Mixed pre-shared keys with post-quantum cryptography

By integrating post-quantum cryptography mechanisms with pre-shared keys through pseudorandom functions, the key exchange process becomes resistant to both classical and quantum adversaries, ensuring secure and authentic communications.

GB2643757APending Publication Date: 2026-03-04NOKIA TECHNOLOGIES OY
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
GB · GB
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-02
Publication Date
2026-03-04

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method of mixing pre-shared keys with post-quantum cryptography (PQC) comprises sending by a first apparatus a key exchange request to a second apparatus, wherein the key exchange request comprises
Need to check novelty before this filing date? Find Prior Art

Description

[0002] Key exchange is a fundamental process in cryptography where two parties securely exchange cryptographic keys, enabling encrypted communications between the two parties. SUMMARY

[0003] In a first aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to: send a key exchange request to a second apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM), and information indicating that a post-quantum pre-shared key (PPK) is used; receive a response from the second apparatus, wherein the response to the key exchange request comprises at least a first responder ciphertext generated based on the first public key using the PQC KEM by the second apparatus and information indicating that a PPK is used; and generate a seed key based on a first PQC KEM shared secret extracted from the first responder ciphertext, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

[0004] In a second aspect of the present disclosure, there is provided a second apparatus. The second apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus at least to: receive a key exchange request from a first apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) by the first apparatus and information indicating that a post-quantum pre-shared key (PPK) is used; generate a first PQC KEM shared secret based on the first public key using the PQC KEM; and generate a seed key based on the first PQC KEM shared secret, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

[0005] In a third aspect of the present disclosure, there is provided a method. The method comprises sending, by a first apparatus, a key exchange request to a second apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) and information indicating that a post-quantum pre-shared key (PPK) is used; receiving, by the first apparatus, a response to from the second apparatus, wherein the response to the key exchange request comprises at least a first responder ciphertext generated based on the first public key using the PQC KEM by the second apparatus and information indicating that a PPK is used; and generating, by the first apparatus, a seed key based on a first PQC KEM shared secret extracted from the first responder ciphertext, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

[0006] In a fourth aspect of the present disclosure, there is provided a method. The method comprises receiving, by a second apparatus, a key exchange request from a first apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) by the first apparatus and information indicating that a post-quantum pre-shared key (PPK) is used; generating, by the second apparatus, a first PQC KEM shared secret based on the first public key using the PQC KEM; and generating, by the second apparatus, a seed key based on the first PQC KEM shared secret, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and 2 authenticity of the communication between the first apparatus and the second apparatus.

[0007] In a fifth aspect of the present disclosure, there is provided an apparatus. The apparatus comprises means for sending a key exchange request to a second apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) and information indicating that a post-quantum pre-shared key (PPK) is used; means for receiving a response from the second apparatus, wherein the response to the key exchange request comprises at least a first responder ciphertext generated based on the first public key using the PQC KEM by the second apparatus and information indicating that a PPK is used; and means for generating a seed key based on a first PQC KEM shared secret extracted from the first responder ciphertext, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

[0008] In a sixth aspect of the present disclosure, there is provided an apparatus. The apparatus comprises means for receiving a key exchange request from a first apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) by the first apparatus and information indicating that a post-quantum pre-shared key (PPK) is used; means for generating a first PQC KEM shared secret based on the first public key using the PQC KEM and means for generating a seed key based on the first PQC KEM shared secret, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

[0009] In a seven aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the third aspect or the fourth aspect.

[0010] It is to be understood that the Summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Some example embodiments will now be described with reference to the accompanying drawings, where:

[0012] FIG. 1 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;

[0013] FIG. 2 illustrates an example key exchange process in accordance with some example embodiments of the present disclosure;

[0014] FIG. 3 illustrates an example flowchart of a method implemented at a first apparatus in accordance with some example embodiments of the present disclosure;

[0015] FIG. 4 illustrates an example flowchart of a method implemented at a second apparatus in accordance with some example embodiments of the present disclosure;

[0016] FIG. 5 illustrates a simplified block diagram of a device that is suitable for implementing example embodiments of the present disclosure; and

[0017] FIG. 6 illustrates a block diagram of an example computer readable medium in accordance with some example embodiments of the present disclosure;

[0018] Throughout the drawings, the same or similar reference numerals represent the same or similar element. DETAILED DESCRIPTION

[0019] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.

[0020] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.

[0021] References in the present disclosure to “one embodiment,” “an embodiment,” “an example embodiment,” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.

[0022] It shall be understood that although the terms “first,” “second,”..., etc. in front of noun(s) and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and they do not limit the order of the noun(s). For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.

[0023] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0024] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included.

[0025] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.

[0026] As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.

[0027] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) 5 accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0028] As used herein, the term “communication network” refers to any system that 10 facilitates the transmission of data between two or more entities. This includes, but is not limited to, wide area networks (WANs), local area networks (LANs), satellite communication networks, commercial value-added networks (VANs), ordinary telephone lines, private leased lines, and any combination thereof. The communication network may employ various technologies such as wired, wireless, optical, or any other suitable 15 medium for data transmission. For example, the “communication network” may refer to a network following any suitable communication standards, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrow Band Internet of Things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G), the second generation (2G), 2.5G, 2.75G, the third generation (3G), the fourth generation (4G), 4.5G, the fifth generation (5G), 5.5G, the sixth generation (6G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.

[0029] As used herein, the term “network device” may refer to any hardware or software component that facilitates communication within a network. This includes, but is not limited to, routers, switches, hubs, bridges, gateways, firewalls, access points, modems, and network interface cards (NICs). Network devices may operate using various protocols and technologies, such as Ethernet, Wi-Fi, Bluetooth, Zigbee, and others. These devices can be configured to perform functions such as data routing, packet switching, network security, and traffic management. The term ‘network device’ encompasses both physical devices and virtualized instances that provide equivalent functionality. For example, the term “network device” may refer to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may also refer to a base station (BS) or an access point (AP), for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.

[0030] The term “terminal device” refers to any end-user device that can connect to a network to send or receive data. This includes, but is not limited to, mobile phones, smartphones, tablets, laptops, desktop computers, smartwatches, loT devices, and any other electronic device capable of network communication. Terminal devices may operate using various communication protocols and technologies, such as Wi-Fi, Bluetooth, cellular networks (e.g., 4G, 5G), Ethernet, and others. These devices can be configured to perform functions such as data transmission, reception, processing, and storage. The term ‘terminal device’ encompasses both physical devices and virtualized instances that provide equivalent functionality. For example, the terminal device may refer to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), a Portable Subscriber Station, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehiclemounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node). In the following description, the terms “terminal device”, “communication device”, “terminal”, “user equipment” and “UE” may be used interchangeably.

[0031] As used herein, the term “resource,” refers to any component, device, information, or service that can be utilized to facilitate communication and data exchange. This includes, but is not limited to, bandwidth, processing power, memory, storage, network interfaces, and software applications. Resources may be physical, such as routers, switches, and servers, or virtual, such as virtual machines, cloud services, and software- defined networking components. The term ‘resource’ encompasses both tangible and intangible elements that contribute to the efficient operation and management of the communication network. The term “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” may refer to any resource for performing a communication, for example, a communication between a terminal device and a network device, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other combination of the time, frequency, space and / or code domain resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.

[0032] FIG. 1 illustrates an example communication environment 100 in which example embodiments of the present disclosure can be implemented. In the communication environment 100, a plurality of communication devices, including a first apparatus 110 and a second apparatus 120, can communicate with each other.

[0033] In some example embodiments, the first apparatus 110 or the second apparatus 120 may be a terminal device which may be any type of mobile, fixed or portable terminal, including a mobile phone, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a media computer, a multimedia tablet, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a positioning device, a television receiver, a radio receiver, an e-book device, a gaming device or any combination thereof, including accessories and peripherals of these devices or any combination thereof. In some embodiments, the first apparatus 110 may also support any type of interface for the user (such as a "wearable" circuit, etc.). It is noted that the first apparatus 110 may be another device than a terminal device, and the scope of the present disclosure is not limited in this respect.

[0034] In some example embodiments, the second apparatus 120 or the first apparatus 110 may be a network device which may include, for example, a wireless router configured to provide wireless network coverage to an indoor environment where a user is located. The wireless router may be a network device that complies with the 802.11 series of standards or may be implemented by any suitable device, such as a Wi-Fi access point (AP), and the scope of the present disclosure is not limited in this respect. The second apparatus 120 may, for example, communicate with other network devices (such as a base station) to provide wireless network coverage to terminal devices within a specific range. It is noted that the second apparatus 120 may be another device than a network device., and the scope of the present disclosure is not limited in this respect.

[0035] In some example embodiments, the first apparatus 110 and the second apparatus 120 may be of the same type, e.g., both are terminal devices / network devices, and the scope of the present disclosure is not limited in this respect.

[0036] It is to be understood although in FIG. 1, it is shown that the first apparatus 110 and the second apparatus 120 are connected via one single communication link, that it is merely for a simplified illustration. The first apparatus 110 and the second apparatus 120 may be connected to each other using various methods and technologies. These connections may include, but are not limited to, wired connections, wireless connections, optical connections, satellite connections, hybrid connections. Ad-hot networks, mesh networks, and so on. There also may be other apparatuses, or other networks other than the communication link between the first apparatus 110 and the second apparatus 120 and the scope of the present disclosure is not limited in this respect.

[0037] It is to be understood that the number of apparatuses and their connections shown in FIG. 1 are only for the purpose of illustration without suggesting any limitation. The communication environment 100 may include any suitable number of apparatuses configured to implementing example embodiments of the present disclosure.

[0038] Communications in the communication environment 100 may be implemented according to any proper communication protocol(s), comprising, but not limited to, 1) landline communication protocols including public switching telephony network (PSTN), intranet, ethernet, integrated services digital network (ISDN), digital subscriber line (DSL), Tl / El, VoIP, H.233, signaling system No. 7 (SS7), H.323, X.25, asynchronous transfer mode (ATM), frame relay (FR), etc.; 2) cellular communication protocols of the first generation (1G), the second generation (2G), the third generation (3G), the fourth generation (4G), the fifth generation (5G), 5.5G, the sixth generation (6G), and the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.

[0039] In some example embodiments, the first apparatus 110 and the second apparatus 120 may need to exchange keys for a secure communication. Key exchange is a fundamental process in cryptography where two parties securely exchange cryptographic keys, enabling encrypted and integrity protected communications between them. One of the most well-known key exchange methods is Diffie-Hellman algorithm, which allows two parties to generate a shared secret key over an insecure channel without transmitting the shared secret key itself. The Diffie-Hellman key exchange enables two parties, who have no prior knowledge of each other, to jointly create a shared secret key. This shared secret key and further derived keys can then be used to encrypt and integrity protect subsequent communications using symmetric-key ciphers. The process involves each party generating a private key and a corresponding public key. Both parties then exchange their public keys and use their private keys to compute the shared secret. The advantage of this key exchange method lies in the fact that even if an attacker intercepts the public keys, they cannot easily derive the shared secret without the private keys.

[0040] However, with the development of quantum computing technologies, the traditional Diffie-Hellman key exchange, including its widely used variants such as an Elliptic Curve Diffie-Hellman (ECDH), is vulnerable to attacks by quantum computers. Specifically, a sufficiently powerful quantum computer running Shor's algorithm can efficiently solve the discrete logarithm problem, which underlies the security of Diffie-Hellman key exchange. This would allow a quantum attacker to derive the shared secret from the public values exchanged during the Diffie-Hellman process.

[0041] The cryptographically relevant quantum computers in near future may break traditional cryptographic algorithms deployed widely today. The Internet key exchange protocol version 2 (IKEv2) is one such an example of a cryptosystem that could be broken. The IKEv2 is a well-adopted protocol used to set up a secure and authenticated communication channel, primarily for Internet protocol security (IPsec) virtual private networks (VPN)s, which also uses Diffie-Hellman key exchange process. IPSec is used to secure networks over the internet and within a data center, which also relies on IKEv2 to establish and manage its security associations (SAs). Although IKEv2 is enhanced in IP security maintenance and extensions (IPSECME) working group (WG) at the Internet engineering task force (IETF) to leverage post-quantum cryptography (PQC) algorithms, due to the uncertainty associated with PQC algorithms about the underlying mathematics, compliance issues, unknown vulnerabilities, hardware and software implementations, PQC algorithms have not had sufficient maturing time to rule out classical cryptanalytic attacks and implementation bugs.

[0042] The IKEv2 operates in two phases: Phase 1: establishing a secure, authenticated channel using a Diffie-Hellman key exchange to create a shared secret key; Phase 2: managing the actual data transfer, using the established secure channel to negotiate and maintain IPsec SAs. As seen, the first phase of the IKEv2 involves a Diffie-Hellman (DH) key exchange to establish a shared secret key that will be used for encrypting further communications, which means the IKEv2 will also face the challenge stated above.

[0043] In the Internet Draft (I-D) to the IEFT "Post-quantum Hybrid Key Exchange with ML-KEM in the Internet Key Exchange Protocol Version 2 (IKEv2)" retrieved at https: / / datatracker.ietf.org / doc / draft-kampanakis-ml-kem-ikev2 / , it is discussed the use of module-lattice-based key-encapsulation mechanism (ML-KEM), a type of post-quantum cryptography (PQC) KEM as an additional key exchange in IKEv2 along with the traditional key exchange. Like what has been discussed above, the involvement of PQC algorithms in this approach also suffers from the uncertainty risk associated with PQC algorithms

[0044] In IETF request for comments (RFC) 8784, it is described an extension of IKEv2 to allow it to be resistant to a quantum computer by using pre-shared keys. The general idea is to add an additional secret that is shared between the initiator and the responder; this secret is in addition to the authentication method that is already provided within IKEv2. This secret provides quantum resistance to the IPsec SAs and any subsequent IKE 12 SAs. However, the pre-shared keys in the RFC 8784 are used with traditional cryptography which is also susceptible to attacks from cryptographically relevant quantum computers.

[0045] There is a need to strengthen the Diffie-Hellman key exchange process so that it can be secured against both classical and quantum adversaries.

[0046] In accordance with some example embodiments of the present disclosure, there is provided one or more solutions for an enhanced key exchange process, which protect the current Diffie-Hellman against both classical and quantum adversaries. In the following, embodiments of the present disclosure will be described with reference to FIG. 2, in which some embodiments of the present disclosure will be described with reference to the IKEv2 key exchange process, however, it is to be understood that this is merely for the purpose of illustration, the present disclosure is not limited to the IKEv2 key exchange process. For example, the present disclosure can be applied to the key exchange process of multiplexed application substrate over QUIC encryption (MASQUE), WireGuard and other protocols adopting the Diffie-Hellman key exchange method by adaptively modifying some embodiments in the present disclosure.

[0047] Example embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0048] Referring now to FIG. 2, which illustrates an example key exchange process in accordance with some example embodiments of the present disclosure. The key exchange process occurs between a first apparatus and a second apparatus, for example, the first apparatus 110 and the second apparatus 120 in FIG. 1. In below, the first apparatus 110 will be described as an initiator that initiates a key exchange process with the second apparatus 120, which will be described as a responder that completes the key exchange process together with the first apparatus 110. It is to be understood that the first apparatus 110 and the second apparatus 120 may be exchangeable, that is to say, the second apparatus 120 may initiate the key exchange process which makes it the initiator, and the first apparatus 110 may complete the key exchange process together with the first apparatus which makes it a responder.

[0049] In some example embodiments, the first apparatus 110 initiates a key exchange process by sending (201) a key exchange request to the second apparatus 120. In the key exchange request, the first apparatus 110 may encapsulate information needed for the key 13 exchange in the payload of the request. The key exchange request may comprise at least a public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM), and information indicating that a post-quantum pre-shared key (PPK) is used. In the context of the IKEv2, the key exchange request may be the IKESAINIT request, which is the first message exchanged by the initiator (the first apparatus 110) with the responder (the second apparatus 120). In some example embodiments, the information in the key exchange request may typically include one or more of the following: 1) a header (HDR), which may contain the security parameter indexes (SPIs), version numbers, exchange type, message ID and flags of various sorts. The header is used to identify and manage the IKEv2 messages; 2) a security association of the initiator (SAil) payload, which may contain the proposals for the IKE SA from the initiator. The SAil may include information about the cryptographic algorithms and parameters that the initiator supports and wishes to use for the secure communication. In some example embodiments, the SAil payload may contain the PQC KEM used by the initiator; 3) a key exchange of the initiator (KEi) payload, which may contain the Diffie-Hellman public value of the initiator. The KEi is be used to establish a shared secret between the initiator and the responder, which may be used to derive encryption and authentication keys. In some example embodiments, the KEi may contain a public key 'pki' generated using a PQC key encapsulation mechanism (KEM) by the first apparatus 110, the generation of the public key 'pki' will be described in detail later; 4) a nonce of the initiator (Ni) payload, which may contain a random value generated by the initiator. The Ni is used to ensure the freshness of the exchange and to protect against replay attacks; and 5) an indication of using post-quantum pre-shared keys (PPK), which is a status notification indicating that a PPK is used for the key exchange process.

[0050] It is to be understood that the information listed above is for key exchange in the context of the IKEv2, different information may be needed for different protocols, and the scope of the present disclosure is not limited in this respect.

[0051] In some example embodiments, as stated above, the key exchange of the initiator (KEi) contains a public key generated by the first apparatus 110 using a PQC KEM. PQC KEMs are cryptographic protocols designed to secure communications against the potential threats posed by quantum computers, keys generated and derived by a PQC KEM is considered quantum safe.

[0052] In the following, embodiments will be described with module-lattice-based keyencapsulation mechanism (ML-KEM) as an example PQC KEM to generate the public key, however, it is to be understood that other PQC KEM may also be used to generate the public key, for example, Frodo key encapsulation mechanism (FrodoKEM), Nth-degree truncated polynomial ring units (NTRU), secure and balanced efficiency with rounding (SABER), etc., and the scope of the present disclosure is not limited in this respect.

[0053] Now, the generation of the public key that is put in the KEi payload of the key exchange request will be explained as an example. The first apparatus 110 may generate the public key (encapsulation key) 'pki' and a private key (decapsulation key) 'sk' using a PQC KEM, e.g., the ML-KEM, which may be represented as: ML-KEM-KeyGen () -> (pki, sk) (1) wherein ML-KEM-KeyGen is the PQC KEM key generator used for the generation of the public key and the private key, (pki, sk) are the keys generated with 'pki' being the public key and 'sk' being the private key.

[0054] The first apparatus 110 then puts the generated public key to the KEi pay load of the IKESAINIT request, along with information indicating that a PPK is used for the key exchange process in the status notification, e.g., a status notification USEPPK. The information is to notify the second apparatus 120 that a PPK is used in the IKE SA INIT request. According to the IETF RFC 8784, the information indicating that a PPK is used is the status notification USE PPK and is mandatory. However, along the development of the protocol, other types of status notification other than the USE PPK may be adopted if developed. Also, such information may be different in other protocols, and the scope of the present disclosure is not limited in this respect.

[0055] Upon receiving the key exchange request from the first apparatus 110, which comprises at least the public key 'pki' generated using the post-quantum cryptography (PQC) key generation mechanism (KEM) by the first apparatus 110 and the information indicating that a post-quantum pre-shared key (PPK) is used, the second apparatus 120 generates a shared secret 'pqcss' based on the public key 'pki' using the same PQC KEM. The second apparatus 120 generates a seed key based on the shared secret 'pqc ss', and the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus 120. In some example embodiments, the second apparatus may extract the public key 'pki' from the KEi payload and generate the shared secret 'pqc ss', together with a responder ciphertext 'dr' using an encapsulation algorithm same as the one used by the first apparatus 110 (contained in the SAi payload), which takes the public key 'pki' received from the first apparatus 110 as input. The shared secret is a PQC KEM shared secret, which means it is quantum safe. The encapsulation algorithm may be a ML-KEM same as the ML-KEM used by the first apparatus 100. The process may be represented as: ML-Encaps(pki) -> (dr, pqc ss) (2) wherein ML-Encaps () is the PQC KEM used to generate the shared secret and the responder ciphertext by the second apparatus 200, taking 'pki' as the input, 'dr' being the generated responder ciphertext and 'pqc ss' being the generated shared secret.

[0056] In some example embodiments, to achieve indistinguishability under adaptive chosen ciphertext attack (IND-CCA2) security, the shared secret 'pqc ss' may be concatenated with the responder ciphertext 'dr' to generate a ciphertext 'pqc dr' of the shared secret. In some example embodiments, other technologies may be used to protect the shared PQC secret from adaptive chosen ciphertext attacks (CCA2), e.g., using a onetime signature, or an encrypt-then-MAC (message authentication code) (EtM). The use of different technologies to achieve IND-CCA2 may need adaptive modification, e.g., the support for such technologies in the first apparatus 110 and the second apparatus 120.

[0057] In some example embodiments, the second apparatus 120 may then generate (202) a seed key based on the ciphertext 'pqc dr' of the shared secret. For example, the seed key may be generated using a pseudorandom function (PRF) with the ciphertext 'pqc dr' of the shared secret, the nonce 'Ni' of the first apparatus 110 extracted from the IKE SA^l^ request and a nonce 'Nr' of the second apparatus 120 as inputs. The nonce 'Ni' of the first apparatus 110 may be concatenated with the nonce 'Nr' of the second apparatus 120 to achieve IND-CCA2. In the context of the IKEv2, the generated seed key is referred to as SKEYSEED. As the PQC KEM is applied, the generated quantum safe seed key will be referred to as PQC SKEYSEED in the present disclosure in the following. It is to be understood that there may be different names for seed key in different protocols, and the scope of the present disclosure is not limited in this respect. The process may be represented as: pqc ctr = pqc ss || ctr (4) PQC SKEYSEED = prf (Ni Nr, pqc ctr) (5) wherein 'pqc ss || ctr' means 'pqc ss is concatenated with 'ctr', and prf() is the pseudorandom function used to generate the PQC SKEYSEED, 'Ni \ Nr' means the 'Ni' is concatenated with 'Nr'.

[0058] The second apparatus 120 also puts the responder ciphertext 'ctr' in a response to the IKESAINIT request and sends (203) the response to the first apparatus 110. In some example embodiments, in the context of IKEv2, the response to the IKE SA INIT request may comprise one or more of the following: 1) a header (HDR), which may contain the security parameter indexes (SPIs), version numbers, exchange type, message ID and flags of various sorts. The header is used to identify and manage the IKEv2 messages; 2) a security association response (SArl) payload, which may be used by the responder to select and confirm the cryptographic algorithms and parameters proposed by the initiator in the SAil payload. This selection forms the basis of the security association (SA) that will be used for the IKESA. In some example embodiments, the SArl may contain the confirmation that the same PQC KEM is used by the responder; 3) a key exchange response (KEr) payload, which may contain the Diffie-Hellman public value of the responder. In some example embodiments, the KEr may contain the responder ciphertext 'ctr' discussed above; 4) a nonce response (Nr) payload, which may contain a random value generated by the responder. Similarly, the Nr is used to ensure the freshness of the exchange and to protect against replay attacks; and 5) an indication of using post-quantum pre-shared keys (PPK), which may be a status notification indicating that a PPK is used for the key exchange process. 6) Optionally, a certificate request (CERTREQ) payload, which requests the initiator's certificate for authentication. If the authentication of the initiator adopts different technologies, other types of payloads corresponding to other types of authentications may be used.

[0059] Now, the generation of the seed key based on the responder ciphertext 'ctr' by the first apparatus 110 will be detailed as an example. Upon receiving the response from the second apparatus 120, which comprises at least the responder ciphertext 'ctr' generated based on the public key 'pki' using the same PQC KEM by the second apparatus and information indicating that a PPK is used, the first apparatus 110 generates a seed key based on a PQC KEM shared secret extracted from the responder ciphertext 'ctr', and the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus 110 and the second apparatus 120. In some embodiments, the first apparatus 110 may extract the responder ciphertext 'ctr' from the KEr payload from the response and generates (204) a seed key based on the responder ciphertext 'ctr'.

[0060] In some example embodiments, the first apparatus 110 may extract the shared secret by applying a decapsulation algorithm to the responder ciphertext 'ctr', using the private key 'sk' generated together with the public key 'pki', which may be represent as: Decaps (sk, ctr) -> pqc ss (6) wherein Decaps() is the decapsulation algorithm used to decapsulate the responder ciphertext, with 'sk', ctr and being the input and 'pqc ss' being the output.

[0061] In some example embodiments, to achieve indistinguishability under adaptive chosen ciphertext attack (IND-CCA2) security, the shared secret 'pqc ss may be concatenated with the responder ciphertext “ctr” to generate a ciphertext 'pqc ctr' of the shared secret. In some example embodiments, other technologies may be used to protect the shared PQC secret from adaptive chosen ciphertext attacks (CCA2), e.g., using a onetime signature, or an encrypt-then-MAC (message authentication code) (EtM). The use of different technologies to achieve IND-CCA2 may need adaptive modification, e.g., the support for such technologies in the first apparatus 110 and the second apparatus 120.

[0062] Then, the first apparatus 110 generates (204) a seed key PQC SKEYSEED based on the shared secret 'pqcss'. For example, the seed key may be generated using a pseudorandom function (PRF) with the ciphertext 'pqc ctr' of the shared secret, the nonce 'Ni' of the first apparatus 110 (chose and sent in the IKESAINIT request to the second apparatus 120) and the nonce 'Nr' of the second apparatus 120 (extracted from the Nr payload in the response sent by the second apparatus 120) as inputs. The nonce 'Ni' of the first apparatus 110 may be concatenated with the nonce 'Nr' of the second apparatus 120 to achieve IND-CCA2. The process may be represented as: pqc ctr = pqc ss | ctr (7) PQC SKEYSEED = prf(Ni \ Nr, pqcctr) (8) wherein 'pqc ss || ctr' means 'pqc ss is concatenated with 'ctr', and prf() is the pseudorandom function used to generate the PQC SKEYSEED, 'Ni Nr' means the 'Ni' is concatenated with 'Nr'.

[0063] After the request / response exchange, both the first apparatus 110 and the second apparatus 120 now have the seed key PQC SKEYSEED. With the seed key, the first apparatus 110 and the second apparatus 120 may generate one or more intermediate keys for following communication including authentication, integrity verification, etc. Some of the intermediate keys generated comprise at least one of: SK d', an intermediate key for further key material derivation, SK_pi', an intermediate key for authentication of the first apparatus, or SKpr', an intermediate key for authentication of the second apparatus.

[0064] The first apparatus 110 and the second apparatus 120 may also generate one or more derived keys based on the one or more intermediate keys, one or more derived keys comprising at least one of: SK d, a key for further key material derivation, SK pi, a key for the authentication of the first apparatus, SK pr, a key for the authentication of the second apparatus SKei, a key for encryption of the first apparatus, SK_er, a key for encryption of the second apparatus, SK ai. a key for integrity protection of the first apparatus, or SKar. a key for integrity protection of the second apparatus.

[0065] The generation of the one or more intermediate keys and one or more derived keys may be represented as: PQC SKEYSEED = prf(Ni Nr,pqc ctr) (10) (SK d' 1 SK cn 1 SK_ar { SKe / | SK_er SKpi' { SKpr',1 = prf (PQC SKEYSEED, Ni I Nr | SPIi I SPIr) SK d = prf+ (PPK, SK d) SKppi = prf+ (PPK, SKppi) SK pr = prf (PPK, SK pr) whereinprf() is the pseudorandom function used to generate the PQC SKEYSEED, 'Ni Nr' means the 'Ni' is concatenated with 'Nr', and whereinprf+() is the pseudorandom function used to generate the intermediate keys SK d', SK_pi' and SK_pr' and the derived keys SK d, SK ai, SK ar, SK ei and SK er.

[0066] As seen, all the intermediate keys are generated with PQC SKEYSEED as the seed key, which is quantum safe, the intermediate keys therefore are quantum safe.

[0067] In some example embodiments, the first apparatus 110 may then send (205) an authentication request to the second apparatus 120. In some example embodiments, the authentication request may comprise one or more of the following: 1) a header (HDR); 2) encrypted payloads SK{], encrypted using at least one of the generated derived keys. The payloads may comprise; i) an identification of the initiator (IDi) payload, which asserts the identity of the initiator, proving knowledge of the secret corresponding to IDi.; ii) optionally, the certificate of the initiator (CERT) payload, which provides the initiator’s certificate for authentication purposes. If the authentication of the initiator adopts different technologies, other types of payloads corresponding to other types of authentications may be used; iii) optionally, the certificate request (CERTREQ) payload, which requests the responder's certificate for authentication purposes. If the authentication of the initiator adopts different technologies, other types of payloads corresponding to other types of authentications may be used; iv) an authentication (AUTH) payload, which proves the initiator’s knowledge of the shared secret and integrity protects the contents of the message; v) a traffic selector of the initiator (TSi), which specifies the traffic that the initiator wants to protect with the CHILDSA; vi) a traffic selector of the responder (TSr), which specifies the traffic that the responder wants to protect with the CHILD SA; vii) an indication that a PPK is used, and viii) an identifier of the PPK, e.g., the identifier of the public key.

[0068] Upon receiving the authentication request, the second apparatus 120 may extract the related payloads e.g., the IDi, the CERT, the AUTH, and authenticate the first apparatus 110. In response to a successful authentication, the second apparatus 120 may send (206) a response to the first apparatus 110, indicating the successful authentication. In some example embodiments, the response may comprise one or more of the following: 1) a header (HDR); 2) encrypted payloads SK{}, encrypted using at least one of the generated derived keys. The payloads may comprise; i) an identification of the responder (IDr) payload, which asserts the identity of the initiator, proving knowledge of the secret corresponding to IDi; ii) optionally, the certificate of the responder (CERT) payload, which provides the initiator’s certificate for authentication purposes. If the authentication of the initiator adopts different technologies, other types of payloads corresponding to other types of authentications may be used; iii) an authentication (AUTH) payload, which proves the responder's knowledge of the shared secret and integrity protects the contents of the message; iv) a traffic selector of the initiator (TSi), which specifies the traffic that the initiator wants to protect with the CHILDS A; v) a traffic selector of the responder (TSr), which specifies the traffic that the 21 responder wants to protect with the CHILDSA; and vi) an indication that a PPK is used.

[0069] In some example embodiments, upon receiving the response to the authentication request indicating a successful authentication of the second apparatus 120, the first apparatus 110 sends (207) a security association (SA) creation request to the second apparatus 120, request to create a SA with the second apparatus 120. In some example embodiments, in the context of IKEv2, it is the CREATECHILESA request and it may comprise one or more of the following: 1) a header (HDR); 2) encrypted payloads SK{ }, encrypted using at least one of the generated derived keys. The payloads may comprise; i) a security association of the initiator (SA) payload, which may contain the proposals for the CHILD SA from the initiator. In some example embodiments, the SA may contain the PQC KEM used by the initiator; ii) a key exchange of the initiator (KEi) payload, which may contain a new public key generated using a PQC key encapsulation mechanism (KEM) by the first apparatus 110, the generation of the new public is similar to the generation of the public key 'pki'\ iii) a nonce of the initiator (Ni) payload, which may contain a new random value generated by the initiator; iv) a traffic selector of the initiator (TSi); v) a traffic selector of the responder (TSr); and 3) an indication of using post-quantum pre-shared keys (PPK), which is a status notification indicating that a PPK is used for the SA creation process.

[0070] Similarly, the first apparatus 110 may generate the new public key (denoted as pki) and a new private key (denoted as sk) using a PQC KEM, same as or different from the PQC KEM used to generate the public key 'pki', which may be represented as: ML-KEM-KeyGen’ () -> (pki’, sk) (11) wherein ML-KEM-KeyGen is the PQC KEM key generator used for the generation 22 of the new public key and the private key, (pki’, sk) are the keys generated withpki' being the public key and sk’ being the private key.

[0071] Upon receiving the SA creation request from the first apparatus 110, the second apparatus 120 may extract the new public key (pki) from the KEi payload and generate a new shared secret (denoted as pqc_ss), together with a new responder ciphertext (denoted as c / r'), using the encapsulation algorithm same as the one used by the first apparatus 110 (contained in the SA payload), which takes the new public key (pki') received from the first apparatus 110 as input. The new shared secret is also a PQC shared secret, which means it is quantum safe. The encapsulation algorithm may be a ML-KEM same as the ML-KEM used by the first apparatus 110. The process may be represented as: ML-Encaps’(pki) -> (ctr’, pqc ss) (12) wherein ML-Encaps () is the PQC KEM used to generate the shared secret and the responder ciphertext by the second apparatus 200, taking the new public key pki’ as the input, dr’ being the generated new responder ciphertext and pqc_ss’ being the generated new shared secret.

[0072] In some example embodiments, to achieve indistinguishability under adaptive chosen ciphertext attack (IND-CCA2) security, the new shared secret (pqc ss) may be concatenated with the new responder ciphertext (ctr) to generate a new ciphertext (pqc ctr) of the new shared secret. In some example embodiments, other technologies may be used to protect the shared PQC secret from adaptive chosen ciphertext attacks (CCA2), e.g., using a one-time signature, or an encrypt-then-MAC (message authentication code) (EtM). The use of different technologies to achieve IND-CCA2 may need adaptive modification, e.g., the support for such technologies in the first apparatus 110 and the second apparatus 120.

[0073] The second apparatus 120 then generates (209a) a key material based on the new ciphertext (pqc ct) of the new shared secret. For example, the key material may be generated using a pseudorandom function (PRF) with the new ciphertext (pqc ctr) of the new shared secret, the new nonce of the first apparatus 110 extracted from the CREATECHILDSA request and a new nonce of the second apparatus 120 as inputs. The new nonce of the first apparatus 110 may be concatenated with the new nonce of the second apparatus 120 to achieve IND-CCA2. In the context of the IKEv2, the key material is referred to as KEYMAT, as PQC KEM is applied, the generated quantum safe key 23 material will be referred to as PQC KEYMAT in the present disclosure in the following. It is to be understood that there may be different names for key material in different protocols, and the scope of the present disclosure is not limited in this respect. The process may be represented as: pqcctr' '= pqc ss' || ctr' (13) PQC KEYMAT = prf (SKd, pqc ctr', Ni' | Nr') (14) wherein (pqc ss' ctr') means (pqc ss') is concatenated with (ctr)_ andprf() is the pseudorandom function used to generate the key material PQC KEYMAT, (Ni’ | Nr') means the Ni' is concatenated with (Nr').

[0074] The second apparatus 120 also puts the new responder ciphertext (ctr') in a response to the CREATECHILDSA request and send (208) the response to the first apparatus 110. In some example embodiments, the response may comprise one or more of the following information in the context of IKEv2: 1) a header (HDR); 2) encrypted payloads SK{}, encrypted using at least one of the generated derived keys. The payloads may comprise; i) a security association of the initiator (SA) payload, which may contain the proposals for the CHILD SA from the initiator. In some embodiments, the SA may contain the confirmation that the same PQC KEM is used by the responder; ii) a key exchange of the responder (KEr) payload, which may contain a new responder ciphertext (ctr)-, iii) a nonce of the responder (Ni) payload, which may contain a new random value generated by the responder; iv) a traffic selector of the initiator (TSi); v) a traffic selector of the responder (TSr); and 3) an indication of using post-quantum pre-shared keys (PPK), which is a status notification indicating that a PPK is used for the SA creation process.

[0075] Now, the generation of the key material based on the new responder ciphertext (ctr’) by the first apparatus 110 will be discussed. Upon receiving the response from the 24 second apparatus 120, the first apparatus 110 extracts the new responder ciphertext (ctr) from the KEr payload from the response and generates (209b) a key material PQC KEYMAT based on the new responder ciphertext (ctr).

[0076] In some example embodiments, the first apparatus 110 may extract the new shared secret by applying a decapsulation algorithm to the new responder ciphertext (ctr'), using the new private key (sk) generated together with the new public key (pki'), which may be represent as: Decaps(sk', ctr') -> pqc ss' (15) wherein Decaps() is the decapsulation algorithm used to decapsulate the new responder ciphertext (ctr')), with the (sk) and (ctr) being the input and (pqc ss) being the outputo

[0077] In some example embodiments, to achieve indistinguishability under adaptive chosen ciphertext attack (IND-CCA2) security, the new shared secret 'pqc ss' may be concatenated with the new responder ciphertext (ctr) to generate a new ciphertext 'pqc ctr' of the new shared secret. In some example embodiments, other technologies may be used to protect the shared PQC secret from adaptive chosen ciphertext attacks (CCA2), e.g., using a one-time signature, or an encrypt-then-MAC (message authentication code) (EtM). The use of different technologies to achieve IND-CCA2 may need adaptive modification, e.g. the support for such technologies in the first apparatus 110 and the second apparatus 120.

[0078] Then, the first apparatus 110 generates (209a) a key material PQC KEYMAT based on the new shared secret (pqc ss). For example, the key material may be generated using a pseudorandom function (PRF) with the new ciphertext (pqc ctr) of the new shared secret, the nonce of the first apparatus 110 (chose and sent in the CREATE CHILD request to the second apparatus 120) and the nonce of the second apparatus 120 (extracted from the Nr payload in the response sent by the second apparatus 120) as inputs. The nonce of the first apparatus 110 may be concatenated with the nonce of the second apparatus 120 to achieve IND-CCA2. The process may be represented as: pqc ctr' = pqc ss' | ctr' (16) PQC KEYMA T = prf (SK d, pqc ctr'. Ni' | Nr) (17) wherein (pqc ss' {{ dr') means (pqc ss) is concatenated with (ctr')_ and prf() is the pseudorandom function used to generate the key material PQC KEYMAT, (Ni' | Nr') means the Ni' is concatenated with (Nr).

[0079] After the request / response exchange, both the first apparatus 110 and the second apparatus 120 now have the key material PQC KEYMAT. With the key material, the first apparatus 110 and the second apparatus 120 may generate one or more keys for the SA for following communication Some of the keys generated comprise at least one of: an encryption key for encrypting data traffic, an integrity key for ensuring the integrity of data, or an authentication key for authenticating data. wherein the respective keys may be used for the secure communication between the first apparatus 110 and the second apparatus 120, e.g., encrypting the data traffic between them, ensuring the integrity of data exchanged between them, or authenticating data exchanged between them.

[0080] Then the first apparatus 110 and the second apparatus 120 may install the at least one generated key in the respective SAs.

[0081] FIG. 3 shows a flowchart of an example method 300 implemented at a first apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 300 will be described from the perspective of the first apparatus 110 in FIG. 1, which acts as an initiator.

[0082] At block 310, the first apparatus 110 sends a key exchange request to a second apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM), and information indicating that a post-quantum pre-shared key (PPK) is used.

[0083] At block 320, the first apparatus 110 receives a response from the second apparatus 120, wherein the response to the key exchange request comprises at least a first responder ciphertext generated based on the first public key using the PQC KEM by the second apparatus and information indicating that a PPK is used.

[0084] At block 330, the first apparatus 110 generates a seed key based on a first PQC KEM shared secret extracted from the first responder ciphertext, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus 110 and the second apparatus 120. As the seed key is generated based on the first PQC KEM shared secret which is quantum safe, the seed key is quantum safe.

[0085] In some example embodiments, the method 300 further comprises: extracting, by the first apparatus 110, the first PQC KEM shared secret from the first responder ciphertext based on a first private key generated using the PQC KEM. Similarly, as the extraction of the first shared secret is based on the first private key generated using the PQC KEM, the first shared secret is also quantum safe.

[0086] In some example embodiments, the method 300 further comprises: generating, by the first apparatus 110, a first ciphertext of the first PQC KEM shared secret; and generating the seed key based on the first ciphertext of the first PQC KEM shared secret, a first nonce of the first apparatus and first nonce of the second apparatus. Similarly, as the generation of the seed key is based on the first PQC KEM first shared secret which is quantum safe, the seed key is also quantum safe.

[0087] In some example embodiments, the one or more intermediate cryptographic keys comprise at least one of: an intermediate key for further key material derivation, an intermediate key for authentication of the first apparatus, or an intermediate key for authentication of the second apparatus. Similarly, as the one or more intermediate cryptographic keys are based on the seed key which is quantum safe, the one or more intermediate cryptographic keys are also quantum safe.

[0088] In some example embodiments, the one or more cryptographic keys comprise at least one of: a key for further key material derivation, a key for authentication of the first apparatus, a key for authentication of the second apparatus, a key for encryption of the first apparatus, a key for encryption of the second apparatus, a key for integrity protection of the first apparatus or a key for integrity protection of the second apparatus. Similarly, as the one or more cryptographic keys are based on the seed key which is quantum safe, the one or more cryptographic keys are also quantum safe.

[0089] In some example embodiments, the method 300 further comprises: sending, by the first apparatus 110, an authentication request to the second apparatus 120, wherein the authentication request comprises at least an identifier of the first public key and information indicating that the identifier of the first public key is included in a payload 27 associated with the authentication request, wherein the payload is encrypted and integrity protected by the one or more cryptographic keys. As the payload is encrypted and integrity protected by the one or more cryptographic keys which are quantum safe, the payload is also quantum safe.

[0090] In some example embodiments, the method 300 further comprises: in response to receiving, by the first apparatus 110, from the second apparatus 120, a response to the authentication request indicating a successful authentication of the second apparatus, sending to the second apparatus, a security association (SA) creation request to create a SA between the first apparatus and the second apparatus, wherein the SA creation request comprises at least a second public key generated using a PQC KEM and information indicating that a PPK is used; receiving, by the first apparatus 110, a response to the SA creation request from the second apparatus 120, wherein the response to the SA creation request comprises at least a second responder ciphertext generated based on the second public key using the PQC KEM by the second apparatus and information indicating that a PPK is used; and generating, by the first apparatus 110, a key material based on a second PQC KEM shared secret extracted from the second responder ciphertext, wherein the key material is used to derive one or more further intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more further cryptographic keys used for security and authenticity of the SA between the first apparatus 110 and the second apparatus 120. Similarly, as the key material is generated based on the second PQC KEM shared secret which is quantum safe, the key material is also quantum safe.

[0091] In some example embodiments, the method 300 further comprises: extracting, by the first apparatus 110, the second PQC KEM shared secret from the second responder ciphertext based on a second private key generated using the PQC KEM. Similarly, as the extraction of the second PQC KEM shared secret is based on the second private key generated using the PQC KEM, the second shared secret is also quantum safe.

[0092] In some example embodiments, the method 300 further comprises: generating, by the first apparatus 110, a second ciphertext of the second PQC KEM shared secret; and generating, by the first apparatus 110, the key material based on the second ciphertext of the second PQC KEM shared secret, a second nonce of the first apparatus and the second nonce of the second apparatus. Similarly, as the key material is generated based on the second ciphertext of the second shared secret which is quantum safe, the key material is also quantum safe.

[0093] In some example embodiments, the one or more further cryptographic keys comprise at least one of: an encryption key for encrypting data traffic, an integrity key for ensuring the integrity of data, or an authentication key for authenticating data; and installing, by the first apparatus 110 the one or more further cryptographic keys in the SA on the first apparatus 110. Similarly, as the one or more further cryptographic keys are generated based on the key material, which is quantum safe, the one or more further cryptographic keys are also quantum safe.

[0094] FIG. 4 shows a flowchart of an example method 400 implemented at a second apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 400 will be described from the perspective of the second apparatus 120 in FIG. 1, which acts as a responder.

[0095] At block 410, the second apparatus 120 receives a key exchange request from a first apparatus 110, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) by the first apparatus and information indicating that a post-quantum pre-shared key (PPK) is used.

[0096] At block 420, the second apparatus 120 generates a first PQC KEM shared secret based on the first public key using the PQC KEM.

[0097] At block 430, the second apparatus 120 generates a seed key based on the first PQC KEM shared secret, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus 110 and the second apparatus 120. As the seed key is generated based on the first PQC KEM shared secret, the seed key is quantum safe.

[0098] In some example embodiments, the method 400 further comprises: generating, by the second apparatus 120, a first responder ciphertext based on the first public key using the PQC KEM; and sending, by the second apparatus 120, a response to the key exchange request to the first apparatus 110, wherein the response to the key exchange request comprises at least the first responder ciphertext and information indicating that a PPK is used. Similarly, as the first responder ciphertext is generated based on the first public key which is quantum safe, the first responder ciphertext is quantum safe.

[0099] In some example embodiments, the method 400 further comprises: generating, by the second apparatus 120, a first ciphertext of the first PQC KEM shared secret based on the first public key; and generating, by the second apparatus 120, the seed key based on the first ciphertext of the first PQC KEM shared secret, the first nonce of the first apparatus and a first nonce of the second apparatus. Similarly, as the seed key is generated based on the first PQC KEM shared secret, which is quantum safe, the seed key is quantum safe.

[0100] In some example embodiments, the one or more intermediate cryptographic keys comprise at least one intermediate key comprising at least one of: an intermediate key for further key material derivation, an intermediate key for authentication of the first apparatus, or an intermediate key for authentication of the second apparatus. Similarly, as the one or more intermediate cryptographic keys are generated based on the seed key which is quantum safe, the one or more intermediate cryptographic keys are also quantum safe.

[0101] In some example embodiments, the one or more cryptographic keys comprise at least one of: a key for further key material derivation, a key for authentication of the first apparatus, a key for authentication of the second apparatus, a key for encryption of the first apparatus, a key for encryption of the second apparatus, a key for integrity protection of the first apparatus or a key for integrity protection of the second apparatus. Similarly, as the one or more cryptographic keys are generated based on the seed key which is quantum safe, the one or more cryptographic keys are also quantum safe.

[0102] In some example embodiments, the method 400 further comprises: receiving, by the second apparatus 120, an authentication request from the first apparatus 110, wherein the authentication request comprises at least an identifier of the first public key and information indicating that the identifier of the first public key is included in a payload associated with the authentication request, wherein the payload is encrypted and integrity protected by the one or more cryptographic keys; and based at least in part on a determination that the first public key is verified, sending, by the second apparatus 120, to the first apparatus 110, a response to the authentication request indicating a successful authentication. Similarly, as the payload is encrypted and integrity protected by the one or more cryptographic keys which are quantum safe, the payload is also quantum safe.

[0103] In some example embodiments, the method 400 further comprises: receiving, by the second apparatus 120, from the first apparatus 110, a security association (SA) creation request to create a SA between the first apparatus and the second apparatus, wherein the SA creation request comprises at least a second public key generated using a PQC KEM and information indicating that a PPK is used; generating, by the second apparatus 120, a second PQC KEM shared secret based on the second public key using the PQC KEM; generating, by the second apparatus 120, a key material based on the second PQC KEM shared secret, wherein the key material is used to derive one or more further intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more further cryptographic keys used for security and authenticity of the SA between the first apparatus 110 and the second apparatus 120. Similarly, as the key material is generated based on the second PQC KEM shared secret which is quantum safe, the key material is also quantum safe.

[0104] In some example embodiments, the method 400 further comprises: generating, by the second apparatus 120, a second responder ciphertext based on the second public key using the PQC KEM; and sending, by the second apparatus 120, a response to the SA creation request to the first apparatus 110, wherein the response to the SA creation request comprises at least the second responder ciphertext and information indicating that a PPK is used. Similarly, as the second responder ciphertext is generated based on the second public key generated using the PQC KEM, the second responder ciphertext is quantum safe.

[0105] In some example embodiments, the method 400 further comprises: generating, by the second apparatus 120, a second ciphertext of the second PQC KEM shared secret; and generating, by the second apparatus 120, the key material based on the second PQC KEM shared secret, the second nonce of the first apparatus and a second nonce of the second apparatus. Similarly, as the key material is generated based on the second PQC KEM shared secret which is quantum safe, the key material is also quantum safe.

[0106] In some example embodiments, the one or more further cryptographic keys comprise at least one of: an encryption key for encrypting data traffic; an integrity key for ensuring the integrity of data; or an authentication key for authenticating data; and installing, by the second apparatus 120, the one or more further cryptographic keys in the SA on the second apparatus 120. Similarly, as the one or more further cryptographic keys are generated based on the key material, which is quantum safe, the one or more further cryptographic keys are also quantum safe.

[0107] In some example embodiments, a first apparatus capable of performing any of the method 300 (for example, the first apparatus 110 in FIG. 1) may comprise means for performing the respective operations of the method 300. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The first apparatus may be implemented as or included in the first apparatus 110 in FIG. 1.

[0108] In some example embodiments, the first apparatus comprises means for sending a key exchange request to a second apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM), and information indicating that a post-quantum pre-shared key (PPK) is used; means for receiving a response from the second apparatus, wherein the response to the key exchange request comprises at least a first responder ciphertext generated based on the first public key by the second apparatus and information indicating that a PPK is used; and means for generating a seed key based on a first PQC KEM shared secret extracted from the first responder ciphertext, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

[0109] In some example embodiments, the first apparatus further comprises: means for extracting the PQC KEM first shared secret from the first responder ciphertext based on a first private key generated using the PQC KEM.

[0110] In some example embodiments, the first apparatus further comprises: means for generating a first ciphertext of the first PQC KEM shared secret; and means for generating the seed key based on the first ciphertext of the first PQC KEM shared secret, a first nonce of the first apparatus and first nonce of the second apparatus.

[0111] In some example embodiments, the one or more intermediate cryptographic keys comprise at least one intermediate key comprising at least one of: an intermediate key for further key material derivation, an intermediate key for authentication of the first apparatus, or an intermediate key for authentication of the second apparatus. 32

[0112] In some example embodiments, the one or more cryptographic keys comprise at least one of: a key for further key material derivation, a key for authentication of the first apparatus, a key for authentication of the second apparatus, a key for encryption of the first apparatus, a key for encryption of the second apparatus, a key for integrity protection of the first apparatus or a key for integrity protection of the second apparatus.

[0113] In some example embodiments, the first apparatus further comprises: means for sending an authentication request to the second apparatus, wherein the authentication request comprises at least an identifier of the first public key and information indicating that the identifier of the first public key is included in a payload associated with the authentication request, wherein the payload is encrypted and integrity protected by the one or more cryptographic keys.

[0114] In some example embodiments, the first apparatus further comprises: means for in response to receiving, from the second apparatus, a response to the authentication request indicating a successful authentication of the second apparatus, send to the second apparatus, a security association (SA) creation request to create a SA between the first apparatus and the second apparatus, wherein the SA creation request comprises at least a second public key generated using a PQC KEM and information indicating that a PPK is used; means for receiving a response to the SA creation request from the second apparatus, wherein the response to the SA creation request comprises at least a second responder ciphertext generated based on the second public key using the PQC KEM by the second apparatus and information indicating that a PPK is used; and means for generating a key material based on a second PQC KEM shared secret extracted from the second responder ciphertext, wherein the key material is used to derive one or more further intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more further cryptographic keys used for security and authenticity of the SA between the first apparatus and the second apparatus.

[0115] In some example embodiments, the first apparatus further comprises: means for extracting the second PQC KEM shared secret from the second responder ciphertext based on a second private key generated using the PQC KEM.

[0116] In some example embodiments, the first apparatus further comprises: means for generating a second ciphertext of the second PQC KEM shared secret; and means for generating the key material based on the second PQC KEM ciphertext of the second shared secret, a second nonce of the first apparatus and the second nonce of the second apparatus.

[0117] In some example embodiments, the one or more further cryptographic keys comprise at least one of: an encryption key for encrypting data traffic, an integrity key for ensuring the integrity of data, or an authentication key for authenticating data; and means for installing the one or more further cryptographic keys in the SA on the first apparatus.

[0118] In some example embodiments, a second apparatus capable of performing any of the method 400 (for example, the second apparatus 120 in FIG. 1) may comprise means for performing the respective operations of the method 400. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The second apparatus may be implemented as or included in the second apparatus 120 in FIG. 1.

[0119] In some example embodiments, the second apparatus comprises means for receiving a key exchange request from a first apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) by the first apparatus and information indicating that a post-quantum pre-shared key (PPK) is used; means for generating a first PQC KEM shared secret based on the first public key using the PQC KEM; and means for generating a seed key based on the first PQC KEM shared secret, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

[0120] In some example embodiments, the second apparatus further comprises: means for generating a first responder ciphertext based on the first public key; and means for sending a response to the key exchange request to the first apparatus, wherein the response to the key exchange request comprises at least the first responder ciphertext and information indicating that a PPK is used.

[0121] In some example embodiments, the second apparatus further comprises: means for generating the first ciphertext of a first PQC KEM shared secret based on the first public key; and means for generating the seed key based on the first ciphertext of the first PQC KEM shared secret, the first nonce of the first apparatus and a first nonce of the second apparatus.

[0122] In some example embodiments, the one or more intermediate cryptographic keys comprise at least one intermediate key comprising at least one of: an intermediate key for authentication of the first apparatus, or an intermediate key for authentication of the second apparatus.

[0123] In some example embodiments, the one or more cryptographic keys comprise at least one of: a key for further key material derivation, a key for authentication of the first apparatus, a key for authentication of the second apparatus, a key for encryption of the first apparatus, a key for encryption of the second apparatus, a key for integrity protection of the first apparatus or a key for integrity protection of the second apparatus.

[0124] In some example embodiments, the second apparatus further comprises: means for receiving an authentication request from the first apparatus, wherein the authentication request comprises at least an identifier of the first public key and information indicating that the identifier of the first public key is included in a payload associated with the authentication request, wherein the payload is encrypted and integrity protected by the one or more cryptographic keys; and means for based at least in part on a determination that the first public key is verified, sending, to the first apparatus, a response to the authentication request indicating a successful authentication.

[0125] In some example embodiments, the second apparatus further comprises: means for receiving from the first apparatus, a security association (SA) creation request to create a SA between the first apparatus and the second apparatus, wherein the SA creation request comprises at least a second public key generated using a PQC KEM and information indicating that a PPK is used; means for generating a second PQC KEM shared secret based on the second public key; means for generating a key material based on the second PQC KEM shared secret, wherein the key material is used to derive one or more further intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more further cryptographic keys used for security and authenticity of the SA between the first apparatus and the second apparatus.

[0126] In some example embodiments, the second apparatus further comprises: means for generating a second responder ciphertext based on the second public key using the PQC KEM; and means for sending a response to the SA creation request to the first apparatus, wherein the response to the SA creation request comprises at least the second responder ciphertext and information indicating that a PPK is used.

[0127] In some example embodiments, the second apparatus further comprises: means for generating a second ciphertext of the second PQC KEM shared secret; and means for generating the key material based on the second ciphertext of the second PQC KEM shared secret, the second nonce of the first apparatus and a second nonce of the second apparatus.

[0128] In some example embodiments, the one or more further cryptographic keys comprise at least one of: an encryption key for encrypting data traffic; an integrity key for ensuring the integrity of data; or an authentication key for authenticating data; and means for installing the the one or more further cryptographic keys in the SA on the second apparatus.

[0129] FIG. 5 is a simplified block diagram of a device 500 that is suitable for implementing example embodiments of the present disclosure. The device 500 may be provided to implement a communication device, for example, the first apparatus 110 or the second apparatus 120 as shown in FIG. 1. As shown, the device 500 includes one or more processors 510, one or more memories 520 coupled to the processor 510, and one or more communication modules 540 coupled to the processor 510.

[0130] The communication module 540 is for bidirectional communications. The communication module 540 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interfaces may represent any interface that is necessary for communication with other network elements. In some example embodiments, the communication module 540 may include at least one antenna.

[0131] The processor 510 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 500 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.

[0132] The memory 520 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 524, an electrically programmable read only memory (EPROM), a flash memory, a hard disk, a compact disc (CD), a digital video disk (DVD), an optical disk, a laser disk, and other magnetic storage and / or optical storage. Examples 36 of the volatile memories include, but are not limited to, a random-access memory (RAM) 522 and other volatile memories that will not last in the power-down duration.

[0133] A computer program 530 includes computer executable instructions that are executed by the associated processor 510. The instructions of the program 530 may include instructions for performing operations / acts of some example embodiments of the present disclosure. The program 530 may be stored in the memory, e.g., the ROM 524. The processor 510 may perform any suitable actions and processing by loading the program 530 into the RAM 522.

[0134] The example embodiments of the present disclosure may be implemented by means of the program 530 so that the device 500 may perform any process of the disclosure as discussed with reference to FIG. 2 to FIG. 4. The example embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.

[0135] In some example embodiments, the program 530 may be tangibly contained in a computer readable medium which may be included in the device 500 (such as in the memory 520) or other storage devices that are accessible by the device 500. The device 500 may load the program 530 from the computer readable medium to the RAM 522 for execution. In some example embodiments, the computer readable medium may include any types of non-transitory storage medium, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e g., RAM vs. ROM).

[0136] FIG. 600 shows an example of the computer readable medium 600 which may be in form of CD, DVD or other optical storage disk. The computer readable medium 600 has the program 530 stored thereon.

[0137] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. Although various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or 37 method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0138] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer readable medium, such as a non-transitory computer readable medium. The computer program product includes computerexecutable instructions, such as those included in program modules, being executed in a device on a target physical or virtual processor, to carry out any of the methods as described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.

[0139] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program code, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.

[0140] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.

[0141] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random-access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0142] Further, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated, various features that are described in the context of a single embodiment may also be implemented in a plurality of embodiments separately or in any suitable sub-combination.

[0143] Although the present disclosure has been described in languages specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1. A first apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to:send a key exchange request to a second apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM), and information indicating that a post-quantum preshared key (PPK) is used;receive a response from the second apparatus, wherein the response to the key exchange request comprises at least a first responder ciphertext generated based on the first public key using the PQC KEM by the second apparatus and information indicating that a PPK is used; andgenerate a seed key based on a first PQC KEM shared secret extracted from the first responder ciphertext, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

2. The first apparatus of claim 1, wherein the first apparatus is caused to:extract the first PQC KEM shared secret from the first responder ciphertext based on a first private key generated using the PQC KEM.

3. The first apparatus of claim 1 or 2, wherein the response to the key exchange request further comprises a first nonce of the second apparatus, and wherein the first apparatus is caused to:generate a first ciphertext of the first PQC KEM shared secret; andgenerate the seed key based on the first ciphertext of the first PQC KEM sharedsecret, a first nonce of the first apparatus and first nonce of the second apparatus.

4. The first apparatus of any of claims 1 to 3, wherein the one or more intermediate cryptographic keys comprise at least one of:an intermediate key for further key material derivation,an intermediate key for authentication of the first apparatus, oran intermediate key for authentication of the second apparatus.

5. The first apparatus of claim I to 4, wherein the one or more cryptographic keys comprise at least one of:a key for further key material derivation,a key for authentication of the first apparatus,a key for authentication of the second apparatus,a key for encryption of the first apparatus,a key for encryption of the second apparatus,a key for integrity protection of the first apparatus, ora key for integrity protection of the second apparatus.

6. The first apparatus of claim 5, wherein the first apparatus is further caused to:send an authentication request to the second apparatus, wherein the authentication request comprises at least an identifier of the first public key and information indicating that the identifier of the first public key is included in a payload associated with the authentication request, wherein the payload is encrypted and integrity protected by the one or more cryptographic keys.

7. The first apparatus of claim 6, wherein the first apparatus is further caused to:in response to receiving, from the second apparatus, a response to the authentication request indicating a successful authentication of the second apparatus, send to the second apparatus, a security association (SA) creation request to create a SA between the first 41apparatus and the second apparatus, wherein the SA creation request comprises at least a second public key generated using a PQC KEM and information indicating that a PPK is used;receive a response to the SA creation request from the second apparatus, wherein the response to the SA creation request comprises at least a second responder ciphertext generated based on the second public key using the PQC KEM by the second apparatus and information indicating that a PPK is used; andgenerate a key material based on a second PQC KEM shared secret extracted from the second responder ciphertext, wherein the key material is used to derive one or more further intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more further cryptographic keys used for security and authenticity of the SA between the first apparatus and the second apparatus.

8. The first apparatus of claim 7, wherein the first apparatus is caused to:extract the second PQC KEM shared secret from the second responder ciphertext based on a second private key generated using the PQC KEM.

9. The first apparatus of claim 7 or 8, wherein the response to the SA creation request further comprises a second nonce of the second apparatus, and wherein the first apparatus is caused to:generate a second ciphertext of the second PQC KEM shared secret; andgenerate the key material based on the second ciphertext of the second PQC KEM shared secret, a second nonce of the first apparatus and the second nonce of the second apparatus.

10. The first apparatus of any of claims 7 to 9, wherein the one or more further cryptographic keys comprise at least one of:an encryption key for encrypting data traffic,an integrity key for ensuring the integrity of data, or42an authentication key for authenticating data; andinstall the one or more further cryptographic keys in the SA on the first apparatus.

11. A second apparatus, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus at least to:receive a key exchange request from a first apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) by the first apparatus and information indicating that a post-quantum pre-shared key (PPK) is used;generate a first PQC KEM shared secret based on the first public key using the PQC KEM; andgenerate a seed key based on the first PQC KEM shared secret, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

12. The second apparatus of claim 11, wherein the second apparatus is caused to:generate a first responder ciphertext based on the first public key using the PQC KEM; andsend a response to the key exchange request to the first apparatus, wherein the response to the key exchange request comprises at least the first responder ciphertext and information indicating that a PPK is used.

13. The second apparatus of claim 11, wherein the key exchange request further comprises a first nonce of the first apparatus, and wherein the second apparatus is caused to:generate a first ciphertext of the first PQC KEM shared secret; andgenerate the seed key based on the first ciphertext of the first PQC KEM shared secret, the first nonce of the first apparatus and a first nonce of the second apparatus.

14. The second apparatus of any of claims 11 to 13, wherein the one or more intermediate cryptographic keys comprise at least one of:an intermediate key for further key material derivation,an intermediate key for authentication of the first apparatus, oran intermediate key for authentication of the second apparatus.

15. The second apparatus of any of claims 14, wherein the one or more cryptographic keys comprise at least one of:a key for further key material derivation,a key for authentication of the first apparatus,a key for authentication of the second apparatus,a key for encryption of the first apparatus,a key for encryption of the second apparatus,a key for integrity protection of the first apparatus, ora key for integrity protection of the second apparatus.

16. The second apparatus of claim 15, wherein the second apparatus is further caused to:receive an authentication request from the first apparatus, wherein the authentication request comprises at least an identifier of the first public key and information indicating that the identifier of the first public key is included in a payload associated with the authentication request, wherein the payload is encrypted and integrity protected by the one or more cryptographic keys; andbased at least in part on a determination that the first public key is verified, send, to the first apparatus, a response to the authentication request indicating a successful44authentication.

17. The second apparatus of claim 16, wherein the second apparatus is further caused to:receive from the first apparatus, a security association (SA) creation request to create a SA between the first apparatus and the second apparatus, wherein the SA creation request comprises at least a second public key generated using a PQC KEM and information indicating that a PPK is used;generate a second PQC KEM shared secret based on the second public key using the PQC KEM;generate a key material based on the second PQC KEM shared secret, wherein the key material is used to derive one or more further intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more further cryptographic keys used for security and authenticity of the SA between the first apparatus and the second apparatus.

18. The second apparatus of claim 17, wherein the second apparatus is further caused to:generate a second responder ciphertext based on the second public key using the PQC KEM; andsend a response to the SA creation request to the first apparatus, wherein the response to the SA creation request comprises at least the second responder ciphertext and information indicating that a PPK is used.

19. The second apparatus of any of claims 17 to 18, wherein the SA creation request further comprises a second nonce of the first apparatus, and the second apparatus is caused to:generate a second ciphertext of the second PQC KEM shared secret; andgenerate the key material based on the second ciphertext of the second PQC KEM45shared secret, the second nonce of the first apparatus and a second nonce of the second apparatus.

20. The second apparatus of any of claims 17 to 19, the one or more further cryptographic keys comprise at least one of:an encryption key for encrypting data traffic;an integrity key for ensuring the integrity of data; oran authentication key for authenticating data; andinstall the one or more further cryptography keys in the SA on the second apparatus.

21. A method, comprising:sending, by a first apparatus, a key exchange request to a second apparatus, wherein the key exchange request comprises at least a first public key generated using a postquantum cryptography (PQC) key generation mechanism (KEM) and information indicating that a post-quantum pre-shared key (PPK) is used;receiving, by the first apparatus, a response from the second apparatus, wherein the response to the key exchange request comprises at least a first responder ciphertext generated based on the first public key using the PQC KEM by the second apparatus and information indicating that a PPK is used; andgenerating, by the first apparatus, a seed key based on a first PQC KEM shared secret extracted from the first responder ciphertext, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

22. A method, comprising:receiving, by a second apparatus, a key exchange request from a first apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) by the first 46apparatus and information indicating that a post-quantum pre-shared key (PPK) is used;generating, by the second apparatus, a first PQC KEM shared secret based on thefirst public key using the PQC KEM; andgenerating, by the second apparatus, a seed key based on the first PQC KEM shared secret, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

23. An apparatus, comprising:means for sending a key exchange request to a second apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) and information indicating that a post-quantum pre-shared key (PPK) is used;means for receiving a response from the second apparatus, wherein the response to the key exchange request comprises at least a first responder ciphertext generated based on the first public key using the PQC KEM by the second apparatus and information indicating that a PPK is used; andmeans for generating a seed key based on a first PQC KEM shared secret extracted from the first responder ciphertext, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

24. An apparatus, comprising:means for receiving a key exchange request from a first apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM) by the first apparatus and information indicating that a post-quantum pre-shared key (PPK) is used;47means for generating a first PQC KEM shared secret based on the first public keyusing the PQC KEM; andmeans for generating a seed key based on the first PQC KEM shared secret, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then 5 mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.

25. A computer readable medium comprising instructions stored thereon for causing 10 an apparatus at least to perform the method of claim 21 or 22.

Citation Information

Patent Citations

  • Generating post-quantum pre-shared keys

    US20240129115A1