key associated with the home network, generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key, generate a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key, and transmit a registration request for registering the UE (101) with the home network (103) along with the ephemeral public key, the encrypted shared key, the cipher-text value, and the MAC-tag value.

[0011] In accordance with an aspect of the disclosure, a home network is provided. The home network includes a transceiver; and a controller configured to receive, from the UE, a registration request, wherein the registration request comprises an ephemeral public key, an encrypted shared key, a cipher-text value, and a message authentication code (MAC) tag value, generate a first ephemeral shared key based at least on the ephemeral public key and an Elliptical Curve Cryptography (ECC) based public key associated with the home network (103), generate a second ephemeral shared key based on the encrypted shared key and a Post-Quantum Cryptography (PQC) based private key associated with the home network (103), generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key, generate an ephemeral decryption key and an ephemeral MAC key based at least on the ephemeral hybrid shared key, generate plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key, and register the UE (101) with the home network (103) based on the generated plaintext.

[0012] In an embodiment, the present disclosure provides shared key generation which is combined with legacy ECC algorithms and PQC algorithms and derive the shared key. This key performs SUPI concealment for primary authentication between UE and HN. Further, the present disclosure provides hybrid encryption method that allows minimal modification in current 3GPP specification to support hybrid security. As a result, the present disclosure protects against "store now decrypt later" attacks.

[0013] In an embodiment, the present disclosure generates a hybrid shared key which may be used for SUPI concealment. This shared key provides security against quantum threats with high-security assurance. This hybrid shared key may also be used for encrypting data between UE and network and not limited to SUPI.

[0014] Advantages, and salient features of the invention will become apparent to those skilled in the art from the following detailed description, which, taken in conjunction with the annexed drawings, discloses exemplary embodiments of the invention. For more enhanced communication system, there is a need for method and network for utilizing phase continuity for generating waveforms with low peak-to average power ratio.

[0015] The novel features and characteristics of the disclosure are set forth in the appended claims. The disclosure itself, however, as well as a preferred mode of use, further objectives, and advantages thereof, will best be understood by reference to the following detailed description of an illustrative embodiment when read in conjunction with the accompanying figures. One or more embodiments are now described, by way of example only, with reference to the accompanying figures wherein like reference numerals represent like elements and in which:

[0016] Figure 1A shows a format of SUCI, and scheme output as defined in prior art.

[0017] Figure 1B shows a flow diagram of Subscription Permanent Identifier (SUPI) concealment procedure at the UE based on Elliptical Curve based Integrated Encryption Scheme (ECIES) as per prior art.

[0018] Figure 1C shows a flow diagram of SUCI de-concealment procedure at HN 103 based on ECIES, as per prior art.

[0019] Figure 1D illustrates a complete sequence flow diagram of SUCI concealment and de-concealment procedure in brief, as per prior art.

[0020] Figure 2A illustrates an exemplary environment 200a in which a User Equipment (UE) 101 is registered with a Home network (HN) 103, in accordance with some embodiments of the present disclosure.

[0021] Figure 2B illustrates a detailed block diagram 200b of the UE 101 shown in Figure 1, in accordance with some embodiments of the present disclosure.

[0022] Figure 2C illustrates a detailed block diagram 200c of the HN 103 shown in Figure 1, in accordance with some embodiments of the present disclosure.

[0023] Figure 2D illustrates a detailed block diagram 200d of the UE 101 shown in Figure 1, in accordance with some embodiments of the present disclosure.

[0024] Figure 2E illustrates a detailed block diagram 200e of the HN 103 shown in Figure 1, in accordance with some embodiments of the present disclosure.

[0025] Figure 2F illustrates a flow diagram of hybrid SUPI concealment at UE 101 using legacy and PQC based shared key generation, in accordance with some embodiments of the present disclosure.

[0026] Figure 2G illustrates a block diagram of modified scheme output based on Hybrid SUPI concealment using legacy and PQC based shared key generation, in accordance with some embodiments of the present disclosure.

[0027] Figure 2H illustrates a flow diagram of hybrid SUCI deconcealment at UE 101 using legacy and PQC based shared key generation, in accordance with some embodiments of the present disclosure.

[0028] Figure 2I illustrates a sequence diagram of hybrid SUPI concealment and deconcealment using legacy and PQC based shared key generation in accordance with some embodiments of the present disclosure.

[0029] Figure 3A illustrates a flow diagram of hybrid SUPI concealment at the UE 101, using PQC and PQC based shared key generation in accordance with some embodiments of the present disclosure.

[0030] Figure 3B illustrates a block diagram of modified scheme output based on Hybrid SUPI concealment using PQC and PQC based shared key generation, in accordance with some embodiments of the present disclosure.

[0031] Figure 3C illustrates a flow diagram of hybrid SUCI deconcealment at the UE 101, using PQC and PQC based shared key generation in accordance with some embodiments of the present disclosure.

[0032] Figure 3D illustrates a sequence diagram of hybrid SUPI concealment and deconcealment using PQC and PQC based shared key generation, in accordance with some embodiments of the present disclosure.

[0033] Figure 4A illustrates a flow diagram of hybrid SUPI concealment at the UE 101, using legacy and PQC based shared key encryption, in accordance with some embodiments of the present disclosure.

[0034] Figure 4B illustrates a flow diagram of hybrid SUCI deconcealment at the UE 101, using legacy and PQC based shared key decryption, in accordance with some embodiments of the present disclosure.

[0035] Figure 4C illustrates a sequence diagram of hybrid SUPI concealment and deconcealment using legacy and PQC based shared key encryption and decryption, in accordance with some embodiments of the present disclosure.

[0036] Figure 5A illustrates a flow diagram of Hybrid SUPI concealment at UE 101, using PQC and PQC based encryption in parallel way, in accordance with some embodiments of the present disclosure.

[0037] Figure 5B illustrates a block diagram of modified scheme output based on Hybrid SUPI concealment using PQC and PQC based shared key encryption in a parallel way, in accordance with some embodiments of the present disclosure.

[0038] Figure 5C illustrates a flow diagram of hybrid SUCI deconcealment at HN 103, using PQC and PQC based decryption in parallel way. , in accordance with some embodiments of the present disclosure.

[0039] Figure 6A illustrates a flow diagram of hybrid SUPI concealment at UE 101, using PQC and PQC based encryption in a sequential way, in accordance with some embodiments of the present disclosure.

[0040] Figure 6B illustrates a block diagram of modified scheme output based on Hybrid SUPI concealment using PQC and PQC based encryption, in accordance with some embodiments of the present disclosure.

[0041] Figure 6C illustrates a flow diagram of Hybrid SUPI de-concealment at HN 103, using PQC and PQC based decryption in sequential way, in accordance with some embodiments of the present disclosure.

[0042] Figure 7A shows a flowchart illustrating a method 700a for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key exchange, in accordance with some embodiments of the present disclosure.

[0043] Figure 7B shows a flowchart illustrating a method 700b for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key exchange, in accordance with some embodiments of the present disclosure.

[0044] Figure 7C shows a flowchart illustrating a method 700c for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key exchange, in accordance with some embodiments of the present disclosure.

[0045] Figure 7D shows a flowchart illustrating a method 700d for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key exchange, in accordance with some embodiments of the present disclosure

[0046] Figure 8A shows a flowchart illustrating an alternative method 800a for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0047] Figure 8B shows a flowchart illustrating a method 800b for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0048] Figure 8C shows a flowchart illustrating a method 800c for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0049] Figure 8D shows a flowchart illustrating a method 800d for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0050] Figure 8E shows a flowchart illustrating a method 800e for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0051] Figure 8F shows a flowchart illustrating a method 800f for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0052] These and other aspects of the example embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating example embodiments and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications may be made within the scope of the example embodiments herein without departing from the spirit thereof, and the example embodiments herein include all such modifications.

[0053] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein may be practiced and to further enable those of skill in the art to practice the embodiments herein. Accordingly, the examples should not be construed as limiting the scope of the embodiments herein.

[0054] For the purposes of interpreting this specification, the definitions (as defined herein) will apply and whenever appropriate the terms used in singular will also include the plural and vice versa. It is to be understood that the terminology used herein is for the purposes of describing particular embodiments only and is not intended to be limiting. The terms "comprising", "having" and "including" are to be construed as open-ended terms unless otherwise noted.

[0055] The words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.," , "i.e.," are merely used herein to mean "serving as an example, instance, or illustration." Any embodiment or implementation of the present subject matter described herein using the words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.," , "i.e.," is not necessarily to be construed as preferred or advantageous over other embodiments.

[0056] Embodiments herein may be described and illustrated in terms of blocks which carry out a described function or functions. These blocks, which may be referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and may optionally be driven by a firmware. The circuits may, for example, be embodied in one or more semiconductor chips, or on substrate supports such as printed circuit boards and the like. The circuits constituting a block may be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments may be physically separated into two or more interacting and discrete blocks without departing from the scope of the disclosure. Likewise, the blocks of the embodiments may be physically combined into more complex blocks without departing from the scope of the disclosure.

[0057] It should be noted that elements in the drawings are illustrated for the purposes of this description and ease of understanding and may not have necessarily been drawn to scale. For example, the flowcharts / sequence diagrams illustrate the method in terms of the steps required for understanding of aspects of the embodiments as disclosed herein. Furthermore, in terms of the construction of the device, one or more components of the device may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the present embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein. Furthermore, in terms of the system, one or more components / modules which comprise the system may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the present embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.

[0058] The accompanying drawings are used to help easily understand various technical features and it should be understood that the embodiments presented herein are not limited by the accompanying drawings. As such, the present disclosure should be construed to extend to any modifications, equivalents, and substitutes in addition to those which are particularly set out in the accompanying drawings and the corresponding description. Usage of words such as first, second, third etc., to describe components / elements / steps is for the purposes of this description and should not be construed as sequential ordering / placement / occurrence unless specified otherwise.

[0059] It should be appreciated by those skilled in the art that any block diagram herein represents conceptual views of illustrative systems embodying the principles of the present subject matter. Similarly, it will be appreciated that any flow charts, flow diagrams, state transition diagrams, pseudo code, and the like represent various processes which may be represented in computer readable medium and executed by a computer or processor, whether or not such computer or processor is explicitly shown.

[0060] In the present document, the word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or implementation of the present subject matter described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments.

[0061] While the disclosure is susceptible to various modifications and alternative forms, specific embodiment thereof has been shown by way of example in the drawings and will be described in detail below. It should be understood, however that it is not intended to limit the disclosure to the particular forms disclosed, but on the contrary, the disclosure is to cover all modifications, equivalents, and alternatives falling within the scope of the disclosure.

[0062] The terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a setup, device, or method that comprises a list of components or steps does not include only those components or steps but may include other components or steps not expressly listed or inherent to such setup or device or method. In other words, one or more elements in a system or apparatus proceeded by "comprises쪋 a" does not, without more constraints, preclude the existence of other elements or additional elements in the system or apparatus.

[0063] In recent years, several broadband wireless technologies have been developed to meet growing number of broadband subscribers for providing better applications and services. A Second-generation (2G) wireless communication system has been developed to provide voice services while ensuring the mobility of users. Third generation (3G) wireless communication system supports not only the voice service, but also data service. In recent years, fourth generation (4G) wireless communication system has been developed to provide high-speed data service. However, currently, the 4G wireless communication systems suffer from a lack of resources to meet the growing demand for high-speed data services. This problem is solved by the deployment of fifth generation (5G) wireless communication system to meet the ever-growing demand for high-speed data services. Furthermore, the 5G wireless communication system provides ultra-reliability and supports low latency applications.

[0064] In 6G, quantum computer or machines will be widely used which can become a threat for current wireless security systems. A quantum computer is a computer which makes use of quantum-mechanical effects. These effects include superposition, which allows quantum bits (qubits) to exist in a combination of several states at once, and entanglement, which allows connections between separate quantum systems such that they cannot be described independently. There exist quantum algorithms that use these effects to solve certain cryptographic problems more efficiently than could be solved on a classical computer. Shor's quantum algorithm for integer factorization runs in polynomial time on a quantum computer. A variant of Shor's algorithm enables a quantum computer to calculate discrete logarithms in polynomial time, both over finite fields and elliptic curves. This variant renders several other public-key cryptosystems insecure, including Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH). To counter the threat of quantum computing to asymmetric cryptography, it is necessary to migrate to quantum-resistant algorithms also called as Post Quantum Cryptography (PQC) algorithms. Hence, there is a need for wireless communication networks including beyond Fifth Generation (5G), Sixth Generation (6G), to adapt to these PQC algorithms for enhanced security.

[0065] PQC algorithms involves multiple algorithms which are used for different purpose like key establishment, digital signature etc. Some of these algorithms are CRYSTALS-KYBER, BIKE, Classic McEliece, HQC and SIKE for key-establishment and CRYSTALS-Dilithium, FALCON and SPHINCS+ for Digital signatures which are post quantum secure.

[0066] In current system (for example, a 5G system) the globally unique 5G subscription permanent identifier is called SUPI as defined in 3GPP specification TS 23.501. The Subscription Concealed Identifier, (SUCI) is a privacy preserving identifier containing the concealed SUPI. As per the above-mentioned 3GPP specification TS 33.501, the SUPI is privacy protected over-the-air by using the SUCI. The UE shall generate a SUCI using a protection scheme with the raw public key, i.e., the Home Network Public Key that was securely provisioned in control of the home network.

[0067] The 5G uses legacy asymmetric crypto algorithm, which is not secure due to the development of quantum computing (QC) machine so there is need to adopt new post quantum cryptography algorithms in 6G. In case of 6G, devices may support both legacy asymmetric crypto algorithm and / or PQC algorithm. Different devices may have different requirements and support of cryptography algorithms may vary accordingly.

[0068] The current profiles (or protection schemes) exist only for non-PQC algorithms such as, Null scheme, the Elliptic Curve Integrated Encryption Scheme (ECIES) Profile A, ECIES Profile B, and the like. Null scheme based primary authentication is performed only when no security is required. ECIES Profile A and ECIES Profile B are based on elliptical curve cryptography (ECC) and are prone to Quantum attacks. These Profiles are configured in SIM (Subscriber Identity Module) during provisioning and there is no dynamic way of choosing various profiles. As described in below table, only highest priority profile in USIM elementary file 'EF SUCI_Calc_Info' needs to be selected by default for primary authentication (or) SUCI encryption as per 3GPP TS 31.102 specification. 3GPP has mentioned profile of protection schemes for concealing subscription permanent identifier in TS 33.501 specification, as iterated below.

[0069]

[0070] ECIES Profile A:

[0071] Subscriber Identity De-Concealing Function (SIDF) and Maintenance Entity (ME) shall implement this profile. The SIDF is a functional element of the UDM (Unified Data Management), responsible for decrypting a SUCI (Subscription Concealed Identifier) to reveal the subscriber's SUPI (Subscription Permanent Identifier). The ECIES parameters for this profile shall be the following:

[0072] - EC domain parameters : Curve25519

[0073] - EC Diffie-Hellman primitive : X25519

[0074] - point compression : N / A

[0075] - KDF : ANSI-X9.63-KDF

[0076] - Hash : SHA-256

[0077] - SharedInfo1 : (the ephemeral public key octet string)

[0078] - MAC : HMAC-SHA-256

[0079] - mackeylen : 32 octets (256 bits)

[0080] - maclen : 8 octets (64 bits)

[0081] - SharedInfo2 : the empty string

[0082] - ENC : AES-128 in CTR mode

[0083] - enckeylen : 16 octets (128 bits)

[0084] - icblen : 16 octets (128 bits)

[0085] - backwards compatibility mode : false

[0086] ECIES Profile B:

[0087] The ME and SIDF shall implement this profile. The ECIES parameters for this profile shall be

[0088] the following:

[0089] - EC domain parameters : secp256r1

[0090] - EC Diffie-Hellman primitive : Elliptic Curve Cofactor Diffie-Hellman Primitive

[0091] - point compression : true

[0092] - KDF : ANSI-X9.63-KDF

[0093] - Hash : SHA-256

[0094] - SharedInfo1 : (the ephemeral public key octet string)

[0095] - MAC : HMAC-SHA-256

[0096] - mackeylen : 32 octets (256 bits)

[0097] - maclen : 8 octets (64 bits)

[0098] - SharedInfo2 : the empty string

[0099] - ENC : AES-128 in CTR mode

[0100] - enckeylen : 16 octets (128 bits)

[0101] - icblen : 16 octets (128 bits)

[0102] - backwards compatibility mode: false

[0103] In 6G, both legacy as well as new crypto algorithms which can be based on quantum algorithms like Quantum key distribution or PQC will be applicable so in that case new Profiles need to be defined which can be used for protection schemes for concealing the subscription permanent identifier. In 5G systems, there are no protection scheme identifiers to support PQC algorithms for concealing of SUPI and de-concealing of SUCI. New PQC algorithm profiles proposed by National Institute of Standards and Technology (NIST) have new parameters, which need to be defined by 3GPP. Only ECIES profile A and B are defined in 33.501 (as reiterated above), which are not quantum safe. If the UE and the Home Network (HN) support different protection schemes, like UE support legacy and network support PQC profiles, the device may initiate registration with concealed SUCI created from legacy algorithms and network in response may reject the authentication and UE is not able to perform successful Registration due to authentication procedure failure which will further delay in registration procedure. Simialrly, if the UE and the Network support legacy protection schemes, the device may initiate registration with concealed SUCI created from legacy algorithms and attackers can use quantum machines to break the legacy algorithms like ECIES (using Elliptical curve cryptography) and decode SUCI to extract IMSI (international mobile subscriber identity). This IMSI if used by attackers to extract user information like location etc. and therefore is highly security vulnerable.

[0104] Figure 1A shows a format of SUCI, and scheme output as defined in prior art. As illustrated in Figure 1A, the SUCI is a privacy preserving identifier containing the concealed SUPI, defined in TS 33.501. The SUCI is composed of SUPI type, Home Network Identifier, Routing Indicator (RI), Protection Scheme Identifier (PSI), Home Network Public Key Identifier, and Scheme Output (SO). The 'SUPI Type' is used to identify the type of identifier. The value of SUPI type is between 0-7; for example, in case of type IMSI, a value '0' is used and while in case of Network Specific Identifier type, a value '1' is used. The HNPKI is used to identify the HN of the subscriber; for e.g., in case of SUPI of type IMSI, the HNPKI comprises of Mobile Country Code (MCC) and Mobile Network Code (MNC). The RI comprises of 1 to 4 decimal digits assigned by the HN operator. The PSI comprises a value in the range of 0 to 15, and it is used to specify which encryption profile should be used to conceal the SUPI. The HNPKI comprises a value in the range 0 to 255, and it represents a public key provisioned by the Home Public Land Mobile Network (HPLMN) or Stand-alone Non-Public Network (SNPN) and it is used to identify the key used for SUPI protection. Further, the SO may comprise a string of characters with a variable length or hexadecimal digits, and it is dependent on the used protection scheme. For e.g., in case of encryption Profile-A, the SO comprises of UE ephemeral public key, ciphertext and mac-tag value.

[0105] In 5G, the SUPI Concealment and SUCI De-concealment is performed according to Elliptical Curve based Integrated Encryption Scheme (ECIES) at the UE and the HN, respectively. The ECIES allows the UE to encrypt the subscription identifier with the help of elliptical curve-based cryptography, symmetric key cryptography and hashing operation. The ECIES performs the encryption on basis of protection scheme profile. Further, during SIM provisioning, the HN shares a protection scheme profile to the UE. These profiles are defined in TS 33.501. Further, the profiles include various configuration parameters for the ECIES scheme. Overall, ECIES allows two parties to establish and to exchange secure information over an insecure channel. the ECIES scheme comprises of five different steps; a Key Generation, a Key Agreement, a Key Derivation, a Symmetric Key Encryption, and a Hash-based Message Authentication Code (HMAC) function.

[0106] Figure 1B shows a flow diagram of Subscription Permanent Identifier (SUPI) concealment procedure at the UE based on Elliptical Curve based Integrated Encryption Scheme (ECIES) as per prior art. In step 1, according to the protection scheme profiles, the UE generates a Public / Private key pair using elliptical curve cryptography. Further, in step 2, the UE uses its own ephemeral private key and provisions the HN public key to derive a shared key using Elliptical Curve based Diffie Hellman (ECDH) key agreement operation. The ECDH key agreement allows both party to derive the same shared key, using each other's public share and own private secret. Further, in step 3, after generating the shared secret, the UE uses a key derivation function to derive multiple keys from the shared key. The Key Derivation Function, ANSI-X9.63-KDF is used for deriving multiple keys out of shared secret key. In SUPI concealment case, the UE generates the ICB (Initial Control Block), MAC key and Advanced Encryption Standard (AES) encryption key using the KDF. In step 4, the UE finally performs the concealment of SUPI using the symmetric key encryption algorithm AES, and generates a concealed value of SUPI. In step 5, the UE uses a Hash-based Message Authentication Code (HMAC) function to ensure integrity protection for the generated concealed SUPI. The HMAC generates a mac-tag of concealed SUPI using derived mac-key. The aforementioned steps can be used for SUPI concealment. Out of these five operations, the key generation and key agreement are based on elliptical curves based public key cryptography. Post concealment of SUPI, the UE sends the SUCI to the HN 103.

[0107] Figure 1C shows a flow diagram of SUCI de-concealment procedure at HN 103 based on ECIES, as per prior art. As shown in Figure 1C, in SUCI de-concealment, the HN 103 uses its private key and the UE ephemeral public key to derive a shared key. Subsequently, similar to SUPI Concealment, the HN 103 uses key derivation function to derive multiple keys from shared key. In SUCI de-concealment case, the HN 103 generates ICB (Initial Control Block), MAC key and AES de-encryption key using the KDF. Further, in the next step, the HN 103 performs the de-concealment of SUCI using symmetric key decryption and validates integrity protection using HMAC function. Similarly, SUPI concealment and the SUCI de-concealment also relies on elliptical curve based cryptography.

[0108] Figure 1D illustrates a complete sequence flow diagram of SUCI concealment and de-concealment procedure in brief, as per prior art. As illustrated in Figure 1D, initially, at step 1(S1) the HN 103 provisions the UE 101 with its public key. Further, when the UE 101 wants to initiate SUPI concealment, it performs public / private key generation as indicated in step 2 (S2), shared secret as indicated in step 3 (S3), and multiple other key generation as indicated in step (S4). Later, it uses AES encryption and HMAC function to encrypt the SUPI and mac-tag generation as indicated in step (S5). These steps are the part of SUPI concealment. After completion of SUPI concealment, the UE 101 creates the Scheme Output, which includes UE Public Key, Cipher-text, and Mac-Tag. Here cipher-text comprises a concealed SUPI and mac-tag consist mac of the concealed SUPI. The scheme output is transferred from the UE 101 to the HN 103 as a part of the SUCI packet as indicated in step 6 (S6). Post receiving the SUCI, the HN 103 initiates the SUCI deconcealment procedure. Further, the HN 103 generates shared secret using key agreement and multiple key generation using the KDF as indicated in step 7(S7). Later, HN 103 validates the integrity of concealed SUPI using HMAC function and finishes SUCI deconcealment with AES decryption function. Both, SUPI concealment and SUCI deconcealment rely on elliptical curve based cryptography.

[0109] The current SUPI concealment and SUCI concealment procedure are based on ECIES based encryption scheme, which is not quantum resistant. Overall, the ECIES includes total five steps as discussed above. Out of these five steps, two steps (key generation and key agreement) are based on elliptical curve-based primitives. As these elliptical curve cryptography rely on the premise of logarithmic hard problem, which can be solved easily using quantum machines. Relying on elliptical curve for key agreement make the entire SUPI concealment and de-concealment insecure. Similarly, SUPI de-concealment (which also uses ECIES) has elliptical curve based key agreement also not secure against quantum threat.

[0110] In order to prevent quantum threat, there is a need to replace classical (quantum unsafe) algorithms to quantum safe algorithms in 6G. The primary authentication procedure needs to be defined based on new algorithms like PQC, Quantum Key Distribution (QKD) that are quantum safe. These PQC algorithms are designed and evaluated for enabling security guarantees against quantum threat. Although, the scope of testing, evaluations, and maturity of these algorithms are not well established like classical algorithm. Thus, a simple adoption of PQC algorithm for primary authentication is not sufficient to enable a highly reliable security assurance. There is a need for Hybrid solutions for primary authentication in 6G, specifically for SUPI concealment and de-concealment.

[0111] In 6G, the primary authentication procedure needs to be defined based on hybrid solution which use a combination of new algorithms like PQC, QKD that is quantum safe, and legacy algorithms, which is well tested, established in current system. There is a need to define new mechanisms for hybrid shared key generation, which may use both legacy methods and PQC methods for shared key generation. There is also a need to define hybrid encryption, which may use a combination of legacy encryption and PQC based encryption for any identifier like SUPI or any other equivalent identifier between the UE 101 and the network for high security assurance.

[0112] The information disclosed in this background of the disclosure section is only for enhancement of understanding of the general background of the invention and should not be taken as an acknowledgement or any form of suggestion that this information forms the prior art already known to a person skilled in the art.

[0113] In an embodiment, the present disclosure discloses a method for registering a User Equipment (UE) with a Home Network (HN) using hybrid key exchange, the method comprises generating an ephemeral public key and an ephemeral private key based on an Elliptical Curve (EC) key generation technique and generating a first ephemeral shared key based on the ephemeral private key and an Elliptical Curve (EC) based home network public key. Further, the method comprises generating a second ephemeral shared key and an encrypted shared key based on a Post-Quantum Cryptography (PQC) based public key associated with the home network. Furthermore, the method comprises generating an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. Thereafter, the method comprises generating a cipher-text value and a Message Authentication Code (MAC) tag value based at least on the ephemeral hybrid shared key. Finally, the method comprises transmitting a registration request for registering the UE with the home network along with the ephemeral public key, the encrypted shared key, the cipher-text value, and the MAC-tag value.

[0114] In an embodiment, the present disclosure discloses a method for registering a User Equipment (UE) with a Home Network (HN) using hybrid key exchange, the method comprises receiving a registration request from the UE, wherein the registration request comprises an ephemeral public key, an encrypted shared key, a cipher-text value, and a message authentication code (MAC) tag value and generating a first ephemeral shared key based at least on the ephemeral public key and an Elliptical Curve Cryptography (ECC) based public key associated with the home network. Further, the method comprises generating a second ephemeral shared key based on the encrypted shared key and a Post-Quantum Cryptography (PQC) based private key associated with the home network. Furthermore, the method comprises generating an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. Thereafter, the method comprises generating an ephemeral decryption key and an ephemeral MAC key based at least on the ephemeral hybrid shared key. Finally, the method comprises generating plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key and registering the UE with the home network based on the generated plaintext.

[0115] In an embodiment, the present disclosure discloses a method for registering a User Equipment (UE) with a Home Network (HN) using hybrid key exchange, the method comprises generating a first ephemeral shared key and a first encrypted shared key based on a first Post-Quantum Cryptography (PQC) based home network public key and generating a second ephemeral shared key and a second encrypted shared key based on a second PQC based home network public key. Further, the method comprises generating an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. Furthermore, the method comprises generating a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key. Finally, the method comprises transmitting a registration request for registering the UE with the home network along with the first encrypted shared key, the second encrypted shared key, the cipher-text value, and the MAC-tag value.

[0116] In an embodiment, the present disclosure discloses a method for registering a User Equipment (UE) with a Home Network (HN) using hybrid key exchange, the method comprises receiving a registration request from the UE, wherein the registration request comprises a first encrypted shared key, a second encrypted shared key, a cipher-text value and a message authentication code (MAC) tag value and generating a first ephemeral shared key based on the first encrypted shared key and a first Post-Quantum Cryptography (PQC) based private key associated with the home network. Further, the method comprises generating a second ephemeral shared key based on the second encrypted shared key and a second PQC based private key associated with the home network. Furthermore, the method comprises generating an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. Thereafter, the method comprises generating plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key. Finally, the method comprises generating plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key and registering the UE with the home network based on the generated plaintext.

[0117] In an embodiment, the present disclosure discloses a method for registering a User Equipment (UE) with a Home Network (HN) using hybrid key encryption, the method comprises generating an ephemeral public key and an ephemeral private key based at least on Elliptical Curve (EC) key generation technique and generating an ephemeral shared key based on the ephemeral private key and an EC based home network public key. Further, the method comprises generating an ephemeral encryption key and an ephemeral message authentication code (MAC) key based at least on ephemeral hybrid shared key. Furthermore, the method comprises generating an intermediate cipher-text value by performing symmetric encryption of a plaintext based on the ephemeral encrypted key. Thereafter, the method comprises generating a cipher text value based on the intermediate cipher-text value and a Post-Quantum Cryptography (PQC) based home network public key. Finally, the method comprises generating a MAC tag value based at least on the cipher text value and the ephemeral MAC-tag key and transmitting a registration request for registering the UE with the home network along with the ephemeral public key, the cipher-text value, and the MAC-tag value.

[0118] In an embodiment, the present disclosure discloses a method for registering a User Equipment (UE) with a Home Network (HN) using hybrid key encryption, the method comprises receiving a registration request from the UE, wherein the registration request comprises an ephemeral public key, a cipher-text value and a message authentication code (MAC) tag value and generating an ephemeral shared key based on the ephemeral public key and an Elliptical Curve (EC) based private key associated with the home network. Further, the method comprises generating an ephemeral decryption key and an ephemeral MAC key based on the ephemeral shared key. Furthermore, the method comprises generating an intermediate cipher text value by applying Post-Quantum Cryptography (PQC) decryption on the cipher-text value based on a PQC based home network public key. Thereafter, the method comprises generating a plaintext by performing a symmetric decryption of the intermediate cipher-text value based at least on the ephemeral decrypted key. Finally, the method comprises generating plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key and registering the UE with the home network based on the generated plaintext.

[0119] In an embodiment, the present disclosure discloses a method for registering a User Equipment (UE) with a Home Network (HN) using hybrid key encryption, the method comprises splitting a plaintext into a first part and a second part. Further, the method comprises generating a first cipher-text value based on a first Post-Quantum Cryptography (PQC) based public key associated with the home network. Thereafter, the method comprises generating a second cipher-text value based on a second PQC based public key associated with the home network. Finally, the method comprises transmitting a registration request for registering the UE with the home network along with the first cipher-text value and the second cipher-text value.

[0120] In an embodiment, the present disclosure discloses a method for registering a User Equipment (UE) with a Home Network (HN) using hybrid key encryption, the method comprises receiving a registration request from the UE, wherein the registration request comprises a first cipher-text value and a second cipher-text value and generating a first part of a plaintext by decrypting the first cipher-text value based on a first Post-Quantum Cryptography (PQC) private key associated with the home network. Further, the method comprises generating a second part of the plaintext by decrypting the second cipher-text value based on a second PQC private key associated with the home network. Thereafter, the method comprises generating the plaintext by combining the first part and the second part of the plaintext. Finally, the method comprises registering the UE with the home network based on the generated plaintext.

[0121] In an embodiment, the present disclosure discloses a method for registering a User Equipment (UE) with a Home Network (HN) using hybrid key encryption, the method comprises generating an intermediate cipher-text value based on a first Post-Quantum Cryptography (PQC) based home network public key and a plain text. Further, the method comprises generating a cipher text value based on the intermediate cipher-text value and a second PQC based home network public key. Finally, the method comprises transmitting a registration request along with the cipher-text value to the UE for registering the UE with the home network.

[0122] In an embodiment, the present disclosure discloses a method for registering a User Equipment (UE) with a Home Network (HN) using hybrid key encryption, the method comprises receiving a registration request, wherein the registration request comprises a cipher-text value. Further, the method comprises generating an intermediate cipher-text value based on the cipher text-value and a second PQC based home network private key. Thereafter, the method comprises generating a plain text based on the intermediate cipher text value and a first PQC based home network private key. Finally, the method comprises registering the UE with the home network based on the generated plaintext.

[0123] In an embodiment, the present disclosure discloses a User Equipment (UE) to register with a Home Network. The UE comprises a processor and a memory. The processor is communicatively coupled with the memory and configured to generate an ephemeral public key and an ephemeral private key based on an Elliptical Curve (EC) key generation technique and generate a first ephemeral shared key based on the ephemeral private key and an Elliptical Curve (EC) based home network public key. Further, the processor is configured to generate a second ephemeral shared key and an encrypted shared key based on a Post-Quantum Cryptography (PQC) based public key associated with the home network. Furthermore, the processor is configured to generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. Thereafter, the processor is configured to generate a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key. Finally, the processor is configured to transmit a registration request for registering the UE with the home network along with the ephemeral public key, the encrypted shared key, the cipher-text value, and the MAC-tag value.

[0124] In an embodiment, the present disclosure discloses a User Equipment (UE) to register with a Home Network. The UE comprises a processor and a memory. The processor is communicatively coupled with the memory and configured to receive a registration request from the UE, wherein the registration request comprises an ephemeral public key, an encrypted shared key, a cipher-text value, and a message authentication code (MAC) tag value and generate a first ephemeral shared key based at least on the ephemeral public key and an Elliptical Curve Cryptography (ECC) based public key associated with the home network. Further, the processor is configured to generate a second ephemeral shared key based on the encrypted shared key and a Post-Quantum Cryptography (PQC) based private key associated with the home network. Furthermore, the processor is configured to generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. Thereafter, the processor is configured to generate an ephemeral decryption key and an ephemeral MAC key based at least on the ephemeral hybrid shared key y. Finally, the processor is configured to generate plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key and register the UE with the home network based on the generated plaintext.

[0125] In an embodiment, the present disclosure discloses a User Equipment (UE) to register with a Home Network. The UE comprises a processor and a memory. The processor is communicatively coupled with the memory and configured to generate a first ephemeral shared key and a first encrypted shared key based on a first Post-Quantum Cryptography (PQC) based home network public key and generate a second ephemeral shared key and a second encrypted shared key based on a second PQC based home network public key. Further, the processor is configured to generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. Thereafter, the processor is configured to generate a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key. Finally, the processor is configured to transmit a registration request for registering the UE with the home network along with the first encrypted shared key, the second encrypted shared key, the cipher-text value, and the MAC-tag value.

[0126] In an embodiment, the present disclosure discloses a User Equipment (UE) to register with a Home Network. The UE comprises a processor and a memory. The processor is communicatively coupled with the memory and configured to receive a registration request from the UE, wherein the registration request comprises a first encrypted shared key, a second encrypted shared key, a cipher-text value, and a message authentication code (MAC) tag value and generate a first ephemeral shared key based on the first encrypted shared key and a first Post-Quantum Cryptography (PQC) based private key associated with the home network. Further, the processor is configured to generate a second ephemeral shared key based on the second encrypted shared key and a second PQC based private key associated with the home network. Furthermore, the processor is configured to generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. Thereafter, the processor is configured to generate an ephemeral decryption key and an ephemeral MAC key based at least on ephemeral hybrid shared key. Finally, the processor is configured to generate plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key and register the UE with the home network based on the generated plaintext.

[0127] In an embodiment, the present disclosure discloses a User Equipment (UE) to register with a Home Network. The UE comprises a processor and a memory. The processor is communicatively coupled with the memory and configured to generate an ephemeral public key and an ephemeral private key based at least on Elliptical Curve (EC) key generation technique and generate an ephemeral shared key based on the ephemeral private key and an EC based home network public key. Further, the processor is configured to generate an ephemeral encryption key and an ephemeral message authentication code (MAC) key based at least on ephemeral hybrid shared key. Furthermore, the processor is configured to generate an intermediate cipher-text value by performing symmetric encryption of a plaintext based on the ephemeral encrypted key. Thereafter, the processor is configured to generate a cipher text value based on the intermediate cipher-text value and a Post-Quantum Cryptography (PQC) based home network public key. Finally, the processor is configured to generate a MAC tag value based at least on the cipher text value and the ephemeral MAC-tag key and transmit a registration request for registering the UE with the home network along with the ephemeral public key, the cipher-text value, and the MAC-tag value.

[0128] In an embodiment, the present disclosure discloses a User Equipment (UE) to register with a Home Network. The UE comprises a processor and a memory. The processor is communicatively coupled with the memory and configured to receive a registration request from the UE, wherein the registration request comprises an ephemeral public key, a cipher-text value, and a message authentication code (MAC) tag value and generate an ephemeral shared key based on the ephemeral public key and an Elliptical Curve (EC) based private key associated with the home network. Further, the processor is configured to generate an ephemeral decryption key and an ephemeral MAC key based on the ephemeral shared key. Furthermore, the processor is configured to generate an intermediate cipher text value by applying Post-Quantum Cryptography (PQC) decryption on the cipher-text value based on a PQC based home network public key. Thereafter, the processor is configured to generate a plaintext by performing a symmetric decryption of the intermediate cipher-text value based at least on the ephemeral decrypted key. Finally, the processor is configured to register the UE with the home network based on the generated plaintext.

[0129] In an embodiment, the present disclosure discloses a User Equipment (UE) to register with a Home Network. The UE comprises a processor and a memory. The processor is communicatively coupled with the memory and configured to generate a first cipher-text value based on a first Post-Quantum Cryptography (PQC) based public key associated with the home network. Thereafter, the processor is configured to generate a second cipher-text value based on a second PQC based public key associated with the home network. Finally, the processor is configured to transmit a registration request for registering the UE with the home network along with the first cipher-text value and the second cipher-text value.

[0130] In an embodiment, the present disclosure discloses a User Equipment (UE) to register with a Home Network. The UE comprises a processor and a memory. The processor is communicatively coupled with the memory and configured to receive a registration request from the UE, wherein the registration request comprises a first cipher-text value and a second cipher-text value. Further, the processor is configured to generate a first part of a plaintext by decrypting the first cipher-text value based on a first Post-Quantum Cryptography (PQC) private key associated with the home network. Furthermore, the processor is configured to generate a second part of the plaintext by decrypting the second cipher-text value based on a second PQC private key associated with the home network. Thereafter, the processor is configured to generate the plaintext by combining the first part and the second part of the plaintext. Finally, the processor is configured to register the UE with the home network based on the generated plaintext.

[0131] In an embodiment, the present disclosure discloses a User Equipment (UE) to register with a Home Network. The UE comprises a processor and a memory. The processor is communicatively coupled with the memory and configured to generate an intermediate cipher-text value based on a first Post-Quantum Cryptography (PQC) based home network public key and a plain text.. Thereafter, the processor is configured to generate a cipher text value based on the intermediate cipher-text value and a second PQC based home network public key. Finally, the processor is configured to transmit a registration request along with the cipher-text value to the UE for registering the UE with the home network.

[0132] In an embodiment, the present disclosure discloses a User Equipment (UE) to register with a Home Network. The UE comprises a processor and a memory. The processor is communicatively coupled with the memory and configured to receive a registration request, wherein the registration request comprises a cipher-text value. Further, the processor is configured to generate an intermediate cipher-text value based on the cipher text-value and a second PQC based home network private key. Thereafter, the processor is configured to generate a plain text based on the intermediate cipher text value and a first PQC based home network private key. Finally, the processor is configured to register the UE with the home network based on the generated plaintext.

[0133] The foregoing summary is illustrative only and is not intended to be in any way limiting. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features will become apparent by reference to the drawings and the following detailed description.

[0134] In an embodiment, a first step to adapt post quantum algorithms to 3GPP is to create profiles for each algorithm containing parameter configuration needed for that particular algorithm. As 3GPP relies on NIST for new algorithms, this creation of PQC profiles with various parameters could be according to NIST standardized PQC algorithms. Created PQC profiles can be utilized for multiple purposes in maintaining UE security like primary authentication of subscriber data, securing from false base stations, and the like. PQC based profiles can be designed with various possibilities or structures like including level of security, key length, and the like. In an embodiment, it may also include hybrid profiles, which combines PQC profiles with legacy profiles for providing enhanced security. Such methodologies in creating PQC profiles for ease of access and enhanced security have been explained in detail below.

[0135] In an aspect of the present invention, new protection scheme identifiers may be added to support PQC algorithms which are reserved for future use. Key changes to profiles may be first, removal of required elliptical curve related parameters as key encryption-based algorithms of PQC can be used for SUPI concealing. Secondly, SharedInfo1 parameter may be encrypted shared key octet string as output by the key encapsulation function of PQC algorithm. Thirdly, since AES-128 (CTR) is prone to Quantum attacks, AES-256 or its variant may be used for symmetric encryption.

[0136] If the UE and the Network support PQC protection schemes, UE may initiate registration to network with concealed SUCI created from PQC algorithms, as PQC profile exists in device or SIM or e-SIM as per proposed solution and network in response will accept the authentication and UE will be able to perform successful Registration without any further delay in registration procedure. Also, if the UE and the Network support PQC protection schemes, the device may initiate registration with concealed SUCI created from PQC algorithms, as per proposed solution, and attackers cannot use quantum machines to break the PQC algorithms to decode SUCI as PQC algorithms are quantum safe. Therefore, IMSI cannot be extracted by attackers and user information like location etc. are secured.

[0137] Further, multiple ways or options of creating these PQC based profiles exists, and multiple embodiments for the same are being described herein. In an embodiment, a common profile for each PQC algorithm is created. Herein, each algorithm may have a protection scheme identifier and level of security that may be separated out from profile parameters and maintained separately. According to the algorithm selected and based on level of security, various parameters of SUPI concealment / SUCI de-concealment may be decided. This level of security may be part of Universal Subscriber Identity Module (USIM) / any access network message indication / core network message indication. Each PQC algorithm may have one common profile created irrespective of level of security. All NIST standardized PQC algorithms for Key encapsulation and digital signature may be part of protection schemes. Therefore, though initial purpose is using key encapsulation mechanism for primary authentication, both key encapsulation and digital signature algorithms defined here can be utilized for different purposes later.

[0138] Following modification may be required to incorporate in 3GPP TS 33.501 standard specification in Annex C: Protection schemes for concealing the subscription permanent identifier:

[0139] 0x0: Null-Scheme Size of input, i.e., size of username used in case of Network Access Identifier (NAI) format or Mobile Subscriber Identification Number (MSIN) in case of IMSI

[0140] 0x1: ECIES Profile Total of 256-bit public key, 64-bit MAC, plus size of input.

[0141] 0x2: ECIES Profile Total of 264-bit public key, 64-bit MAC, plus size of input.

[0142] 0x3: KYBER Total of 768 / 1088 / 1568 byte ciphered shared key, 64-bit MAC, plus size of input

[0143] 0x4: BIKE Total of 1572 / 3114 byte ciphered shared key, 64-bit MAC, plus size of input

[0144] 0x5: Classic McEliece Total of 128 / 188 / 240 byte ciphered shared key, 64-bit MAC, plus size of input

[0145] 0x6: HQC Total of 4481 / 9026 / 14469 byte ciphered shared key, 64-bit MAC, plus size of input

[0146] 0x7: SIKE Total of 346 / 486 / 596 byte ciphered shared key, 64-bit MAC, plus size of input

[0147] 0x8: Dilithium NIST standardised Digital Signature based algorithm

[0148] 0x9: FALCOM NIST standardised Digital Signature based algorithm

[0149] 0xA: SPHINCS+ NIST standardised Digital Signature based algorithm.

[0150] The values 0xB are reserved for future standardized protection schemes. The values 0xC - 0xF are reserved for proprietary protection schemes specified by the home operator.

[0151] Following modification may be required to incorporate in 3GPP TS 33.501 standard specification in Annex C: New section for PQC profiles needs to be created like ECIES.

[0152] C.X.X PQC Profiles

[0153] Unless otherwise stated, the PQC profiles follow the terminology and processing specified in selected NIST PQC algorithms documentation.

[0154] - For generating successive counter blocks from the initial counter block (ICB) in CTR mode, the profiles shall use the standard incrementing function in section B.1 of NIST Special Publication 800-38A with m = 32 bits. The ICB corresponds to T1 in section 6.5. AES-128 in CTR mode or AES-256 (with or without CTR) are preferred. AES-256 is required if need to maintain 256 bit security.

[0155] - The value of the MAC tag in PQC profile, shall be the L most significant octets of the output generated by the HMAC function, where L equals to the maclen.

[0156] - PQC profile use its own standardized processing for key generation (PQC KEM algorithm Key generation process) and shared secret calculation (PQC KEM algorithm shared Key generation).

[0157] - The shared secret output octet string from PQC KEM algorithm shall be used as the input in the KDF.

[0158] A common profile for Kyber algorithm may be provisioned as mentioned in Table 1.A and can include various parameters fixed according to level of security 1, 3, 5 like in Table 1.B.

[0159]

[0160]

[0161] A common profile for BIKE (Bit Flipping Key Encapsulation) algorithm may be provisioned as mentioned in Table 2.A and can include various parameters fixed according to level of security 1, 3, 5 like in Table 2.B.

[0162]

[0163]

[0164] A common profile for Hamming Quasi-Cyclic (HQC) algorithm may be provisioned as mentioned in Table 3.A and can include various parameters fixed according to level of security 1, 3, 5 like in Table 3. B.

[0165]

[0166]

[0167] A common profile for Classic McEliece algorithm may be provisioned as mentioned in Table 4. A, and can include various parameters fixed according to level of security 1, 3, 5 like in Table 4. B.

[0168]

[0169]

[0170] In another embodiment, individual profiles may be created for each level of PQC algorithm. Herein, each algorithm along with a level of security creates a profile or a protection scheme identifier together. According to the algorithm selected, various parameters of SUPI concealment / SUCI de-concealment can be fixed as level of security is already in creation of the protection scheme. Therefore, each PQC algorithm may include one individual profile created for each level of security. In an embodiment, all NIST standardized PQC algorithms for key encapsulation and digital signature may be part of protection schemes. Therefore, though initial purpose is using key encapsulation mechanism for primary authentication, both key encapsulation and digital signature algorithms defined here may be utilized for different purpose later. In an embodiment, some of the NIST 4th round candidate algorithms may also be standardized.

[0171] In an embodiment, following modifications may be required to incorporate in 3GPP standard specification: Protection schemes for concealing the subscription permanent identifier:

[0172] 0x0: Null-Scheme Size of input, i.e., size of username used in case of NAI format or MSIN in case of IMSI

[0173] 0x1: ECIES Profile Total of 256-bit public key, 64-bit MAC, plus size of input.

[0174] 0x2: ECIES Profile Total of 264-bit public key, 64-bit MAC, plus size of input.

[0175] 0x3: KYBER512 Total of 768 byte ciphered shared key, 64-bit MAC, plus size of input

[0176] 0x4: KYBER768 Total of 1088 byte ciphered shared key, 64-bit MAC, plus size of input

[0177] 0x5: KYBER1024 Total of 1568 byte ciphered shared key, 64-bit MAC, plus size of input

[0178] 0xX: McEliece348864 Total of 128 byte ciphered shared key, 64-bit MAC, plus size of input

[0179] 0xX: McEliece460896 Total of 188 byte ciphered shared key, 64-bit MAC, plus size of input

[0180] 0xX: McEliece6688128 Total of 240 byte ciphered shared key, 64-bit MAC, plus size of input

[0181] 0xX: BIKE1 Total of 1572 byte ciphered shared key, 64-bit MAC, plus size of input

[0182] 0xX: BIKE3 Total of 3114 byte ciphered shared key, 64-bit MAC, plus size of input

[0183] 0xX: HQC-128 Total of 4481 byte ciphered shared key, 64-bit MAC, plus size of input

[0184] 0xX: HQC-192 Total of 9026 byte ciphered shared key, 64-bit MAC, plus size of input

[0185] 0xX: HQC-256 Total of 14469 byte ciphered shared key, 64-bit MAC, plus size of input

[0186] 0xX: SIKEp434 Total of 346 byte ciphered shared key, 64-bit MAC, plus size of input

[0187] 0xX: SIKEp610 Total of 486 byte ciphered shared key, 64-bit MAC, plus size of input

[0188] 0xX: SIKEp751 Total of 596 byte ciphered shared key, 64-bit MAC, plus size of input

[0189] 0xX: Dilithium NIST standardised Digital Signature based algorithm

[0190] 0xX: FALCOM NIST standardised Digital Signature based algorithm

[0191] 0xX: SPHINCS+ NIST standardised Digital Signature based algorithm.

[0192] The values 0xC - 0xF are reserved for proprietary protection schemes specified by the home operator.

[0193] Further, a profile for Kyber algorithm can be provisioned as mentioned in Table 5 for Kyber 512 with security level 1, Table 6 for Kyber 768 with security level 3 and Table 7 for Kyber 1024 with security level 5.

[0194]

[0195]

[0196]

[0197] Further, a profile for Kyber algorithm can be provisioned as mentioned in Table 8 for BIKE with security level 1, Table 9 for BIKE with security level 3 and Table 10 for BIKE with security level 5.

[0198]

[0199]

[0200]

[0201] Further, a profile for HQC algorithm can be provisioned as mentioned in Table 11 for HQC-128 with security level 1, Table 12 for HQC-192 with security level 3 and Table 13 for HQC-256 with security level 5.

[0202]

[0203]

[0204]

[0205] Further, a profile for Classic Mc-Eliece algorithm can be provisioned as mentioned in Table 14 for Mc-Eliecer with security level 1, Table 15 for Mc-Eliece with security level 3 , Table 16 for Mc-Eliece with security level 5 Profile configuration 1, Table 17 for Mc-Eliece with security level 5 Profile configuration 2 and Table 18 for Mc-Eliece with security level 5 Profile configuration 3.

[0206]

[0207]

[0208]

[0209]

[0210]

[0211] In another aspect of the present invention, new protection scheme identifiers based on NIST proposed PQC algorithms may also be hybrid, like a combination of two different algorithms. Similar to hybrid key exchange in TLS (Transport Layer security), 3GPP can also adopt such methodologies to combine two algorithms for enhanced security protection and to support fall-back mechanisms when one of the two algorithms get broken in future. Also, Shared key of one algorithm can be concatenated with another algorithm to form a combined shared key for hybrid algorithm. These new hybrid protection scheme identifiers may be added to support PQC algorithms which are reserved for future use in 33.501 Annex C.

[0212] In an embodiment, there can be four such options in creation of PQC based scheme identifiers or profiles.

[0213] Option 1: Legacy + PQC KEM Profile

[0214] Option 2: PQC KEM + PQC KEM Profile

[0215] Option 3: PQC KEM + PQC Digital Signature Profile

[0216] Option 4: Legacy + PQC Digital Signature Profile.

[0217] In all above options, level of security of PQC based scheme identifier can be part of profile or separated from profile as mentioned above.

[0218] In an embodiment, a combination of legacy and PQC KEM based profile may be created. Herein, a hybrid profile, which is a combination of elliptical curve cryptography (ECC) and PQC algorithms, may also be created as new profile which can enhance security and act as fall-back mechanism in case of PQC based algorithms tend to break in future for any reason. One algorithm may be of legacy type, i.e., elliptical curve based protection scheme identifier, and another may be Post Quantum KEM based scheme identifier. Elliptical curve based protection schemes may be according to 3GPP 33.501 i.e., ECIES Profile A or ECIES Profile B. All NIST standardized PQC algorithms for key encapsulation may be part of PQC based protection schemes. In an embodiment, some of the NIST 4th round candidate algorithms may also be standardized.

[0219] This mode of approach is required as an important step towards evolution of PQC, which provisions use of classic standardized cryptographic algorithm combined with a post-quantum algorithms, helping in crypto agility i.e., transitioning smoothly from legacy to PQC. Since NIST standardized PQC algorithms are tested for minimal duration, in case if any PQC algorithm is broken, the algorithm security strength can be fall-back to legacy (ECIES) algorithms, though it may not be quantum safe if PQC algorithm is broken.

[0220] Further, following modification required to incorporate in 3GPP standard specification: Protection schemes for concealing the subscription permanent identifier:

[0221] 0x0: Null-Scheme Size of input, i.e., size of username used in case of NAI format or MSIN in case of IMSI

[0222] 0x1: ECIES Profile Total of 256-bit public key, 64-bit MAC, plus size of input.

[0223] 0x2: ECIES Profile Total of 264-bit public key, 64-bit MAC, plus size of input.

[0224] 0x3: KYBER Total of 768 / 1088 / 1568 byte ciphered shared key, 64-bit MAC, plus size of input

[0225] 0x4: ECIES Profile A + KYBER

[0226] 0x5: ECIES Profile B + KYBER

[0227] 0x6: ECIES Profile A + BIKE

[0228] 0x7: ECIES Profile B + BIKE

[0229] 0x8: ECIES Profile A + Classic McEliece

[0230] 0x9: ECIES Profile B + Classic McEliece

[0231] 0xA: ECIES Profile A + HQC

[0232] 0xB: ECIES Profile B + HQC.

[0233] Like 0x5 to 0xC, any combination of legacy scheme ECIES Profile A / B and below mentioned PQC KEM based schemes are possible to be constructed.

[0234] BIKE Total of 1572 / 3114 byte ciphered shared key, 64-bit MAC, plus size of

[0235] Input

[0236] Classic McEliece Total of 128 / 188 / 240 byte ciphered shared key, 64-bit MAC, plus size of

[0237] Input

[0238] HQC Total of 4481 / 9026 / 14469 byte ciphered shared key, 64-bit MAC, plus

[0239] size of input

[0240] SIKE Total of 346 / 486 / 596 byte ciphered shared key, 64-bit MAC, plus size

[0241] of input

[0242] The values 0xC - 0xF are reserved for proprietary protection schemes specified by the home operator.

[0243] Following modification may be required to incorporate in 3GPP TS 33.501 standard specification in Annex C: New section for Hybrid profiles (ECIES Profile A + PQC) needs to be created like ECIES.

[0244] C.X.X Hybrid Profiles

[0245] - Unless otherwise stated, the Hybrid profiles follow the terminology and processing specified in SECG version 2 and selected NIST PQC algorithms documentation. The profiles shall use "named curves" over prime fields.

[0246] - For generating successive counter blocks from the initial counter block (ICB) in CTR mode, the profiles shall use the standard incrementing function in section B.1 of NIST Special Publication 800-38A with m = 32 bits. The ICB corresponds to T1 in section 6.5.

[0247] AES-128 in CTR mode or AES-256 (with or without CTR) are preferred. AES-256 is required if need to maintain 256 bit security.

[0248] -The value of the MAC tag in Hybrid profile, shall be the L most significant octets of the output generated by the HMAC function, where L equals to the maclen.

[0249] -Hybrid profile use its own standardized processing for key generation (section 6 of RFC 7748 and PQC KEM algorithm Key generation process) and shared secret calculation (section 5 of RFC 7748 and PQC KEM algorithm generated shared Key). Shared key calculated will be combination of both shared keys, one generated from ECIES and other from PQC KEM algorithm. The Diffie-Hellman primitive X25519 (section 5 of RFC 7748 ) takes two random octet strings as input, decodes them as scalar and coordinate, performs multiplication, and encodes the result as an octet string. The shared secret output octet string from X25519 combined with PQC KEM generated shared key shall be used as the input Z in the KDF (section 3.6.1 of ).

[0250] - As the point compression is not applied, the prefix rule for compression type defined in section 5.1.3 shall not be used, i.e., there shall be no prefix for the ephemeral public key.

[0251] - The profiles shall not use backwards compatibility mode (therefore are not compatible with version 1 of SECG).

[0252] A hybrid profile for ECIES profile A combined with Kyber-1024 algorithm and security level 5 can be provisioned as mentioned in Table 19 (Below) and also can have various parameters modified according to Level of security (1,3,5) it supported as marked below. Level 1 and Level 3 parameters as mentioned in Table 1.B can be replaced accordingly. Similarly, any combination ECIES Profile A and other PQC KEMs (Tables 1B, 2B, 3B, 4B of Solution 1) can be made as hybrid profiles.

[0253]

[0254] Following modification may be required to incorporate in 3GPP TS 33.501 standard specification in Annex C: New section for Hybrid profiles (ECIES Profile B + PQC) needs to be created like ECIES.

[0255] C.X.X Hybrid Profiles

[0256] - Unless otherwise stated, the Hybrid profiles follow the terminology and processing specified in SECG version 2 and selected NIST PQC algorithms documentation. The profiles shall use "named curves" over prime fields.

[0257] - For generating successive counter blocks from the initial counter block (ICB) in CTR mode, the profiles shall use the standard incrementing function in section B.1 of NIST Special Publication 800-38A with m = 32 bits. The ICB corresponds to T1 in section 6.5. AES-128 in CTR mode or AES-256 (with or without CTR) are preferred. AES-256 is required if need to maintain 256 bit security.

[0258] - The value of the MAC tag in Hybrid profile, shall be the L most significant octets of the output generated by the HMAC function, where L equals to the maclen.

[0259] - Hybrid profile use its own standardized processing for key generation (section 6 of RFC 7748 and PQC KEM algorithm Key generation process) and shared secret calculation (section 5 of RFC 7748 and PQC KEM algorithm generated shared Key). Shared key calculated will be combination of both shared keys, one generated from ECIES and other from PQC KEM algorithm. The Diffie-Hellman primitive X25519 (section 5 of RFC 7748) takes two random octet strings as input, decodes them as scalar and coordinate, performs multiplication, and encodes the result as an octet string. The shared secret output octet string from X25519 combined with PQC KEM generated shared key shall be used as the input Z in the KDF (section 3.6.1).

[0260] - Algorithm shall use point compression to save overhead and shall use the Elliptic Curve Cofactor Diffie-Hellman Primitive (section 3.3.2) to enable future addition of profiles with cofactor h≠1.

[0261] - For curves with cofactor h = 1 the two primitives (section 3.3.1 and 3.3.2 ) are equal. The profiles shall not use backwards compatibility mode (therefore are not compatible with version 1 of SECG).

[0262] A hybrid profile for ECIES profile B combined with Kyber-1024 algorithm and security level 5 can be provisioned as mentioned in Table 20 (Below) and also can have various parameters modified according to Level of security (1,3,5) it supported as marked below. Level 1 and Level 3 parameters as mentioned in Table 1.B can be replaced accordingly. Similarly, any combination ECIES Profile B and other PQC KEMs (Tables 1B, 2B, 3B, 4B of Solution 1) can be made as hybrid profiles.

[0263]

[0264] In another embodiment, a combination of both PQC KEM based profile is utilised. Herein, the hybrid profile may also consist of both KEM algorithms which may be of post quantum type, i.e., both are Post Quantum Cryptography KEM based scheme identifier. All NIST standardized PQC algorithms for key encapsulation can be part of PQC based protection schemes. Some of the NIST 4th round candidate algorithms may also be standardized. As NIST standardized PQC algorithms are tested for minimal duration, in case if any one of the PQC algorithm is broken, the other PQC algorithm can safeguard to make sure security is not compromised. So, even in post quantum era, these kind of scheme identifiers cannot be broken even if case security is compromised for one of the PQC algorithm.

[0265] Figure 2A illustrates an exemplary environment 200a in which a User Equipment (UE) 101 is registered with a Home network (HN) 103 using hybrid key exchange, in accordance with some embodiments of the present disclosure.

[0266] As illustrated in Figure 2A, the exemplary environment 100 may comprise UE 101, and HN 103. The UE 101 may include, without limitation, a smart phone, a mobile device, a tablet, a laptop, a desktop or any device that can register with the HN 103. The HN 103 may include, without limitation, a base station, a network service station, a network provider and the like. The UE 101 may communicate with the HN 103 through communication network 213. The communication network 117 may be implemented as one of the several types of networks, such as intranet or Local Area Network (LAN). The communication network 213 may either be a dedicated network or a shared network, which represents an association of several types of networks that use a variety of protocols, for example, Hypertext Transfer Protocols (HTTPs) or a Transmission Control Protocol (TCP) and a Transport Layer Security (TLS), a Wireless Application Protocol (WAP), etc.

[0267] The UE 101 may comprise a memory 201, an interface 203 and a processor 205. The HN 103 may comprise an interface 207, a memory 209, and a processor 211. The detailed diagrams of the UE 101 and the HN 103 are explained in Figures 2B-2E.

[0268] In an embodiment, initially, the UE 101 may generate ephemeral public key and an ephemeral private key based on an Elliptical Curve (EC) key generation technique. For example, the UE 101 may generate the public key and private key pair using Elliptical Curve Cryptography (ECC) algorithms. The ECC may be a key-based technique for encrypting data. In other words, the ECC may be a public-key cryptographic algorithm that may be used to perform critical security functions such as encryption, authentication and digital signatures. After generating the ephemeral public key and the ephemeral private key, the UE 101 may generate a first ephemeral shared key based on the ephemeral private key and an Elliptical Urve (EC) based HN 103 public key. The UE 101 may use Elliptical Curve based Diffie Hellman (ECDH) key agreement operation. The ECDH key agreement allows ty to derive the generate the first ephemeral shared key, using UE's 101 private key and the EC based HN 103 public key. In other words, the UE 101 generates the first ephemeral shared key by applying ECC technique on the ephemeral private key and the EC based HN 103 public key.

[0269] Similarly, in the next step, the UE 101 may generate a second ephemeral shared key and an encrypted shared key based on a Post-Quantum Cryptography (PQC) based public key associated with the HN 103. Specifically, the UE 101 may use PQC based HN 103 public key as an input to the PQC key encapsulation to generate the second ephemeral shared key. The PQC encapsulation is an encapsulation technique which takes HN 103 public key as input and outputs the shared secret key and an encapsulation of the secret key. In other words, the UE 101 generates the second ephemeral shared key by applying PQC Key Encapsulation Mechanism (KEM) technique on the PQC based public key associated with the HN 103.

[0270] In the next step, the UE 101 may generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. For example, the UE 101 may combine the first ephemeral shared key and the second ephemeral shared key to generate the ephemeral hybrid shared key. In one example, the ephemeral hybrid shared key may be generated using concatenation, Exclusively - OR (XOR) mathematical function or HMAC functions. For example, hybrid ephemeral shared key (S) = first ephemeral shared key (S1) || second ephemeral shared key (S2) or S= S1 XOR S2 or the HMAC function with S1 and S2 as input.

[0271] For example, after generating the ephemeral hybrid shared secret key, the UE 101 uses a key derivation function to derive multiple keys from the ephemeral hybrid shared secret key. The Key derivation function, such as ANSI-X9.63-KDF is used for deriving multiple keys out of the hybrid shared secret key. In the next step, after generating the ephemeral hybrid shared key, the UE 101 may generate a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key. Specifically, the UE 101 may generate an ephemeral encryption key and an ephemeral MAC key based at least on ephemeral hybrid shared key. Similarly, the UE 101 may generate the cipher-text value by performing symmetric encryption of a plain text based on the ephemeral encrypted key. Finally, the UE 101 may generate the MAC tag value by applying a MAC function on the ephemeral MAC key and the cipher-text value.

[0272] In SUPI concealment case, the UE 101 generates the ICB (Initial Counter Block), MAC key and Advanced Encryption Standard (AES) encryption key using the KDF. The UE 101 finally performs the concealment of SUPI using the symmetric key encryption algorithm (AES), and generates a concealed value of SUPI. The UE 101 uses a Hash-based Message Authentication Code (HMAC) function to ensure integrity protection for the generated concealed SUPI. The HMAC generates a mac-tag of concealed SUPI using derived mac-key. The aforementioned steps can be used for SUPI concealment. Out of these five operations, the key generation and key agreement are based on elliptical curves based public key cryptography. Post concealment of SUPI, the UE 101 sends the SUCI to the HN 103. That is, finally, the UE 101 may transmit a registration request for registering the UE 101 with the HN 103 along with the ephemeral public key, the encrypted shared key, the cipher-text value and the MAC tag value. In an alternative embodiment, the UE 101 may create a security profile. The UE 101 may create the security profile based on creating PQC based profile using one or more PQC parameters for encryption, decryption, encapsulation, and decapsulation of identities and data transmitted from the UE 101 to HN 103 and creating a hybrid profile using one or more hybrid parameters for encryption, decryption, encapsulation and decapsulation of identities and data transmitted from the UE 101 to HN 103. Further, the UE 101 may perform primary authentication using the one or more PQC parameters and the one or more hybrid parameters before transmitting the data from the UE 101 to HN 103. The one or more hybrid parameters may include, without limitation, a type of PQC KEM algorithm, a type of PQC digital signature algorithm, a level of security and the like. The one or more hybrid parameters form the PQC and hybrid (i.e., legacy + PQC) profile.

[0273] In response to the registration request from the UE 101, the HN 103 may generate a first ephemeral shared key based at least on the ephemeral public key and ECC based public key associated with the HN 103. The HN 103 generates the first ephemeral shared key by applying ECC technique on the ephemeral private key and the ECC based HN 103 public key. In the next step, the HN 103 may generate a second ephemeral shared key based on the encrypted shared key and a PQC based private key associated with the HN 103. The HN 103 generates the second ephemeral shared key by applying PQC Key Decapsulation Mechanism (KDM) technique on the encrypted shared and the PQC based public key associated with the HN 103.

[0274] In the next step, the HN 103 may generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. In one example, the ephemeral hybrid shared key may be generated using concatenation, XOR mathematical function or HMAC functions. For example, hybrid ephemeral shared key (S) = first ephemeral shared key (S1) || second ephemeral shared key (S2) or S= S1 XOR S2 or the HMAC function with S1 and S2 as input.

[0275] For example, after generating the ephemeral hybrid shared secret key, the HN 103 uses a key derivation function to derive multiple keys from the ephemeral hybrid shared secret key. The Key derivation function, such as ANSI-X9.63-KDF is used for deriving multiple keys out of the hybrid shared secret key. In the next step, after generating the ephemeral hybrid shared key, the HN 103 may generate an ephemeral decryption key and an ephemeral MAC key based at least on ephemeral hybrid shared key. Similarly, the HN 103 may generate a plaintext by performing a symmetric decryption of the cipher-text value based at least one the ephemeral decrypted key. The plaintext may include 15 digits number. Finally, the HN 103 may generate register the UE 101 with the HN 103 based on the generated plaintext.

[0276] In another embodiment, the UE 101 is to be registered with the HN 103 using hybrid key exchange. The UE 101 may generate a first ephemeral shared key and a first encrypted shared key based on a first Post-Quantum Cryptography (PQC) based home network public key. Specifically, the UE 101 may generate the first ephemeral shared key and the first encrypted shared key by applying a PQC Key Encapsulation Mechanism (KEM) technique on the first PQC based home network public key. The UE 101 may generate a second ephemeral shared key and a second encrypted shared key based on a second PQC based home network public key. Specifically, the UE 101 generate the second ephemeral shared key and the second encrypted shared key by applying the PQC KEM technique on the second PQC based home network public key.

[0277] In the next step, the UE 101 may generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. In one example, the ephemeral hybrid shared key may be generated using concatenation, XOR mathematical function or HMAC functions. For example, hybrid ephemeral shared key (S) = first ephemeral shared key (S1) || second ephemeral shared key (S2) or S= S1 XOR S2 or the HMAC function with S1 and S2 as input.

[0278] For example, after generating the ephemeral hybrid shared secret key, the UE 101 uses a key derivation function to derive multiple keys from the ephemeral hybrid shared secret key. The Key derivation function, such as ANSI-X9.63-KDF is used for deriving multiple keys out of the hybrid shared secret key. In the next step, after generating the ephemeral hybrid shared key, the UE 101 may generate a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key. Specifically, the UE 101 may generate an ephemeral encryption key and an ephemeral MAC key based at least on ephemeral hybrid shared key. Similarly, the UE 101 may generate the cipher-text value by performing symmetric encryption of a plain text based on the ephemeral encrypted key. Finally, the UE 101 may generate the MAC tag value by applying a MAC function on the ephemeral MAC key and the cipher-text value.

[0279] In the next step, the UE 101 may transmit a registration request for registering the UE 101 with the HN 103 along with the ephemeral public key, the encrypted shared key, the cipher-text value and the MAC tag value. The MAC tag value may be for performing integrity check in the HN 103.

[0280] In response to the registration request from the UE 101, the HN 103 may generate a first ephemeral shared key based at least on the first encrypted shared key and first Post-Quantum Cryptography (PQC) based private key associated with the HN 103. The HN 103 may generate a second ephemeral shared key based on the second encrypted shared key and a second PQC based private key associated with the HN 103. In the next step, the HN 103 may generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. The HN 103 generates the second ephemeral shared key by applying PQC Key Decapsulation Mechanism (KDM) technique on the encrypted shared and the PQC based public key associated with the HN 103.

[0281] In the next step, the HN 103 may generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. In one example, the ephemeral hybrid shared key may be generated using concatenation, XOR mathematical function or HMAC functions. For example, hybrid ephemeral shared key (S) = first ephemeral shared key (S1) || second ephemeral shared key (S2) or S= S1 XOR S2 or the HMAC function with S1 and S2 as input.

[0282] For example, after generating the ephemeral hybrid shared secret key, the HN 103 uses a key derivation function to derive multiple keys from the ephemeral hybrid shared secret key. The Key derivation function, such as ANSI-X9.63-KDF is used for deriving multiple keys out of the hybrid shared secret key. In the next step, after generating the ephemeral hybrid shared key, the HN 103 may generate an ephemeral decryption key and an ephemeral MAC key based at least on ephemeral hybrid shared key. Similarly, the HN 103 may generate a plaintext by performing a symmetric decryption of the cipher-text value based at least one the ephemeral decrypted key. The plaintext may include 15 digits number. Finally, the HN 103 may generate register the UE 101 with the HN 103 based on the generated plaintext.

[0283] In another embodiment, the UE 101 is to be registered with the HN 103 using hybrid key encryption. The UE 101 may generate an ephemeral public key and an ephemeral private key based at least on Elliptical Curve (EC) key generation technique. The UE 101 may generate an ephemeral shared key based on the ephemeral private key and an EC based home network public key. In the next step, the UE 101 may generate an ephemeral encryption key and an ephemeral message authentication code (MAC) key based at least on ephemeral hybrid shared key. The UE 101 may generate an intermediate cipher-text value by performing symmetric encryption of a plaintext based on the ephemeral encrypted key.

[0284] In the next step, the UE 101 may generate a cipher-text value based on the intermediate cipher-text value and a PQC based HN 103 public key. Specifically, the UE 101 may generate the cipher-text value by applying PQC based encryption on the intermediate cipher-text value based on the PQC HN 103 public key. In the next step, the UE 101 may generate MAC tag value based at least on the cipher-text value and the ephemeral MAC-tag key. Specifically, the UE 101 may generate the MAC tag value by applying a MAC function on the ephemeral MAC key and the cipher-text value.

[0285] In the next step, the UE 101 may transmit a registration request for registering the UE 101 with the HN 103 along with the ephemeral public key, the cipher-text value and the MAC tag value. The MAC tag value may be for performing integrity check in the HN 103.

[0286] In response to the registration request, the HN 103 may generate an ephemeral shared key based on the ephemeral public key and an Elliptical Curve (EC) based private key associated with the home network 103. The HN 103 may generate an ephemeral decryption key and an ephemeral MAC key based on the ephemeral shared key. In the next step, the HN 103 may generate an intermediate cipher text value by applying Post Quantum Cryptography (PQC) decryption on the cipher-text value based on a PQC based home network public key. In the next step, the HN 103 may generate a plaintext by performing a symmetric decryption of the intermediate cipher-text value based at least on the ephemeral decrypted key. Finally, the HN 103 may register the UE 101 with the HN 103 based on the generated plain text.

[0287] In another embodiment, the UE 101 is to be registered with the HN 103 using hybrid key encryption. Specifically, the UE 101 may split a plaintext into a first part and a second part. In the next step, the UE 101 may generate a first cipher-text value based on a first Post-Quantum Cryptography (PQC) based public key associated with the home network 103. Specifically, the UE 101 may generate the first cipher-text value by applying a first Post Quantum Cryptography (PQC) Key Encapsulation Mechanism (KEM) technique on the first part of the plaintext and the first PQC based home network public key. The UE 101 may generate a second cipher-text value base on a second PQC based public key associated with the HN 103. Specifically, the UE 101 may generate the second cipher-text value by applying a second PQC KEM technique on the second part of the plaintext and the PQC based public key associated with the home network Finally the UE 101 may transmit a registration request for registering the UE 101 with the HN 103 along with the first cipher text value and the second cipher text value.

[0288] The HN 103 may receive the registration request, in response to receiving the registration request, the HN 103 may generate a first part of a plaintext by decrypting the first cipher-text value based on a first Post-Quantum Cryptography (PQC) private key associated with the home network 103. The HN 103 may generate a second part of the plaintext by decrypting the second cipher-text value based on a second PQC private key associated with the home network 103. Specifically, the HN 103 may decrypt the first cipher-text value by applying a first PQC decryption technique on the first cipher-text value and the first PQC private key. Similarly, the HN 103 may decrypt the second cipher-text value by applying a second PQC decryption technique on the second cipher-text value and the second PQC private key. The HN 103 may generate the plaintext by combining the first part and the second part of the plaintext. Finally, the HN 103 may register the UE 101 with the HN 103 based on the generated plaintext.

[0289] In another embodiment, the UE 101 is to be registered with the HN 103 using hybrid key encryption. Specifically, the UE 101 may generate an intermediate cipher-text value based on a first Post Quantum Cryptography (PQC) based home network public key and a plain text. Specifically, the UE 101 may generate the intermediate cipher text value by applying a first PQC encryption technique on the plain text and the first PQC based home network public key.

[0290] In the next step, the UE 101 may generate a cipher-text value based on the intermediate cipher-text value and a second PQC based HN 103 public key. Specifically, the HN 103 may generate the cipher text value by applying a second PQC encryption technique on the intermediate cipher-text value and the second PQC based home network public key. Finally the UE 101 may transmit a registration request for registering the UE 101 with along with the cipher text value to the HN 103 for registering the UE 101 with the home network 103.

[0291] The HN 103 may receive the registration request, in response to receiving the registration request, the HN 103 may generate an intermediate cipher-text value based on the cipher text-value and a second PQC based home network private key. Specifically, the HN 103 may generate the intermediate cipher-text value by applying a second PQC decryption technique on the cipher-text value and the second PQC based home network private key. The HN 103 may generate a plain text based on the intermediate cipher text value and a first PQC based home network private key. Specifically, the HN 103 may generate the plain text value by applying a first PQC decryption technique on the intermediate cipher-text value and the first PQC based home network private key In the next step, the HN 103 may register the UE 101 with the HN 103 based on the generated plaintext.

[0292] Figure 2B illustrates a detailed block diagram 200b of the UE 101 shown in Figure 1, in accordance with some embodiments of the present disclosure.

[0293] In an embodiment, the UE 101 may include an interface 203, a memory 201, a Central Processing Unit (also referred as "CPUs" or "the one or more processors"). In some embodiments, the memory 201 may be communicatively coupled to the one or more processors 205. The memory 201 stores instructions executable by the one or more processors 205. The one or more processors 205 may comprise at least one data processor for executing program components for executing user or system-generated requests. The one or more processors 205 may perform one or more functions of the UE 101 for registering the UE 101 with the HN 103 using a hybrid key exchange or the hybrid key encryption. The memory 201 may store instructions, executable by the one or more processors 205, which on execution, may cause the one or more processors 205 to register the UE 101 with the HN 103. The interface 203 may be coupled with the one or more processors 205. For example, the one or more processors 205 may communicate with HN 103 as shown in Figure 1.

[0294] In an embodiment, the one or more processor 205 may include one or more modules or hardware units, for e.g., a generation unit 215, and a transmitting unit 217, but not limited thereto. In some embodiments, the one or more modules or units may be software modules which may be stored in the memory 201. The one or more modules or hardware units may be configured to perform the various operations of the present disclosure to register the UE 101 with the HN 103 using a hybrid key exchange or the hybrid key encryption.

[0295] Figure 2C illustrates a detailed block diagram of HN 103 shown in Figure 1, in accordance with some embodiments of the present disclosure.

[0296] In an embodiment, some of the functions of the HN 103 may be performed by the HN 103 itself. In an embodiment, the HN 103 may include an interface 207, a memory 209, a Central Processing Unit (also referred as "CPUs" or "the one or more processors"). In some embodiments, the memory 209 may be communicatively coupled to the one or more processors 211. The memory 209 stores instructions executable by the one or more processors 211. The one or more processors 211 may comprise at least one data processor for executing program components for executing user or system-generated requests. The one or more processors 211 may perform one or more functions of the HN 103 for registering the UE 101 with the HN 103 using a hybrid key exchange or the hybrid key encryption. The memory 209 may store instructions, executable by the one or more processors 211, which on execution, may cause the one or more processors 211 to register the UE 101 with the HN 103 using a hybrid key exchange or the hybrid key encryption..

[0297] In an embodiment, the one or more processor 211 may include one or more modules or hardware units, for e.g., a receiving unit 217, a generation unit 219, a registering unit 221, but not limited thereto. In some embodiments, the one or more modules or units may be software modules which may be stored in the memory 209. The one or more modules or hardware units may be configured to perform the various operations of the present disclosure to register the UE 101 with the HN 103 using a hybrid key exchange or the hybrid key encryption.

[0298] Figure 2D illustrates a detailed block diagram 200d of the UE 101 shown in Figure 1, in accordance with some embodiments of the present disclosure.

[0299] In an embodiment, the UE 101 may include an interface 203, a memory 201, a Central Processing Unit (also referred as "CPUs" or "the one or more processors"). In some embodiments, the memory 201 may be communicatively coupled to the one or more processors 205. The memory 201 stores instructions executable by the one or more processors 205. The one or more processors 205 may comprise at least one data processor for executing program components for executing user or system-generated requests. The one or more processors 205 may perform one or more functions of the UE 101 for registering the UE 101 with the HN 103 using a hybrid key exchange or the hybrid key encryption. The memory 201 may store instructions, executable by the one or more processors 205, which on execution, may cause the one or more processors 205 to register the UE 101 with the HN 103. The interface 203 may be coupled with the one or more processors 205. For example, the one or more processors 205 may communicate with HN 103 as shown in Figure 2A.

[0300] In an embodiment, the one or more processor 205 may include one or more modules or hardware units, for e.g., a splitting unit 223, a generation unit 225 and a transmitting unit 227, but not limited thereto. In some embodiments, the one or more modules or units may be software modules which may be stored in the memory 201. The one or more modules or hardware units may be configured to perform the various operations of the present disclosure to register the UE 101 with the HN 103 using a hybrid key exchange or the hybrid key encryption.

[0301] Figure 2E illustrates a detailed block diagram 200e of the HN 103 shown in Figure 1, in accordance with some embodiments of the present disclosure.

[0302] In an embodiment, some of the functions of the HN 103 may be performed by the HN 103 itself. In an embodiment, the HN 103 may include an interface 207, a memory 209, a Central Processing Unit (also referred as "CPUs" or "the one or more processors"). In some embodiments, the memory 209 may be communicatively coupled to the one or more processors 211. The memory 209 stores instructions executable by the one or more processors 211. The one or more processors 211 may comprise at least one data processor for executing program components for executing user or system-generated requests. The one or more processors 211 may perform one or more functions of the HN 103 for registering the UE 101 with the HN 103 using a hybrid key exchange or the hybrid key encryption. The memory 209 may store instructions, executable by the one or more processors 211, which on execution, may cause the one or more processors 211 to register the UE 101 with the HN 103 using a hybrid key exchange or the hybrid key encryption..

[0303] In an embodiment, the one or more processor 211 may include one or more modules or hardware units, for e.g., a receiving unit 229, a generation unit 231, a registering unit 233, but not limited thereto. In some embodiments, the one or more modules or units may be software modules which may be stored in the memory 209. The one or more modules or hardware units may be configured to perform the various operations of the present disclosure to register the UE 101 with the HN 103 using a hybrid key exchange or the hybrid key encryption.

[0304] Figure 2F illustrates a flow diagram of hybrid SUPI concealment at UE 101 using legacy and PQC based shared key generation, in accordance with some embodiments of the present disclosure.

[0305] Figure 2F depicts concealing the hybrid SUPI. Here, instead of relying either on the elliptical curve based public key cryptography, (which is not quantum secure) or on post quantum safe cryptography algorithms (which is not well tested), a hybrid combination of classical algorithm with PQC algorithm may be used. At step 1 of Hybrid SUPI concealment at the UE 101, the UE 101 may generate ephemeral public and private key pair based on an elliptical curve. At step 2, a, UE 101 may generate a shared key (s1) using elliptical curve based diffie-hellman key agreement. It takes the EC based UE private key and the HN 103 public key and generates the shared key (s1). In step 2b, the UE 101 may generate the shared key (s2) using PQC based key encapsulation method. Here, PQC key encapsulation method receives the PQC based HN 103 public key as input and may generate the output with shared key (s2) and an encrypted shared key. In step 3 (hybrid shared key generation function), a hybrid shared key(s) is generated using shared key (s1) and shared key (s2). This hybrid shared key generation may use either simple concatenation, where the shared key "s" can be generated using a simple concatenation of "s1" and "s2"; for e.g., s = s1 || s2. The Hybrid shared key may also be generated using a XOR operation; for e.g., s = s1 XOR s2. Another way for generating the hybrid-shared secret may be using a HMAC function, where s1 and s2 will be the inputs and s will be the output. After generating the shared key(s), in step 4, the UE 101 may receive the shared key(s) as input and may generate multiple keys similar to ECIES scheme like ICB, MAC key and AES encryption key. At step 5, the UE 101 may use symmetric key encryption to conceal the SUPI. Further, in step 6, the UE 101 may use the HMAC function to derive the MAC tag corresponding to the encrypted SUPI, which is required to provide integrity. Overall, embodiments herein provide hybrid based shared key generation for SUCI concealment using elliptical curves-based algorithms along with post quantum safe cryptographic algorithms.

[0306] Further, after SUPI concealment at UE 101, the scheme output may be sent to the HN 103. Generally, the scheme output may include encrypted SUPI and other parameters that are required for smooth de-concealment of SUCI at HN 103 end.

[0307] Figure 2G illustrates a block diagram of modified scheme output based on Hybrid SUPI concealment using legacy and PQC based shared key generation, in accordance with some embodiments of the present disclosure.

[0308] As illustrated in Figure 2G, a new concealment using legacy + PQC based shared key generation is proposed. In proposed SUPI concealment, the UE 101 may also generate one encrypted share key as output correspond to the shared key (s2). Further, in order to arrive at the same shared key (s2) at the HN 103 end, the encrypted shared key may be included in a scheme output along with the EC based UE public key, cipher-text and MAC-tag.

[0309] Figure 2H illustrates a flow diagram of hybrid SUCI deconcealment at UE 101 using legacy and PQC based shared key generation, in accordance with some embodiments of the present disclosure. Figure 2H depicts the process of deconcealing the hybrid SUPI. Here, instead of relying either on elliptical curve based public key cryptography (which is not quantum secure) or on post quantum safe cryptography algorithms (which is not well tested), a hybrid combination of classical algorithm with PQC algorithm may be used. After receiving the SUCI from the UE 101, the HN 103 may retrieve the EC based UE public key, encrypted shared key, cipher text, and MAC-tag associated with it. At step 1a, the HN 103 may generate the shared key (s1) using an elliptical curve based diffie-hellman key agreement. It takes EC based UE public key and HN 103 private key and generates the shared key (s1). At step 1b, the HN 103 may use a PQC decapsulation method, which takes the PQC based HN 103 private key and encrypted shared key as an input and retrieve the shared key (s2) as output. In step 3 (hybrid shared key generation function), hybrid shared key (s) are generated using shared key (s1) and shared key (s2). This hybrid shared key generation may use either simple concatenation, where shared key "s" can be generated using simple concatenation of "s1" and "s2"; for e.g., s = s1 || s2. Hybrid shared keys may also be generated using XOR operation; for e.g., s = s1 XOR s2. Another way for generating hybrid-shared secret may using a HMAC function, where s1 and s2 will be input and s will be output. Here, by using PQC decapsulation method at the HN 103 along with an ECDH based key agreement for shared key generation, embodiments herein make SUCI de-concealment secure. Further, the generated shared key (s) may be used in step 3 (key derivation). In step 3, the KDF takes the shared key as input and may generate multiple keys similar to SUPI concealment. In step 4, the HN 103 may use symmetric key decryption to deconceal the SUCI and validate integrity of the received SUCI using the HMAC function. Overall, embodiments herein are combining elliptical curves-based procedures of the ECIES scheme with post quantum safe cryptographic algorithm in SUCI de-concealment.

[0310] Figure 2I illustrates a sequence diagram of hybrid SUPI concealment and deconcealment using legacy and PQC based shared key generation in accordance with some embodiments of the present disclosure. As illustrated in Figure 2I, the initially EC Based Public Key, PQC based HN 103 public key are provision to the UE 101, during SIM provisioning as indicated in the step 1 (S1). Later, when the UE 101 wants to initiate SUPI concealment, the UE 101 may generate EC based public, private pair as indicated in step 2(S2)and generate shared key (s1) using ECDH key agreement as indicated in step 3 (S3). For performing PQC based key encapsulation for shared key (s2) generation, embodiments herein uses combined shared generation, and the KDF for multiple key generation. Later, it uses AES encryption and HMAC function to perform encryption of SUPI and mac-tag generation as indicated in step 4 (S4) and step 5(S5). These all steps are the part of SUPI concealment. After completion of SUPI concealment, the UE 101 creates the scheme output as indicated in the step 6 (S6), which may include the Encrypted shared key, Cipher-text, and Mac-Tag. The cipher-text comprises of the concealed SUPI. The mac-tag includes the mac of the concealed SUPI. The scheme output is transferred from the UE 101 to the HN 103 as a part of the SUCI packet. Post receiving the SUCI, the HN 103 initiates SUCI de-concealment procedure. Further, the HN103 may generate a share secret using ECDH key agreement for s1 as indicated in step 7 (S7), PQC key decapsulation for s2, combined shared generation for s, and the KDF for multiple key generation. Later, the HN 103 validates integrity of SUCI packet using HMAC function and completes SUCI concealment using AES decryption function as indicated in step 8 (S8) and step 9 (S9). Hybrid usage of the algorithm for SUPI concealment and SUCI de-concealment make them quantum safe as well highly reliable.

[0311] Figure 3A illustrates a flow diagram of hybrid SUPI concealment at the UE 101, using PQC and PQC based shared key generation in accordance with some embodiments of the present disclosure. As illustrated in Figure 3A depicts Hybrid SUPI concealment. Here, instead of relying just on a single post quantum safe cryptography algorithm (which may be not well tested or secure), a hybrid combination of multiple PQC algorithms may be used. At steps 1a, and 1b, the UE 101 may generate shared key (s1) and shared key (s2) using PQC based key encapsulation method. Here, the PQC key encapsulation method for both these steps may use different PQC algorithms. The PQC key encapsulation method includes receiving the PQC based HN 103 public key-1, HN 103 public key-2, as input and may generate output with the shared key (s1), the shared key (s2) and the encrypted shared key (es1), the encrypted shared key (es2). In step 2 (hybrid shared key generation function), hybrid shared key(s) are generated using the shared key (s1) and the shared key (s2). This hybrid shared key generation may use either simple concatenation, where the shared key "s" can be generated using simple concatenation of "s1" and "s2", for e.g., s = s1 || s2. The hybrid shared key may also be generated using XOR operation; for e.g., s = s1 XOR s2. Another way for generating the hybrid-shared secret may use the HMAC function, where s1 and s2 will be input and s will be output. After generating the shared key(s), in step 3, the UE 101 may receive shared key(s) as input and may generate multiple keys similar to ECIES scheme like ICB, MAC key and AES encryption key. At step 4, the UE 101 may use symmetric key encryption to conceal the SUPI. Further, in step 5, the UE 101 may use the HMAC function to derive the MAC tag corresponding to encrypted SUPI, which is required to provide integrity. Overall, embodiments herein provide hybrid based shared key generation for concealing the SUCI using multiple post quantum safe cryptographic algorithms. Further, after SUPI concealment at UE 101, the scheme output may be sent to the HN 103. Generally, the scheme output may include the encrypted SUPI and other parameters that are required for smooth de-concealment of SUCI at the HN 103 end.

[0312] Figure 3B illustrates a block diagram of modified scheme output based on Hybrid SUPI concealment using PQC and PQC based shared key generation, in accordance with some embodiments of the present disclosure. Figure 3B depicts a new scheme output for hybrid based SUPI concealment and deconcealment using PQC and PQC based shared key generation is proposed. In proposed SUPI concealment, the UE 101 may generate multiple encrypted share keys as output correspond to the multiple shared keys. Further, in order to arrive at the same shared key at the HN 103 end, the encrypted shared key (es1) and encrypted shared key (es2) may be included in the scheme output along with the cipher-text and MAC-tag.

[0313] Figure 3C illustrates a flow diagram of hybrid SUCI deconcealment at the UE 101, using PQC and PQC based shared key generation in accordance with some embodiments of the present disclosure. As illustrated in Figure 3c, after receiving the SUCI from the UE 101, the HN 103 may retrieve encrypted shared keys, cipher text, and MAC-tag associated with it. At steps 1a and 1b, the HN 103 may use a PQC decapsulation method, which take PQC based HN 103 private key-1, private key- and encrypted shared key (es1), encrypted shared key (es2) as an input and retrieve the shared key (s1), and the shared key (s2) as output. In step 2 (hybrid shared key generation function), the hybrid shared key(s) are generated using the shared key (s1) and shared key (s2). This hybrid shared key generation may use either simple concatenation, where the shared key "s" can be generated using a simple concatenation of "s1" and "s2"; for e.g., s = s1 || s2. Hybrid shared key may also be generates using XOR operation; for e.g., s = s1 XOR s2. Another way for generating the hybrid-shared secret may be using the HMAC function, where s1 and s2 will be input and s will be output. Further, the generated shared key (s) may be used in step 3 for key derivation. In step 3, the KDF takes the shared key as input and may generate multiple keys similar to SUPI 5 concealment. In step 4, the HN 103 may use the symmetric key decryption to de-conceal the SUCI and validate integrity of the received SUCI using the HMAC function. Overall, embodiments herein are combining multiple post quantum safe cryptographic algorithm in the SUCI deconcealment.

[0314] Figure 3D illustrates a sequence diagram of hybrid SUPI concealment and deconcealment using PQC and PQC based shared key generation, in accordance with some embodiments of the present disclosure. As illustrated in Figure 3D, initially multiple PQC based

[0315] HN 103 public key may provision to the UE 101, during SIM provisioning as indicated in the step 1 (S1). Later, when the UE 101 wants to initiate SUPI concealment, the UE 101 performs PQC based key encapsulation for generating the shared key (s1), and the shared key (s2), and uses the combined shared generation as indicated in the step 2 (S2), the KDF for multiple key generation as indicated in the step 3 (S3). Later, it uses AES encryption and HMAC function to perform encryption of SUPI and mac-tag as indicated in the step 4 (S4) and step 5 (S5). These steps are the part of SUPI concealment. After completion of SUPI concealment, the UE 101 creates the scheme output, which may include multiple Encrypted shared key(s), Ciphertext(s), and Mac-Tag(s). Here, the cipher-text comprises concealed SUPI and mactag, which includes the mac of concealed SUPI. The scheme output is transferred from the UE 101 to the HN 103 as a part of the SUCI packet as indicated in the step 6 (S6). Post receiving the SUCI, the HN 103 initiates the SUCI de-concealment procedure. Further, HN 103 may generate the shared secret using PQC key decapsulation as indicated in the step 7 (S7) and uses combined shared generation, and the KDF for multiple key generation as indicated in the step 8 (S8). Later, the HN 103 validates the integrity of the SUCI packet using the HMAC function and completes SUCI concealment using an AES decryption function as indicated in the step 9 (S9). Because of multiple PQC algorithms used in SUPI concealment and SUCI de-concealment making both of them quantum safe and more reliable.

[0316] Figure 4A illustrates a flow diagram of hybrid SUPI concealment at the UE 101, using legacy and PQC based shared key encryption, in accordance with some embodiments of the present disclosure. Figure 4A depicts the process of performing Hybrid SUPI concealment. Here, instead of relying either on elliptical curve based public key cryptography (which is not quantum secure) or on post quantum safe cryptography algorithms (which is not well tested), a hybrid combination of classical algorithm with PQC algorithm may be used for encryption and decryption of the SUPI.

[0317] At step 1, the UE 101 generates an ephemeral public and private key pair based on elliptical curve. At step 2, the UE 101 generates the shared key (s1) using elliptical curve based diffie-hellman key agreement. It takes the EC based UE private key and the HN 103 public key and generates the shared key. After generating the shared key, the (s), in step 3, the UE 101 may receive the shared key(s) as input and may generate multiple keys similar to ECIES scheme like ICB, MAC key and AES encryption key using KDF. At step 4, the UE 101 may use symmetric key encryption to conceal the SUPI and generate an intermediate cipher text. At step 5, the UE 101 may use asymmetric key encryption based on the PQC algorithm to encrypt intermediate cipher text. PQC based encryption takes the PQC based HN 103 public key, and the intermediate cipher text as input, and generates the concealed SUPI as output. Further, in step 6, the UE 101 may use the HMAC function to derive the MAC tag corresponding to the encrypted SUPI, which is required to provide integrity. Overall, embodiments herein provide hybrid encryption for SUCI concealment using ECIES along with post quantum safe cryptographic encryption.

[0318] Further, after SUPI concealment at UE 101, the scheme output may be sent to HN 103. Generally, the scheme output may include the encrypted SUPI and other parameters that are required for smooth de-concealment of SUCI at the HN 103 end. In proposed SUPI concealment, the scheme output will include EC based UE public key, cipher-text and MAC-tag similar to classical ECIES based SUPI concealment.

[0319] Figure 4B illustrates a flow diagram of hybrid SUCI deconcealment at the UE 101, using legacy and PQC based shared key decryption, in accordance with some embodiments of the present disclosure. Figure 4b depicts the process of Hybrid SUPI de-concealment. Here, after receiving the SUCI from the UE 101, the HN 103 may retrieve the EC based UE public key, cipher text, and MAC-tag associated with it. At step 1, the HN 103 may generate shared key using an elliptical curve based diffie-hellman key agreement. It takes the EC based UE public key and the HN 103 private key and generates the shared key. Further, the generated shared key may be used in step 3 for key derivation. In step 2, the KDF takes the shared key as input and may generate multiple keys similar to SUPI concealment. In step 4, the HN 103 may use asymmetric key decryption to initiate the SUCI decryption. The HN 103 uses PQC based decryption, which takes HN 103 private key, cipher text and generates an intermediate cipher text. The HN 103 may use symmetric key decryption to de-conceal the intermediate cipher-text. In step 5, the HN 103 validates integrity of the received SUCI using the HMAC function. Overall, embodiments herein combine elliptical curves-based procedures of the ECIES scheme with post quantum safe cryptographic algorithm in SUCI de-concealment.

[0320] Figure 4C illustrates a sequence diagram of hybrid SUPI concealment and deconcealment using legacy and PQC based shared key encryption and decryption, in accordance with some embodiments of the present disclosure.

[0321] As illustrated in Figure 4C, initially multiple ECC based public key and PQC based HN 103 public key may provision to the UE 101, during SIM provisioning as indicated in the step 1 (S1). Later, when the UE 101 wants to initiate SUPI concealment, the UE 101 performs PQC based key encapsulation for generating the shared key (s1), and the shared key (s2), and uses the HN 103 public key and UE EC private key as indicated in the step 2 (S2). At step 3 (S3), the UE 101 generates encrypted key and MAC key, ICB from shared key using KDF. Later, it uses AES encryption and encrypt SUPI and may generate intermediate cipher text value as indicated in the step 4 (S4). At step 5 (S5) the UE 101 may encrypt intermediate cipher text value using PQC based encryption. At step 6 (S6) the UE 101 may generate MAC tag of encrypted SUPI using HMAC. These steps are the part of SUPI concealment. After completion of SUPI concealment, the UE 101 creates the scheme output, which may include multiple Encrypted shared key(s), Ciphertext(s), and Mac-Tag(s). Here, the cipher-text comprises concealed SUPI and mactag, which includes the mac of concealed SUPI. The scheme output is transferred from the UE 101 to the HN 103 as a part of the SUCI packet as indicated in the step 7 (S7). Post receiving the SUCI, the HN 103 initiates the SUCI de-concealment procedure. Further, HN 103 may generate the shared secret using PQC key decapsulation as indicated in the step 7 (S7). At step 8, the HN 103 may generate shared secret key using HN 103 EC private key and UE EC based public key. At step 9, the HN 103 may generate decrypted key, MAC key, ICB from shared keys using KDF. The HN 103 may decrypt the SUPI using PQC based decapsulation as indicated in the step 10 and the HN 103 may decrypt the intermediate cipher text using decrypted key with AES. At step 11 (S11) the HN 103 may validate the cipher text value.

[0322] Figure 5A illustrates a flow diagram of Hybrid SUPI concealment at UE 101, using PQC and PQC based encryption in parallel way, in accordance with some embodiments of the present disclosure. Figure 5A depicts the process of performing Hybrid SUPI concealment. Here, instead of relying just on single post quantum safe cryptography algorithm (which may be not well tested or secure), a hybrid combination of multiple PQC algorithms may be used. At step 1a, the UE 101 may use PQC based encryption algorithm 1. Here, PQC based encryption take plaintext- 1 (half of SUPI) and the PQC based HN 103 public key as inputs and the generated cipher text-1 as output. Similarly, at step 1b, the UE 101 may use PQC based encryption algorithm 2. Here, the PQC based encryption takes plaintext-2 (other half of SUPI) and the PQC based HN 103 public key as inputs and the generated cipher text-2 as output. Overall, embodiments herein provide hybrid encryption based SUCI concealment using multiple post quantum safe cryptographic algorithms parallel way. Further, after SUPI concealment at UE 101, the scheme output may be sent to the HN 103. Generally, the scheme output may include the encrypted SUPI and other parameters that are required for smooth de-concealment of SUCI at the HN 103 end.

[0323] Figure 5B illustrates a block diagram of modified scheme output based on Hybrid SUPI concealment using PQC and PQC based shared key encryption in a parallel way, in accordance with some embodiments of the present disclosure. As illustrated in Figure 6B, a new scheme output for hybrid based SUPI concealment and de-concealment using PQC + PQC based encryption is proposed. In proposed SUPI concealment, cipher-text-1, cipher-text-2 needs to be sent in the scheme output.

[0324] Figure 5C illustrates a flow diagram of hybrid SUCI deconcealment at HN 103, using PQC and PQC based decryption in parallel way. Figure 5C depicts the process of Hybrid SUCI de-concealment at the HN 103. Here, instead of relying just on a single post quantum safe cryptography algorithm (which may be not well tested or secure), a hybrid combination of multiple PQC algorithms may be used. At step 1a, the HN 103 may use PQC based encryption algorithm 1. Here, PQC based encryption take ciphertext-1 and PQC based HN 103 public key as input and generated plaintext-1 (first half of SUPI) as output. Similarly, at step 1b, the HN 103 may use PQC based encryption algorithm 2. Here, the PQC based encryption take ciphertext-2 and the PQC based HN 103 public key as input and generated plaintext-2 (second half of SUPI) as output. Overall, embodiments herein provide hybrid encryption based SUCI concealment using multiple post quantum safe cryptographic algorithms parallel way.

[0325] Figure 6A illustrates a flow diagram of hybrid SUPI concealment at UE 101, using PQC and PQC based encryption in a sequential way, in accordance with some embodiments of the present disclosure. Figure 6A depicts the process of Hybrid SUPI concealment. Here, instead of relying just on single post quantum safe cryptography algorithm (which may be not well tested or secure), a hybrid combination of multiple PQC algorithms may be used. At step 1 of Hybrid SUPI concealment at UE 101, the UE 101 may use PQC based encryption algorithm 1. Here, PQC based encryption take plaintext (SUPI) and PQC based HN 103 public key as input and generated intermediate cipher text as output. At step 2, the UE 101 uses another PQC based encryption algorithm 2. Here, the PQC based encryption takes intermediate cipher text and PQC based HN 103 public key as input and generates the final cipher text or concealed SUPI. Overall, embodiments herein provide a hybrid based encryption for SUCI concealment using multiple post quantum safe cryptographic algorithms by doing the concealment and de-concealment in sequential way. Further, after SUPI concealment at UE 101, the scheme output may be sent to the HN 103. Generally, the scheme output may include encrypted SUPI and other parameters that are required for smooth de-concealment of SUCI at the HN 103 end.

[0326] Figure 6B illustrates a block diagram of modified scheme output based on Hybrid SUPI concealment using PQC and PQC based encryption, in accordance with some embodiments of the present disclosure. As illustrated in Figure 6B, a new scheme output for hybrid based SUPI concealment and de-concealment using PQC and PQC based encryption is proposed. In proposed SUPI concealment, cipher-text needs to be sent with scheme output.

[0327] Figure 6C illustrates a flow diagram of Hybrid SUPI de-concealment at HN 103, using PQC and PQC based decryption in sequential way, in accordance with some embodiments of the present disclosure. As illustrated in Figure 6C, which depicts Hybrid SUPI de-concealment. Here, instead of relying just on a single post quantum safe cryptography algorithm (which may be not well tested or secure), a hybrid combination of multiple PQC algorithms may be used. At step 1 of Hybrid SUPI de-concealment at the HN103, the HN103may use PQC based algorithm 2. Here, PQC decryption procedure takes cipher-text and PQC based HN 103 public key-2 as input and generated intermediate cipher text as output. At step 2, UE 101 uses another PQC based encryption algorithm 1. Here PQC decryption takes intermediate cipher text and PQC based HN 103 public key-1 as input and generate plain-text SUPI. Overall, embodiments herein provide hybrid based encryption for SUCI concealment using multiple post quantum safe cryptographic algorithms by doing the concealment and de-concealment in a sequential way.

[0328] Figure 6D illustrates a sequence diagram of hybrid SUPI concealment and deconcealment using PQC and PQC based shared key encryption and decryption, in accordance with some embodiments of the present disclosure. As illustrated in Figure 6D, initially multiple PQC based first HN 103 public key and PQC based second HN 103 public key may provision to the UE 101, during SIM provisioning as indicated in the step 1 (S1). Later, when the UE 101 wants to initiate SUPI concealment, the UE 101 may encrypt SUPI using PQC based HN 103 public key and may generate intermediate cipher text as indicated in the step 2 (S2). At step 3 (S3), the UE 101 may encrypt intermediate cipher-text suing PQC based HN 103 public key and may generate final cipher text. The final cipher text may be transmitted to the HN 103 as indicated in the step 4 (S4). The HN 103 may decrypt the cipher text using the first PQC based HN 103 public key and may generate intermediate cipher text as indicated in the step 5 (S5). At step 6 (S6) the HN 103 may decrypt the intermediate cipher text using PQC based HN 103 public key and may generate the SUPI or plaintext.

[0329] Figure 7A shows a flowchart illustrating a method 700a for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key exchange, in accordance with some embodiments of the present disclosure.

[0330] As illustrated in Figure 7A, the method 700a may comprise one or more steps. The method 700a may be described in the general context of computer executable instructions. Generally, computer executable instructions can include routines, programs, objects, components, data structures, procedures, modules, and functions, which perform particular functions or implement particular abstract data types.

[0331] The order in which the method 700a is described is not intended to be construed as a limitation, and any number of the described method blocks can be combined in any order to implement the method. Additionally, individual blocks may be deleted from the methods without departing from the scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or combination thereof.

[0332] At block 702, the method 700a comprises generating an ephemeral public key and an ephemeral private key based on an Elliptical Curve (EC) key generation technique. The operations of block 702 may be performed by the processor 205 (particularly may be performed by the generation unit 215) of Figure 2B.

[0333] At block 704, the method 700a comprises generating a first ephemeral shared key based on the ephemeral private key and an Elliptical Curve (EC) based home network public key. The operations of block 704 may be performed by the processor 205 (particularly may be performed by the generation unit 215) of Figure 2B.

[0334] At block 706, the method 700a comprises generating a second ephemeral shared key and an encrypted shared key based on a Post-Quantum Cryptography (PQC) based public key associated with the home network 103. The operations of block 706 may be performed by the processor 205 (particularly may be performed by the generation unit 215) of Figure 2B.

[0335] At block 708, the method 700a comprises generating an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. The operations of block 708 may be performed by the processor 205 (particularly may be performed by the generation unit 215) of Figure 2B.

[0336] At block 710, the method 700a comprises generating a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key. The operations of block 710 may be performed by the processor 205 (particularly may be performed by the generation unit 215) of Figure 2B.

[0337] At block 712, the method 700a comprises transmitting a registration request for registering the UE 101 with the home network along with the ephemeral public key, the encrypted shared key, the cipher-text value, and the MAC-tag value. The operations of block 712 may be performed by the processor 205 (particularly may be performed by the transmitting unit 217) of Figure 2B.

[0338] Figure 7B shows a flowchart illustrating a method 700b for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key exchange, in accordance with some embodiments of the present disclosure.

[0339] As illustrated in Figure 7B, the method 700b may comprise one or more steps. The method 700b may be described in the general context of computer executable instructions. Generally, computer executable instructions can include routines, programs, objects, components, data structures, procedures, modules, and functions, which perform particular functions or implement particular abstract data types.

[0340] The order in which the method 700b is described is not intended to be construed as a limitation, and any number of the described method blocks can be combined in any order to implement the method. Additionally, individual blocks may be deleted from the methods without departing from the scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or combination thereof.

[0341] At block 714, the method 700b comprises receiving a registration request from the UE 101, wherein the registration request comprises an ephemeral public key, an encrypted shared key, a cipher-text value, and a message authentication code (MAC) tag value. The operations of block 714 may be performed by the processor 211 (particularly may be performed by the receiving unit 219) of Figure 2C.

[0342] At block 716, the method 700b comprises generating a first ephemeral shared key based at least on the ephemeral public key and an Elliptical Curve Cryptography (ECC) based public key associated with the home network 103. The operations of block 716 may be performed by the processor 211 (particularly may be performed by the generation unit 221) of Figure 2C.

[0343] At block 718, the method 700b comprises generating a second ephemeral shared key based on the encrypted shared key and a Post-Quantum Cryptography (PQC) based private key associated with the home network 103. The operations of block 718 may be performed by the processor 211 (particularly may be performed by the generation unit 221) of Figure 2C.

[0344] At block 720, the method 700b comprises generating an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. The operations of block 710 may be performed by the processor 211 (particularly may be performed by the generation unit 221) of Figure 2C.

[0345] At block 722, the method 700b comprises generating an ephemeral decryption key and an ephemeral MAC key based at least on the ephemeral hybrid shared key. The operations of block 722 may be performed by the processor 211 (particularly may be performed by the generation unit 221) of Figure 2C.

[0346] At block 724, the method 700b comprises generating plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key. The operations of block 724 may be performed by the processor 211 (particularly may be performed by the generation unit 221) of Figure 2C.

[0347] At block 726, the method 700b comprises registering the UE 101 with the home network based on the generated plaintext. The operations of block 726 may be performed by the processor 211 (particularly may be performed by the registering unit 221) of Figure 2C.

[0348] Figure 7C shows a flowchart illustrating a method 700c for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key exchange, in accordance with some embodiments of the present disclosure.

[0349] As illustrated in Figure 7C, the method 700c may comprise one or more steps. The method 700c may be described in the general context of computer executable instructions. Generally, computer executable instructions can include routines, programs, objects, components, data structures, procedures, modules, and functions, which perform particular functions or implement particular abstract data types.

[0350] The order in which the method 700c is described is not intended to be construed as a limitation, and any number of the described method blocks can be combined in any order to implement the method. Additionally, individual blocks may be deleted from the methods without departing from the scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or combination thereof.

[0351] At block 728, the method 700c comprises generating a first ephemeral shared key and a first encrypted shared key based on a first Post-Quantum Cryptography (PQC) based home network public key. The operations of block 728 may be performed by the processor 205 (particularly may be performed by the generation unit 215) of Figure 2B.

[0352] At block 730, the method 700c comprises generating a second ephemeral shared key and a second encrypted shared key based on a second PQC based home network public key. The operations of block 730 may be performed by the processor 205 (particularly may be performed by the generation unit 215) of Figure 2B.

[0353] At block 732, the method 700c comprises generating an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key. The operations of block 734 may be performed by the processor 205 (particularly may be performed by the generation unit 215) of Figure 2B.

[0354] At block 734, the method 700c comprises generating a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key. The operations of block 736 may be performed by the processor 205 (particularly may be performed by the generation unit 215) of Figure 2B.

[0355] At block 736, the method 700c comprises transmitting a registration request for registering the UE 101 with the home network along with the first encrypted shared key, the second encrypted shared key, the cipher-text value, and the MAC-tag value. The operations of block 736 may be performed by the processor 205 ((particularly may be performed by the transmitting unit 217) of Figure 2B.

[0356] Figure 7d shows a flowchart illustrating a method 700d for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key exchange, in accordance with some embodiments of the present disclosure.

[0357] As illustrated in Figure 7d, the method 700d may comprise one or more steps. The method 700d may be described in the general context of computer executable instructions. Generally, computer executable instructions can include routines, programs, objects, components, data structures, procedures, modules, and functions, which perform particular functions or implement particular abstract data types.

[0358] The order in which the method 700d is described is not intended to be construed as a limitation, and any number of the described method blocks can be combined in any order to implement the method. Additionally, individual blocks may be deleted from the methods without departing from the scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or combination thereof.

[0359] At block 738, the method 700d comprises receiving a registration request from the UE, wherein the registration request comprises an ephemeral public key, an encrypted shared key, a cipher-text value, and a message authentication code (MAC) tag value. The operations of block 738 may be performed by the processor 211 (particularly may be performed by the receiving unit 219) of Figure 2C.

[0360] At block 740, the method 700d comprises generating a first ephemeral shared key based on the first encrypted shared key and a first Post-Quantum Cryptography (PQC) based private key associated with the home network 103. The operations of block 740 may be performed by the processor 211 (particularly may be performed by the generation unit 221) of Figure 2C.

[0361] At block 742, the method 700d comprises generating a second ephemeral shared key based on the second encrypted shared key and a second PQC based private key associated with the home network 103. The operations of block 742 may be performed by the processor 211 (particularly may be performed by the generation unit 221) of Figure 2C.

[0362] At block 744, the method 700d comprises generating a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key. The operations of block 736 may be performed by the processor 211 (particularly may be performed by the generation unit 221) of Figure 2C.

[0363] At block 746, the method 700c comprises generating an ephemeral decryption key and an ephemeral MAC key based at least on ephemeral hybrid shared key. The operations of block 746 may be performed by the processor 211 ((particularly may be performed by the generation unit 221) of Figure 2C.

[0364] At block 748, the method 700d comprises generating plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key. The operations of block 748 may be performed by the processor 211 ((particularly may be performed by the generation unit 221) of Figure 2C.

[0365] At block 750, the method 700d comprises registering the UE 101 with the home network 103 based on the generated plaintext. The operations of block 750 may be performed by the processor 211 ((particularly may be performed by the registering unit 223) of Figure 2C.

[0366] Figure 8A shows a flowchart illustrating a method 800a for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0367] At block 802, the method 800a comprises generating an ephemeral public key and an ephemeral private key based at least on Elliptical Curve (EC) key generation technique. The operations of block 802 may be performed by the processor 205 (particularly, by the generating unit 215) of Figure 2B.

[0368] At block 804, the method 800a comprises generating an ephemeral shared key based on the ephemeral private key and an EC based home network public key. The operations of block 804 may be performed by the processor 205 (particularly, by the generation unit 215) of Figure 2B.

[0369] At block 806, the method 800a comprises generating an ephemeral encryption key and an ephemeral message authentication code (MAC) key based at least on ephemeral hybrid shared key. The operations of block 806 may be performed by the processor 205 (particularly, by the generation unit 215) of Figure 2B.

[0370] At block 808, the method 800a comprises generating an intermediate cipher-text value by performing symmetric encryption of a plaintext based on the ephemeral encrypted key. The operations of block 808 may be performed by the processor 205 (particularly, by the generation unit 215) of Figure 2B.

[0371] At block 810, the method 800a comprises generating a cipher text value based on the intermediate cipher-text value and a Post Quantum Cryptography (PQC) based home network public key. The operations of block 810 may be performed by the processor 205 (particularly, by the generation unit 215) of Figure 2B.

[0372] At block 812, the method 800a comprises generating a MAC tag value based at least on the cipher text value and the ephemeral MAC-tag key. The operations of block 812 may be performed by the processor 205 (particularly, by the generation unit 215) of Figure 2B.

[0373] At block 814, the method 800a comprises transmitting a registration request for registering the UE 101 with the home network 103 along with the ephemeral public key, the cipher-text value, and the MAC-tag value. The operations of block 814 may be performed by the processor 205 (particularly, by the transmitting unit 217) of Figure 2B.

[0374] Figure 8B shows a flowchart illustrating a method 800b for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0375] At block 816, the method 800b comprises receiving a registration request from the UE, wherein the registration request comprises an ephemeral public key, a cipher-text value and a message authentication code (MAC) tag value. The operations of block 816 may be performed by the processor 211 (particularly, by the receiving unit 219) of Figure 2C.

[0376] At block 818, the method 800b comprises generating an ephemeral shared key based on the ephemeral public key and an Elliptical Curve (EC) based private key associated with the home network 103. The operations of block 818 may be performed by the processor 211 (particularly, by the generation unit 221) of Figure 2C.

[0377] At block 820, the method 800b comprises generating an ephemeral encryption key and an ephemeral message authentication code (MAC) key based at least on ephemeral hybrid shared key. The operations of block 820 may be performed by the processor 211 (particularly, by the generation unit 221) of Figure 2C.

[0378] At block 822, the method 800a comprises generating an intermediate cipher text value by applying Post Quantum Cryptography (PQC) decryption on the cipher-text value based on a PQC based home network public key. The operations of block 822 may be performed by the processor 211 (particularly, by the generation unit 221) of Figure 2C.

[0379] At block 824, the method 800b comprises generating a plaintext by performing a symmetric decryption of the intermediate cipher-text value based at least on the ephemeral decrypted key. The operations of block 824 may be performed by the processor 211 (particularly, by the generation unit 221) of Figure 2C.

[0380] At block 826, the method 800b comprises registering the UE 101 with the home network based on the generated plaintext. The operations of block 826 may be performed by the processor 205 (particularly, by the registering unit 223) of Figure 2C.

[0381] Figure 8c shows a flowchart illustrating a method 800c for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0382] At block 828, the method 800c comprises splitting a plaintext into a first part and a second part. The operations of block 828 may be performed by the processor 205 (particularly, by the splitting unit 225) of Figure 2D.

[0383] At block 830, the method 800c comprises generating a first cipher-text value based on a first Post-Quantum Cryptography (PQC) based public key associated with the home network 103. The operations of block 830 may be performed by the processor 205 (particularly, by the generation unit 227) of Figure 2D.

[0384] At block 832, the method 800c comprises generating a second cipher-text value based on a second PQC based public key associated with the home network 103. The operations of block 832 may be performed by the processor 205 (particularly, by the generation unit 227) of Figure 2D.

[0385] At block 834, the method 800c comprises transmitting a registration request for registering the UE 101 with the home network 103 along with the first cipher-text value and the second cipher-text value. The operations of block 834 may be performed by the processor 205 (particularly, by the transmitting unit 229) of Figure 2D.

[0386] Figure 8D shows a flowchart illustrating a method 800d for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0387] At block 836, the method 800d comprises receiving a registration request from the UE 101, wherein the registration request comprises a first cipher-text value and a second cipher-text value. The operations of block 836 may be performed by the processor 211 (particularly, by the receiving unit 231) of Figure 2E.

[0388] At block 838, the method 800d comprises generating a first part of a plaintext by decrypting the first cipher-text value based on a first Post-Quantum Cryptography (PQC) private key associated with the home network 103. The operations of block 838 may be performed by the processor 211 (particularly, by the generation unit 233) of Figure 2E.

[0389] At block 840, the method 800d comprises generating a second part of the plaintext by decrypting the second cipher-text value based on a second PQC private key associated with the home network 103. The operations of block 840 may be performed by the processor 211 (particularly, by the generation unit 233) of Figure 2E.

[0390] At block 842, the method 800d comprises generating the plaintext by combining the first part and the second part of the plaintext. The operations of block 842 may be performed by the processor 211 (particularly, by the generation unit 233) of Figure 2E.

[0391] At block 844, the method 800d comprises registering the UE 101 with the home network 103 based on the generated plaintext. The operations of block 844 may be performed by the processor 211 (particularly, by the registering unit 235) of Figure 2E.

[0392] Figure 8E shows a flowchart illustrating a method 800e for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0393] At block 846, the method 800e comprises generating an intermediate cipher-text value based on a first Post Quantum Cryptography (PQC) based home network public key and a plain text. The operations of block 846 may be performed by the processor 205 (particularly, by the generating unit 215) of Figure 2B.

[0394] At block 848, the method 800e comprises generating a cipher text value based on the intermediate cipher-text value and a second PQC based home network public key. The operations of block 848 may be performed by the processor 205 (particularly, by the generation unit 215) of Figure 2B.

[0395] At block 850, the method 800e comprises transmitting a registration request along with the cipher-text value to the HN 103 for registering the UE 101 with the home network 103. The operations of block 850 may be performed by the processor 205 (particularly, by the transmitting unit 217) of Figure 2B.

[0396] Figure 8F shows a flowchart illustrating a method 800f for registering a User Equipment (UE) 101 with a Home Network (HN) 103 using hybrid key encryption, in accordance with some embodiments of the present disclosure.

[0397] At block 852, the method 800f comprises receiving a registration request, wherein the registration request comprises a cipher-text value. The operations of block 852 may be performed by the processor 211 (particularly, by the receiving unit 231) of Figure 2E.

[0398] At block 854, the method 800f comprises generating a cipher text value based on the intermediate cipher-text value and a second PQC based home network public key. The operations of block 854 may be performed by the processor 211 (particularly, by the generation unit 233) of Figure 2E.

[0399] At block 856, the method 800e comprises generating a plain text based on the intermediate cipher text value and a first PQC based home network private key. The operations of block 856 may be performed by the processor 211 (particularly, by the generation unit 233) of Figure 2E.

[0400] At block 858, the method 800e comprises registering the UE 101 with the home network 103 based on the generated plaintext. The operations of block 858 may be performed by the processor 211 (particularly, by the generation unit 235) of Figure 2E.

[0401] Advantages of the present disclosure

[0402] In an embodiment, the present disclosure provides shared key generation which is combined with legacy ECC algorithms and PQC algorithms and derive the shared key. This key performs SUPI concealment for primary authentication between UE and HN. Further, the present disclosure provides hybrid encryption method that allows minimal modification in current 3GPP specification to support hybrid security. As a result, the present disclosure protects against "store now decrypt later" attacks.

[0403] In an embodiment, the present disclosure generates a hybrid shared key which may be used for SUPI concealment. This shared key provides security against quantum threats with high-security assurance. This hybrid shared key may also be used for encrypting data between UE and network and not limited to SUPI.

[0404] The terms "including", "comprising", "having" and variations thereof mean "including but not limited to", unless expressly specified otherwise. The enumerated listing of items does not imply that any or all of the items are mutually exclusive, unless expressly specified otherwise. The terms "a", "an" and "the" mean "one or more", unless expressly specified otherwise.

[0405] In alternative embodiments, certain operations may be performed in a different order, modified, or removed. Moreover, steps may be added to the above-described logic and still conform to the described embodiments. Further, operations described herein may occur sequentially or certain operations may be processed in parallel. Yet further, operations may be performed by a single processing unit or by distributed processing units.

[0406] Finally, the language used in the specification has been principally selected for readability and instructional purposes, and it may not have been selected to delineate or circumscribe the inventive subject matter. It is therefore intended that the scope of the invention be limited not by this detailed description, but rather by any claims that issue on an application based here on. Accordingly, the disclosure of the embodiments of the invention is intended to be illustrative, but not limiting, of the scope of the invention, which is set forth in the following claims.

[0407]

Claims

1.A method (700a) performed by a user equipment (UE) for registering the UE with a Home Network (HN) (103) using a hybrid key exchange, the method (700a) comprising:generating (702) an ephemeral public key and an ephemeral private key based on an Elliptical Curve (EC) key generation technique;generating (704) a first ephemeral shared key based on the ephemeral private key and an Elliptical Curve (EC) based a home network public key;generating (706) a second ephemeral shared key and an encrypted shared key based on a Post-Quantum Cryptography (PQC) based on a public key associated with the home network;generating (708) an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key;generating (710) a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key; andtransmitting (712) a registration request for registering the UE (101) with the home network (103) along with the ephemeral public key, the encrypted shared key, the cipher-text value, and the MAC-tag value.2.The method of claim 1, wherein:generating the first ephemeral shared key comprises generating the first ephemeral shared key by applying an Elliptical Curve Cryptography (ECC) technique on the ephemeral private key and the EC based home network public key, andgenerating the second ephemeral shared key and the encrypted shared key comprises generating the second ephemeral shared key and the encrypted shared key by applying a PQC Key Encapsulation Mechanism (KEM) technique on the PQC based public key associated with the home network (103).3.The method of claim 1, wherein generating the cipher-text value and the MAC-tag value based at least on the ephemeral hybrid shared key comprises:generating an ephemeral encryption key and an ephemeral MAC key based at least on ephemeral hybrid shared key;generating the cipher-text value by performing symmetric encryption of a plaintext based on the ephemeral encrypted key; andgenerating the MAC-tag value by applying a MAC function on the ephemeral MAC key and the cipher-text value.4.The method of claim 1, further comprising:encrypting data to transmit from the UE (101) to the HN (103) using the generated ephemeral hybrid shared key.5.The method of claim 1, further comprising:creating a security profile in the UE (101) and the HN (103), wherein the security profile is created by:creating a PQC based profile using one or more PQC parameters for encryption, decryption, encapsulation and de-capsulation of identities and data transmitted from the UE (101) to HN (103); andcreating a hybrid profile using one or more hybrid parameters for encryption, decryption, encapsulation and de-capsulation of identities and data transmitted from the UE (101) to HN (103).6.The method of claim 5, further comprising:performing primary authentication using the one or more PQC parameters and the one or more hybrid parameters at UE (101) before transmitting the data from the UE (101) to HN (103).7.A method performed by a home network (HN) (103) for registering a user euipment (UE) (101), the method comprising:receiving, from the UE, a registration request, wherein the registration request comprises an ephemeral public key, an encrypted shared key, a cipher-text value, and a message authentication code (MAC) tag value;generating a first ephemeral shared key based at least on the ephemeral public key and an Elliptical Curve Cryptography (ECC) based public key associated with the home network (103);generating a second ephemeral shared key based on the encrypted shared key and a Post-Quantum Cryptography (PQC) based private key associated with the home network (103);generating an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key;generating an ephemeral decryption key and an ephemeral MAC key based at least on the ephemeral hybrid shared key;generating plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key; andregister the UE (101) with the home network (103) based on the generated plaintext.8.The method of claim 7,wherein generating the first ephemeral shared key comprises generating the first ephemeral shared key by applying an Elliptical Curve Cryptography (ECC) technique on the ephemeral public key and the ECC based home network public key, andwherein generating the second ephemeral shared key comprises generating the second ephemeral shared key by applying a PQC Key Decapsulation Mechanism (KDM) technique on the encrypted shared hey and the PQC based public key associated with the home network (103).9.A user equipment (UE) for registering the UE with a Home Network (HN) (103) using a hybrid key exchange, the UE comprising:a transceiver; anda controller configured to:generate an ephemeral public key and an ephemeral private key based on an Elliptical Curve (EC) key generation technique,generate a first ephemeral shared key based on the ephemeral private key and an Elliptical Curve (EC) based a home network public key,generate a second ephemeral shared key and an encrypted shared key based on a Post-Quantum Cryptography (PQC) based on a public key associated with the home network,generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key,generate a cipher-text value and a message authentication code (MAC) tag value based at least on the ephemeral hybrid shared key, andtransmit a registration request for registering the UE (101) with the home network (103) along with the ephemeral public key, the encrypted shared key, the cipher-text value, and the MAC-tag value.10.The UE of claim 9, wherein the controller is further configured to:generate the first ephemeral shared key by applying an Elliptical Curve Cryptography (ECC) technique on the ephemeral private key and the EC based home network public key, andgenerate the second ephemeral shared key and the encrypted shared key by applying a PQC Key Encapsulation Mechanism (KEM) technique on the PQC based public key associated with the home network (103).11.The UE of claim 9, wherein the controller is further configured to:generate an ephemeral encryption key and an ephemeral MAC key based at least on ephemeral hybrid shared key,generate the cipher-text value by performing symmetric encryption of a plaintext based on the ephemeral encrypted key,generate the MAC-tag value by applying a MAC function on the ephemeral MAC key and the cipher-text value, andencrypt data to transmit from the UE (101) to the HN (103) using the generated ephemeral hybrid shared key.12.The UE of claim 9, wherein the controller is further configured to:create a security profile in the UE (101) and the HN (103), wherein the security profile is created by: creating a PQC based profile using one or more PQC parameters for encryption, decryption, encapsulation and de-capsulation of identities and data transmitted from the UE (101) to HN (103), and creating a hybrid profile using one or more hybrid parameters for encryption, decryption, encapsulation and de-capsulation of identities and data transmitted from the UE (101) to HN (103).13.The UE of claim 9, wherein the controller is further configured to:perform primary authentication using the one or more PQC parameters and the one or more hybrid parameters at UE (101) before transmitting the data from the UE (101) to HN (103).14.A home network (HN) (103) for registering a user euipment (UE) (101), the home network comprising:a transceiver; anda controller configured to:receive, from the UE, a registration request, wherein the registration request comprises an ephemeral public key, an encrypted shared key, a cipher-text value, and a message authentication code (MAC) tag value,generate a first ephemeral shared key based at least on the ephemeral public key and an Elliptical Curve Cryptography (ECC) based public key associated with the home network (103),generate a second ephemeral shared key based on the encrypted shared key and a Post-Quantum Cryptography (PQC) based private key associated with the home network (103),generate an ephemeral hybrid shared key based on the first ephemeral shared key and the second ephemeral shared key,generate an ephemeral decryption key and an ephemeral MAC key based at least on the ephemeral hybrid shared key,generate plaintext by performing a symmetric decryption of the cipher-text value based at least on the ephemeral decrypted key, andregister the UE (101) with the home network (103) based on the generated plaintext.15.The home network of claim 14, wherein the controller is further configured to:generate the first ephemeral shared key by applying an Elliptical Curve Cryptography (ECC) technique on the ephemeral public key and the ECC based home network public key, andgenerate the second ephemeral shared key by applying a PQC Key Decapsulation Mechanism (KDM) technique on the encrypted shared hey and the PQC based public key associated with the home network (103).