Context-Based Cipher Selection

The context-based cipher selection system addresses the challenge of balancing cryptographic security and energy efficiency in wireless networks by optimizing PQC algorithm choice based on network context, enhancing resource efficiency and performance.

JP2025528664APending Publication Date: 2025-09-02RAKUTEN MOBILE INC +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025500316
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-07-13
Filing Date
2022-09-22
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

Existing wireless communication networks face challenges in selecting Post-Quantum Cryptography (PQC) algorithms that balance cryptographic security with minimal energy consumption and resource efficiency, leading to sub-optimal resource utilization.

Method used

A context-based cipher selection method and system that optimizes PQC algorithm choice based on network usage, security level, and energy efficiency using a service management and orchestrator framework, employing supervised learning and decision trees to automate the selection process.

Benefits of technology

Reduces energy consumption and improves performance by optimizing cryptographic operations according to network context, ensuring efficient resource use and reduced latency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025528664000001_ABST
    Figure 2025528664000001_ABST
Patent Text Reader

Abstract

[0009] A system and method for selecting a cryptographic algorithm in a network may include receiving network data from one or more network interfaces or network elements, analyzing the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms, and identifying the cryptographic algorithm from the plurality of cryptographic algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency. Additionally, analyzing the network data to identify the cryptographic algorithm may further include receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with a significance related to the network security level parameter.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to Indian Patent Application No. 202241040077, filed on July 13, 2022, the disclosure of which is incorporated herein by reference in its entirety.

[0002] The disclosure described herein relates to context-based cipher selection for energy-efficient operation. [Background technology]

[0003] Various standards bodies are focusing on Post-Quantum Cryptography (PQC) algorithms that can withstand cryptanalysis attacks by quantum computers due to the availability of quantum computing resources. Various PQC algorithms are being considered by standards bodies, such as the National Institute of Standards and Technology (NIST), which is considering PQC algorithms such as those disclosed in NIST IR 8413, "Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process," published in July 2022. In addition, Banerjee et al., "Energy Consumption of Candidate Algorithms for NIST PQC Standards," University of Waterloo, pp. 1-13, discusses energy consumption analyses of various cryptographic algorithms. Additionally, there are several proprietary and open source implementations of PQC algorithms available for researchers to study their performance characteristics and cryptographic strength.

[0004] Therefore, the requirement that PQC algorithms be quantum-resistant requires that the complexity of the cryptographic operations involved in PQC algorithms be strengthened in terms of new mathematical principles, increased key sizes, and algorithmic complexity, etc. The general method proposed by NIST to classify PQC algorithms in terms of the level of security they provide is as follows:

[0005] Level I: This is at least as difficult as breaking the security of a block cipher using an exhaustive key search with a 128-bit key, such as, but not limited to, Advanced Encryption Standard (AES) 128.

[0006] Level II: Breaking the security of a hash function may be at least as difficult as using a collision search with a 256-bit hashed hash algorithm, for example, but not limited to, Secure Hash Algorithm (SHA) 256 / SHA3-256.

[0007] Level III: May be at least as difficult to break the security of a block cipher, for example, but not limited to, AES192, using an exhaustive key search with a 192-bit key.

[0008] Level IV: It may be at least as difficult to break the security of a hash function, for example, but not limited to, SHA384 / SHA3-384, using a collision search with a 384-bit hashed message digest.

[0009] Level V: May be at least as difficult to break the security of a block cipher, for example, but not limited to, AES256, using an exhaustive key search with a 256-bit key.

[0010] However, enhanced cryptographic operations may impose higher performance requirements from the central processing unit (CPU) and memory resources of computing devices, among other components, and therefore may result in higher energy consumption by network elements. Wireless communication networks, such as Open Radio Access Network (O-RAN) elements deployed beyond fifth generation (5G) or sixth generation (6G), are expected to support zero trust network design and operation. All network element interfaces may be required to provide methods for securing the confidentiality, integrity, and authenticity of operations, which must be achieved through implementations of PQC cryptographic methods and protocols. Standards specify various PQC algorithms and associated parametric variations, but the standards carry different levels of energy consumption signatures. As a result, mobile network operators face a highly complex problem of adopting appropriate cryptographic algorithms for each network use case, resulting in non-optimal or sub-optimal selection of PQC algorithms and parameters, thereby resulting in wasteful consumption of resources and energy. Therefore, it is desirable to address the aforementioned and other disadvantages and provide a useful alternative.

[0011] Therefore, what is needed is a method and system for context-based cipher selection that requires minimal energy consumption, is resource efficient, and places low strain on computing resources and network elements. [Prior art documents] [Patent documents]

[0012] [Non-Patent Document 1] NIST IR 8413, “Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process” [Non-patent document 2] Banerjee et al. “Energy Consumption of Candidate Algorithms for NIST PQC Standards” University of Waterloo, pp.1-13 Summary of the Invention

[0013] According to exemplary embodiments, a context-based cipher selection method and system for energy-efficient operation in wireless communication networks is disclosed. The method and system can provide an optimized and automated process for determining an appropriate PQC cipher algorithm based on various parameters, including, but not limited to, the context of network usage, the level of cryptographic protection, and energy consumption. The disclosed method and system described herein enables, among other advantages, reduced energy consumption, optimization of encryption levels based on the context of network usage, and associated performance improvements (e.g., reduced latency) due to automation in the decision-making process.

[0014] According to other example embodiments, methods and systems for context-based cipher selection for energy-efficient operation are disclosed, which may include initializing system parameters, collecting O-Cloud (O-Cloud) telemetry information via O1 and O2 interfaces, and receiving external system context via an application interface or operator input, which may include a network criticality level and an applicable security level. The methods and systems of the present disclosure described herein may also include determining an optimal energy-efficient cipher configuration via a lookup table, supervised learning, or decision tree approach, and selecting final cipher parameters from rApp and cipher family guidance received from a Service Management and Orchestrator (SMO) via the O-Cloud. Here, rApp may refer to an application hosted on a non-real-time RAN intelligent controller (non-RT-RIC). The methods and systems of the present disclosure described herein may also include providing final policy guidance by an rApp security application to the O-Cloud layer and enforcing the policy in the O-Cloud layer. Furthermore, cryptographic optimization implementations can be supported more generally through the cloud orchestration layer.

[0015] According to another example embodiment, a method for selecting a cryptographic algorithm in a network is disclosed, which may include receiving network data from one or more network interfaces or network elements, analyzing the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms, and identifying the cryptographic algorithm from the plurality of cryptographic algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency.

[0016] Additionally, the step of analyzing the network data to identify the cryptographic algorithm may further include receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance related to the network security level parameter.

[0017] Additionally, the step of analyzing the network data to identify the cryptographic algorithm may further include receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance related to the network criticality parameter.

[0018] Additionally, analyzing the network data to identify the cryptographic algorithm may further include receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance associated with the energy efficiency parameter.

[0019] Additionally, the step of receiving network data from one or more network interfaces or network elements in the network is further based on a service management and orchestrator (SMO) framework, the SMO framework including an orchestrator module in communication with the network infrastructure module.

[0020] Additionally, analyzing the network data to identify the cryptographic algorithm from the plurality of cryptographic algorithms may be performed via an orchestrator module.

[0021] Additionally, the method may include transmitting the identified cryptographic algorithm from the orchestrator module to a network infrastructure module.

[0022] The method may also include receiving, via the orchestrator module, from the network infrastructure module, a selection of conditions for the identified cryptographic algorithm.

[0023] Additionally, the method may include generating, via the orchestrator module, a cryptographic policy for the network regarding the identified cryptographic algorithm.

[0024] Additionally, the method may include transmitting, via the orchestrator module, a cryptographic policy for the network regarding the identified cryptographic algorithm to the network infrastructure module.

[0025] In another exemplary embodiment, an apparatus for selecting a cryptographic algorithm in a network is disclosed. The apparatus may include a memory storage that stores computer-executable instructions and a processor communicatively coupled to the memory storage, wherein the processor executes the computer-executable instructions to cause the apparatus to receive network data from one or more network interfaces or network elements, analyze the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms, and identify the cryptographic algorithm from the plurality of cryptographic algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency.

[0026] Additionally, the computer-executable instructions, when executed by the processor, may further cause the device to receive a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance level with respect to the network security level parameter.

[0027] Furthermore, the computer-executable instructions, when executed by the processor, may further cause the apparatus to receive a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance with respect to the network criticality parameter.

[0028] Additionally, the computer-executable instructions, when executed by the processor, may further cause the device to receive a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with a degree of importance with respect to the energy efficiency parameter.

[0029] Additionally, the step of receiving network data from one or more network interfaces or network elements in the network may further be based on a service management and orchestrator (SMO) framework, the SMO framework including an orchestrator module in communication with the network infrastructure module.

[0030] Additionally, analyzing the network data to identify the cryptographic algorithm from the plurality of cryptographic algorithms may be performed via an orchestrator module.

[0031] Additionally, the computer-executable instructions, when executed by the processor, may further cause the device to transmit the identified cryptographic algorithm from the orchestrator module to the network infrastructure module.

[0032] The computer-executable instructions, when executed by the processor, may also cause the device to receive, via the orchestrator module, from the network infrastructure module, a selection of conditions regarding the identified cryptographic algorithm.

[0033] Additionally, the computer-executable instructions, when executed by the processor, may further cause the device, via the orchestrator module, to generate a cryptographic policy for the network regarding the identified cryptographic algorithm.

[0034] In another exemplary embodiment, a non-transitory computer-readable medium is disclosed that includes computer-executable instructions for selecting a cryptographic algorithm in a network by an apparatus, the computer-executable instructions, when executed by at least one processor of the apparatus, cause the apparatus to receive network data from one or more network interfaces or network elements, analyze the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms, and identify the cryptographic algorithm from the plurality of cryptographic algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency. [Brief explanation of the drawings]

[0035] The features, advantages, and significance of exemplary embodiments of the present disclosure will now be described with reference to the accompanying drawings, in which like reference numerals refer to like elements.

[0036] [Figure 1] FIG. 1 is a diagram of a general system architecture of the disclosed context-based cipher selection method and system described herein, in accordance with one or more embodiments. [Figure 2] 1 illustrates a perspective view of a three-dimensional space representing standardized levels of parameters considered for the selection of cryptographic algorithms for energy-efficient operation in wireless communication networks, according to one or more embodiments. [Figure 3] FIG. 10 illustrates another diagram of a method for enabling O-RAN network compatible selection of cryptographic algorithms for energy-efficient operation using a Service Management and Orchestrator (SMO), according to one or more embodiments. [Figure 4] FIG. 1 illustrates a process flow diagram illustrating a method for determining a cipher configuration for the context-based cipher selection methods and systems of the present disclosure described herein, in accordance with one or more embodiments. DETAILED DESCRIPTION OF THE INVENTION

[0037] The following detailed description of the exemplary embodiments refers to the accompanying drawings, in which the same reference numbers in different drawings may identify the same or similar elements.

[0038] The above disclosure provides illustration and description, but is not intended to be exhaustive or to limit implementations to the precise form disclosed. Modifications and variations are possible in light of the above disclosure or may be acquired from practice of the implementations. Furthermore, one or more features or components of one embodiment may be incorporated into or combined with other embodiments (or one or more features of other embodiments). Additionally, in the flowcharts and descriptions of operations provided below, it should be understood that one or more operations may be omitted, one or more operations may be added, one or more operations may occur (at least partially) concurrently, and the order of one or more operations may be rearranged.

[0039] It will be apparent that the systems and / or methods described herein may be implemented in different forms of hardware, firmware, or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not intended to limit the implementation. Thus, the operation and behavior of the systems and / or methods are described herein without reference to specific software code, and it will be understood that software and hardware can be designed to implement the systems and / or methods based on the description herein.

[0040] Although particular combinations of features are recited in the claims and / or disclosed herein, these combinations do not limit the disclosure of possible implementations. Indeed, many of these features can be combined in ways not specifically recited in the claims and / or disclosed herein. Although each dependent claim listed below may depend directly on only one claim, the disclosure of possible implementations includes each dependent claim in combination with all other claims in the claim set.

[0041] No element, act, or instruction used herein should be construed as critical or required unless explicitly described as such. Also, as used herein, the articles "a" and "an" are intended to include one or more items and may be used interchangeably with "one or more." Where only one item is intended, the term "one" or similar language is used. Also, as used herein, the terms "has," "have," "having," "include," "including," etc. are intended to be open-ended terms. Furthermore, the phrase "based on" is intended to mean "based at least in part on," unless expressly stated otherwise. Furthermore, phrases such as "at least one of [A] and [B]" or "at least one of [A] or [B]" should be understood to include A only, B only, or both A and B.

[0042] Throughout this specification, references to "one embodiment," "an embodiment," "a non-limiting exemplary embodiment," or similar language mean that a particular feature, structure, or characteristic described in connection with the illustrated embodiment is included in at least one embodiment of the solution. Thus, throughout this specification, the phrases "in one embodiment," "in an embodiment," "in one non-limiting exemplary embodiment," and similar language may, but do not necessarily, all refer to the same embodiment.

[0043] Furthermore, the described features, advantages, and characteristics of the present disclosure may be combined in any suitable manner in one or more embodiments. Those skilled in the art will recognize, in light of the description herein, that the present disclosure may be practiced without one or more of the specific features or advantages of a particular embodiment. In other cases, additional features and advantages may be recognized in particular embodiments that may not be present in all embodiments of the present disclosure.

[0044] In one implementation of the present disclosure described herein, a display page can include information residing in the memory of a computing device, and this information can be transmitted from the computing device to a database center and vice versa over a network. The information can be stored in memory in the computing device, in data storage at the edge of the network, or in a server at the database center. A computing device or a mobile device can receive non-transitory computer-readable media that can include instructions, logic, data, or code that can be stored in persistent or temporary memory of the mobile device or that can affect or initiate actions by the mobile device. Similarly, one or more servers can communicate with one or more mobile devices over a network and can transmit computer files residing in memory. The network can include, for example, the Internet, a wireless communication network, or any other network for connecting one or more mobile devices to one or more servers.

[0045] Any discussion of computing or mobile devices may also apply to any type of networked device, including, but not limited to, mobile devices and telephones such as mobile phones (e.g., any "smartphone"), personal computers, server computers, or laptop computers, personal digital assistants (PDAs), roaming devices such as network-connected roaming devices, wireless devices such as wireless email devices or other devices capable of wirelessly communicating with a computer network, or any other type of networked device that may communicate over a network and process electronic transactions. Any description of any mentioned mobile device may also apply to other devices, such as short-range ultra-high frequency (UHF) devices, near-field communication (NFC), infrared (IR), and devices including Wi-Fi capabilities, among others.

[0046] "Software," "application," "app," and "firmware" and similar phrases and terms may include any non-transitory computer-readable medium that stores a program that, when executed by a computer, causes the computer to perform a method, function, or control operation.

[0047] "Network" and similar phrases and terms may include one or more data links that enable the transport of electronic data between computer systems and / or modules. When information is transferred or provided to a computer over a network or another communications connection (either wired, wireless, or a combination of wired or wireless), the computer uses the connection as a computer-readable medium. Thus, by way of example and not limitation, a computer-readable medium may also include a network or data link that may be used to carry or store desired program code means in the form of computer-executable instructions or data structures and that may be accessed by a general-purpose or special-purpose computer.

[0048] Similar phrases and terms such as "portal" or "terminal" may include an intranet page, an Internet page, locally residing software or application, a mobile device graphical user interface, or a digital presentation for a user. A portal may also be any graphical user interface for accessing the various modules, components, features, options, and / or attributes of the present disclosure described herein. For example, a portal may be a web page accessed with a web browser, a mobile device application, or any application or software residing on a computing device.

[0049] FIG. 1 illustrates a diagram of a general network architecture according to one or more embodiments. Referring to FIG. 1, end users 110, network support team users 120, and administrator terminal / dashboard users 130 (collectively referred to herein as users 110, 120, and 130) can interact with a central server or application server 100 via a secure network according to one or more embodiments. Additionally, users 110, 120, and 130 may also interact directly with one another via the network system of the present disclosure described herein. Here, users 110 may be any type of customer of a network or communications service provider, a network service provider agent, or a vendor, such as users operating computing devices and user terminals A, B, and C, among others. Each of users 110 can communicate with server 100 via a respective terminal or portal, and server 110 can provide or automatically operate the network impact prediction engine system and method of the present disclosure described herein. Users 120 may include application development members or support agents of a network service provider for developing, integrating, and monitoring the context-based cipher selection method and system of the present disclosure described herein, including assisting with network event scheduling / modification, and providing support services to end users 110. Administrator terminal / dashboard users 130 may be any type of user with access privileges to access the dashboard or management portal of the present disclosure described herein, which can provide various user tools, GUI information, maps, graphs, and customer support options. It is contemplated within the scope of the present disclosure described herein that either of users 110 and 120 may also access the administrator terminal / dashboard 130 of the present disclosure described herein.

[0050] 1 , in accordance with one or more embodiments, the central server 100 of the present disclosure described herein can further bi-directionally communicate with a database / third-party server 140, which may also include users. Here, server 140 may include vendors and databases on which various captured, collected, or aggregated data, such as current, real-time, and past network-related historical and KPI data, may be stored and retrieved for network analysis, prediction, and simulation by server 100. Furthermore, server 140 may include various cipher family suites or algorithms. However, it is contemplated within the scope of the present disclosure described herein that the context-based cipher selection method and system of the present disclosure described herein may include any type of general network architecture.

[0051] With further reference to FIG. 1 , one or more of the servers or terminals of elements 100-140 may include a personal computer (PC), a printed circuit board with a computing device, a minicomputer, a mainframe computer, a microcomputer, a telephone computing device, a wired / wireless computing device (e.g., a smartphone, a personal digital assistant (PDA)), a laptop, a tablet, a smart device, a wearable device, or any other similarly functional device.

[0052] 1, one or more of the servers, terminals, and users 100-140 may include a set of components such as a processor, memory, storage components, input components, output components, communication interfaces, and JSON UI rendering components. The set of components of a device may be communicatively coupled via a bus.

[0053] The bus may comprise one or more components that enable communication between a set of one or more components of the servers or terminals of elements 100-140. For example, the bus may be a communications bus, crossover, network, etc. The bus may be implemented using single or multiple (two or more) connections between a set of one or more components of the servers or terminals of elements 100-140. The disclosure is not limited in this respect.

[0054] One or more of the servers or terminals of elements 100-140 may comprise one or more processors. The one or more processors may be implemented in hardware, firmware, and / or a combination of hardware and software. For example, the one or more processors may comprise a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), a microprocessor, a microcontroller, a digital signal processor (DSP), a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a general-purpose single-chip or multi-chip processor or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, or any conventional processor, controller, microcontroller, or state machine. The one or more processors may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. In some embodiments, particular processes and methods may be performed by circuitry that is specific to a given function.

[0055] The one or more processors may control the overall operation of one or more of the servers or terminals of elements 100-140 and / or a set of components (e.g., memory, storage components, input components, output components, communication interfaces, rendering components) of one or more of the servers or terminals of elements 100-140.

[0056] One or more of the servers or terminals of elements 100-140 may further comprise memory. In some embodiments, the memory may comprise random access memory (RAM), read only memory (ROM), electrically erasable programmable ROM (EEPROM), flash memory, magnetic memory, optical memory, and / or another type of dynamic or static storage device. The memory may store information and / or instructions for use (e.g., execution) by the processor.

[0057] A storage component of one or more of the servers or terminals of elements 100-140 may store information and / or computer-readable instructions and / or code related to the operation and use of one or more of the servers or terminals of elements 100-140. For example, the storage component may include a hard disk (e.g., a magnetic disk, optical disk, magneto-optical disk, and / or solid-state disk), a compact disc (CD), a digital versatile disc (DVD), a universal serial bus (USB) flash drive, a Personal Computer Memory Card International Association (PCMCIA) card, a floppy disk, a cartridge, a magnetic tape, and / or another type of non-transitory computer-readable medium, along with a corresponding drive.

[0058] One or more of the servers or terminals of elements 100-140 may further comprise input components. The input components may include one or more components that enable the servers and one or more of terminals 100-140 to receive information, such as via user input (e.g., a touchscreen, keyboard, keypad, mouse, stylus, button, switch, microphone, camera, etc.). Alternatively or additionally, the input components may include sensors for sensing information (e.g., a global positioning system (GPS) component, an accelerometer, a gyroscope, an actuator, etc.).

[0059] Any one or more output components of the server or terminal of elements 100-140 may include one or more components (e.g., a display, a liquid crystal display (LCD), a light-emitting diode (LED), an organic light-emitting diode (OLED), a haptic feedback device, a speaker, etc.) that may provide output information from device 100.

[0060] One or more of the servers or terminals of elements 100-140 may further comprise a communications interface. The communications interface may include a receiver component, a transmitter component, and / or a transceiver component. The communications interface may enable one or more of the servers or terminals of elements 100-140 to establish connections and / or transfer communications with other devices (e.g., a server, another device). The communications may be enabled via a wired connection, a wireless connection, or a combination of wired and wireless connections. The communications interface may enable one or more of the servers or terminals of elements 100-140 to receive information from and / or provide information to another device. In some embodiments, the communication interface may provide for communication with another device over a network such as a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a private network, an ad hoc network, an intranet, the Internet, an optical fiber-based network, a cellular network (e.g., a fifth-generation (5G) network, a sixth-generation (6G) network, a long-term evolution (LTE) network, a third-generation (3G) network, a code division multiple access (CDMA) network, etc.), a public land mobile network (PLMN), a telephone network (e.g., a public switched telephone network (PSTN)), etc., and / or a combination of these or other types of networks. Alternatively or additionally, the communication interface may enable communication with another device via a device-to-device (D2D) communication link, such as FlashLinQ, WiMedia, Bluetooth, ZigBee, Wi-Fi, LTE, 5G, etc.In other embodiments, the communication interface may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, or the like.

[0061] FIG. 2 illustrates a three-dimensional space representing the normalized levels of each parameter considered for the selection of a cryptographic algorithm for energy-efficient operation in a wireless communication network, according to one embodiment disclosed herein. Referring to FIG. 2, the three-dimensional space optimization described herein is used to provide three normalized levels, namely, "low," "medium," and "high," for each parameter considered for the selection of a cryptographic algorithm for energy-efficient operation in a wireless communication network. Each of the normalized levels is represented in ascending order on the respective x-, y-, and z-axes. Furthermore, the context-based parameters considered within the context-based cryptographic selection system and method described herein may include cryptographic algorithms (or cryptographic families or suites) and their respective encryption level selections based on 1) network usage indicative of network criticality ("network criticality"), 2) energy consumption or energy efficiency in cryptographic operations / joules ("energy efficiency"), and 3) the level of cryptographic protection and security ("security level"). The above parameters are represented on each axis of the three-dimensional space with three normalized levels.

[0062] Here, the methods and systems of the present disclosure described herein include seamless selection of a cryptographic algorithm based on context-based parameters and standardized levels for energy-efficient operation in wireless communication networks. The selection of a cryptographic algorithm from a family of cryptographic algorithms and corresponding variants can be achieved through statistical or machine learning (ML)-based clustering methods. Furthermore, the standardized levels can be extended to more granular levels to determine an optimal combination of cryptographic algorithms and parameters for energy-efficient operation. Here, in some exemplary embodiments, the implementation of cryptographic algorithm selection optimization is described based on an O-RAN architecture implementation. However, within the scope of the present disclosure described herein, it is contemplated that the disclosed methods and systems can also be more supported through a cloud orchestration layer.

[0063] 3 is a process flow or signaling diagram illustrating a method for enabling O-RAN network-compatible selection of cryptographic algorithms for energy-efficient operation within a service management and orchestrator (SMO) module or framework 100, according to one example of the present disclosure described herein. In particular, in step 1, the O-Cloud platform module 200 transmits collected O1 and O2 telemetry data to the SMO module or framework 100, which includes an rApp module 120 and a non-real-time RAN intelligent controller platform module 140 (“non-RT RIC”). Here, the rApp module 120 can be any type of RAN automation application or process, such as a network evolution rApp, a network deployment rApp, a network optimization rApp, a network repair rApp, and an automation and artificial intelligence (AI) rApp. Furthermore, the non-RT RIC module 140 can be an orchestration and automation function, and can be an element of an open RAN architecture that can control and optimize other RAN elements and resources, particularly using artificial intelligence and machine learning to enhance the control and optimization of such network resources. Additionally, O-Cloud module 200 may be a general cloud infrastructure network-based module. In step 2, rApp module 120 hosted in non-RT RIC platform module 140 may analyze O1 and O2 telemetry data and identify a cipher suite or cryptographic algorithm family based on the use case and security level (among other factors). Here, elements O1 and O2 may be interfaces connecting SMO module or framework 100 to rApp module 120 and non-RT RIC module 140 (and any other RAN management elements). In particular, the O2 interface is generally how SMO module or framework 100 communicates with O-Cloud platform module 200.

[0064] Continuing with FIG. 3 , in step 3, cryptographic policy (“cryptographic policy”) guidance information is sent to the O-Cloud platform module 200 for the SMO module or framework 100 to select an energy-efficient cryptographic algorithm, e.g., an algorithm such as Falcon or Crystal Dilithium. Here, cryptographic policy may refer to rule-based conditions determined in an rApp. Furthermore, because there is a predetermined set of cryptographic algorithms in the context of PQC, application of these rule-based conditions will result in one or more groups of cryptographic algorithms. One way to find this mapping to one or more other groups of cryptographic algorithms may be via a table lookup. However, in other embodiments, a more granular approach via a decision tree / machine learning process may also be used. In step 4, the O-Cloud platform module 200 successfully selects a cryptographic policy, such as a cryptographic policy associated with the Falcon cryptographic algorithm, and the selected cryptographic policy is then sent to the SMO module or framework 100. Furthermore, the rApp / non-RT RIC module receives confirmation of the change in the selected cryptographic policy in the O-Cloud platform module 200.

[0065] Continuing with reference to FIG. 3 , in step 5, the rApp / non-RT RIC module of the SMO module or framework 100 generates final cryptographic policy guidance data for the O-Cloud platform module 200. Then, in step 6, the SMO module or framework 100 sends the final cryptographic policy guidance information for the cryptographic algorithm and parameters to be applied to both data at rest and data in transit to the O-Cloud platform module 200. As an example, such final cryptographic policy guidance information for the Falcon cryptographic algorithm may include, among other things, Q for the number of queries, λ for the target security level, and n for the ring order. Here, it can be assumed that the system has a previous baseline cryptographic policy enabled before the final cryptographic policy is applied in step 6. For example, in the 3GPP® standard, even if encryption is disabled, it is treated as a cryptographic policy using null encryption. Furthermore, a method for cipher suite optimization may be performed within an algorithm implemented within the rApp module 120 hosted in the non-RT RIC platform module 140. The energy consumption telemetry information collected from the O-Cloud platform, the network usage context, and the security level of the algorithms can be used as inputs to generate cryptographic policies to be enforced on the interfaces (O1, O2, A1, etc.) and the cloud platform (persistent data encryption, etc.).

[0066] Still referring to step 6 of FIG. 3 , as previously disclosed, one embodiment of the final cryptographic policy guidance may include the Falcon cryptographic algorithm family of PQC algorithms. For further illustrative purposes, the algorithm may meet high security, high energy, and high network criticality characteristics, as shown in Table 2. Furthermore, three key parameters of this algorithm class are 1) the maximum number of signature queries, Q; 2) the target security level, λ; and 3) the degree, n, of the ring, Z. For NIST Level I, Q=2^64, n=512, and λ=128; and for NIST Level V, n=1024 and λ=256. Thus, for illustrative purposes, the final cryptographic policy and parameters for a critical infrastructure network, such as smart grid security, in CSV format may be represented as {(Security-High, Energy-High, Critical-High)(Q=2^64, n=1024, λ=256)}.

[0067] Here, in one exemplary embodiment, some of the exemplary cryptographic algorithm suites or families may be represented in an exemplary decision or truth table, as shown with respect to Table 1, which illustrates some partial exemplary possibilities for context-based cryptographic algorithm or suite selection based on standardized levels (low, medium, high) as applied to network security level, energy efficiency, and network criticality. However, a total of 3 3 It is contemplated within the scope of the present disclosure described herein that there may be 27 possibilities. As an example, if the desired security level is low and the energy efficiency requirement is low, but the network criticality requirement or importance is medium, then a DualModeMS cipher family or suite may be selected for efficient energy operation within the network.

[0068] [Table 1]

[0069] Here, the selection of a cryptographic algorithm, suite, scheme, or family may be further based on the energy consumption of the key generation operation among various PQC algorithms and their security levels (or families of cryptographic algorithms). In addition, the energy consumption during signing of a public key signature may also be taken into account when determining the selection of an appropriate PQC algorithm, and may be considered for various PQC algorithms (or families of cryptographic algorithms).

[0070] Because the energy consumption during each operation may differ based on the software implementation and hardware platform on which the operation is performed, it is further contemplated within the scope of the disclosure described herein that there may be other suitable recommendations dynamically generated for different cryptographic operations, such as those shown in Table 1. In one exemplary embodiment, an alternative decision function for public key signatures is shown below with respect to Table 2.

[0071] [Table 2]

[0072] Additionally, contextual information related to the application, network, and deployment can be captured at system initialization time through one of an application programming interface (API) and operator input. In one or more exemplary embodiments, the mapping of network criticality levels is shown below in Table 3, and the mapping of network security levels is shown below in Table 4.

[0073] [Table 3]

[0074] [Table 4]

[0075] FIG. 5 shows a flowchart of an exemplary embodiment of a context-based cipher selection method for energy-efficient operation and a method for determining a cipher configuration for a system, such as logic embedded within an xApp when determining a cipher configuration. Here, in step 502, the method may include initializing system parameters and collecting telemetry information for the O-Cloud module 200 via the O1 and O2 interfaces. Next, in step 504, the method may include receiving external system context via an application program interface (API) or operator input, which may include a network criticality level and applicable security levels. Here, the external system context may refer to information that may be unrelated to the network operation or security level itself. One example of this may be a change in the energy source of network operation, which may result from an event such as a power grid failure, among other things. When such an event occurs, the network system may switch to an alternative or temporary energy source, such as a change to a sustainable / renewable energy source to reduce power consumption. Under such a scenario of reduced network power consumption, the lowest energy encryption algorithm is selected to comply with the reduced power consumption requirement for the network, despite the predetermined rules for cryptographic policy selection. Then, in step 506, the method may include determining an optimal energy-efficient cryptographic configuration via a table lookup / supervised learning or decision tree approach. Next, in step 508, the method may include the O-Cloud module 200 selecting final cryptographic parameters from the cryptographic family guidance received from the rApp module 120 and the SMO module or framework 100. Next, in step 510, the method may include providing the final policy guidance to the O-Cloud layer module 200 by the rApp security application or rApp module 120. Further, in step 512, the final cryptographic policy can be applied to the O-Cloud layer module 200.Here, the aforementioned process of FIG. 5 can be achieved at the K8S orchestration layer, particularly for data-at-rest encryption on the cloud platform.

[0076] Table 5 provides a summary of one exemplary embodiment of configuration parameters that may be used with the context-based selection methods and systems of the present disclosure described herein, where the configuration parameters from "Encrypting Secret Data at Rest" by Kubernetes (May 30, 2022), which are currently available but do not comply with post-quantum cryptography requirements, may be considered a "low" security level.

[0077] [Table 5]

[0078] However, AES with key lengths of 256 or greater is currently considered quantum safe and can be supported through cryptographic library extensions at the Kubernetes layer. This can be securely exposed through an extension to the kube-apiserver encryption configuration, namely, "Encrypting Secret Data at Rest" by Kubernetes (May 30, 2022). Therefore, the security levels to which AES can be mapped against the PQC requirements are provided in Table 6 below.

[0079] [Table 6]

[0080] Additionally, a ProviderConfiguration API field appears in the ResourceConfiguration API field, which can store the provided configuration for the cryptographic provider as provided by Kubernetes, as shown in Table 7.

[0081] [Table 7]

[0082] Here, in the example of Table 7, the PostQuantumEncryption API can be extended to support the ProviderConfiguration API field. The PQCConfiguration API field description can include the algorithms and keys used to create the encryption transformer, such as AES 128, 192, and 256-bit keys. The PostQuantumEncryption field contains API configuration information for the AES encryption transformer, as provided in Table 8.

[0083] [Table 8]

[0084] Here, the Key field may contain the name and secret data of the provided key for the cryptographic transformer, as provided in Table 9.

[0085] [Table 9]

[0086] It should be understood that the specific order or hierarchy of blocks in the processes / flowcharts disclosed herein is an example of an example approach. Based on design preferences, it should be understood that the specific order or hierarchy of blocks in the processes / flowcharts may be rearranged. Further, some blocks may be combined or omitted. The accompanying method claims present elements of the various blocks in a sample order and are not limited to the specific order or hierarchy presented.

[0087] Some embodiments may relate to systems, methods, and / or computer-readable media at any possible level of technical detail. Furthermore, one or more of the above components described above may be implemented as instructions stored on a computer-readable medium and executable by at least one processor (and / or may include at least one processor). The computer-readable medium may include a computer-readable non-transitory storage medium (or media) having computer-readable program instructions for causing a processor to perform operations.

[0088] A computer-readable storage medium may be a tangible device that can hold and store instructions for use by an instruction execution device. The computer-readable storage medium may be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory stick, floppy disk, mechanically encoded devices such as punch cards or groove ridge structures having instructions recorded thereon, and any suitable combination of the foregoing. As used herein, computer-readable storage media should not be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses passing through a fiber optic cable), or electrical signals transmitted through wires.

[0089] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in the respective computing / processing device.

[0090] The computer-readable program code / instructions for carrying out operations may be either source code or object-oriented programming languages ​​written in any combination of one or more programming languages, including assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or object code such as Smalltalk, C++, and procedural programming languages ​​such as the "C" programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet Service Provider). In some embodiments, electronic circuits including, for example, programmable logic circuits, field programmable gate arrays (FPGAs), or programmable logic arrays (PLAs) may execute computer-readable program instructions by utilizing state information in the computer-readable program instructions to personalize the electronic circuit to perform aspects or operations.

[0091] These computer-readable program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, executing via the processor of the computer or other programmable data processing apparatus, produce means for implementing the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. These computer-readable program instructions may also be stored on a computer-readable storage medium that can direct a computer, programmable data processing apparatus, and / or other device to function in a particular manner, such that the computer-readable storage medium on which the instructions are stored comprises a product containing instructions that implement aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.

[0092] The computer-readable program instructions may also be loaded into a computer, other programmable data processing apparatus, or other device and cause the computer, other programmable apparatus, or other device to perform a series of operational steps to create a computer-implemented process, such that the instructions, running on the computer, other programmable apparatus, or other device, implement the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.

[0093] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer-readable media according to various embodiments. In this regard, each block in the flowcharts or block diagrams may represent a module, segment, or portion of instructions, including one or more executable instructions for implementing the specified logical function(s). The methods, computer systems, and computer-readable media may include additional, fewer, different, or differently arranged blocks than shown in the figures. In some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the figures. For example, two blocks shown in succession may actually be executed concurrently or substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block of the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, can be implemented by a dedicated hardware-based system that performs the specified functions or operations or executes a combination of dedicated hardware and computer instructions.

[0094] It will be apparent that the systems and / or methods described herein may be implemented in different forms of hardware, firmware, or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not intended to limit the implementation. Thus, the operation and behavior of the systems and / or methods are described herein without reference to specific software code, and it will be understood that software and hardware can be designed to implement the systems and / or methods based on the description herein.

Claims

1. 1. A method for selecting a cryptographic algorithm in a network, the method comprising: receiving network data from one or more network interfaces or network elements; analyzing the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms; identifying the cryptographic algorithm from the plurality of cryptographic algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency; A method comprising:

2. 2. The method of claim 1, wherein the step of analyzing the network data to identify the cryptographic algorithm further comprises receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance related to the network security level parameter.

3. 2. The method of claim 1, wherein the step of analyzing the network data to identify the cryptographic algorithm further comprises receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance related to the network criticality parameter.

4. 2. The method of claim 1, wherein analyzing the network data to identify the cryptographic algorithm further comprises receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance associated with the energy efficiency parameter.

5. 10. The method of claim 1, wherein the step of receiving network data from one or more network interfaces or network elements is further based on a service management and orchestrator (SMO) framework, the SMO framework including an orchestrator module in communication with a network infrastructure module.

6. The method of claim 5 , wherein the step of analyzing the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms is performed via the orchestrator module.

7. The method of claim 6 , further comprising transmitting the identified cryptographic algorithm from the orchestrator module to the network infrastructure module.

8. 8. The method of claim 7, further comprising receiving, via the orchestrator module, from the network infrastructure module, a selection of conditions for the identified cryptographic algorithm.

9. 10. The method of claim 8, further comprising generating, via the orchestrator module, a cryptographic policy for the network regarding the identified cryptographic algorithm.

10. 10. The method of claim 9, further comprising: transmitting, via the orchestrator module, the cryptographic policy for the network for the identified cryptographic algorithm to the network infrastructure module.

11. 1. An apparatus for selecting a cryptographic algorithm in a network, comprising: memory storage for storing computer-executable instructions; a processor communicatively coupled to the memory storage, the processor executing the computer-executable instructions to cause the device to: receiving network data from one or more network interfaces or network elements; analyzing the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms; identifying the cryptographic algorithm from the plurality of cryptographic algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency; An apparatus configured to cause

12. The computer-executable instructions, when executed by the processor, further cause the device to: The apparatus of claim 11 , further comprising: receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance level relative to the network security level parameter.

13. The computer-executable instructions, when executed by the processor, further cause the device to: The apparatus of claim 11 , further comprising: receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance level related to the network criticality parameter.

14. The computer-executable instructions, when executed by the processor, further cause the device to: The apparatus of claim 11 , further comprising: receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with an importance associated with the energy efficiency parameter.

15. 12. The apparatus of claim 11, wherein the step of receiving network data from one or more network interfaces or network elements is further based on a Service Management and Orchestrator (SMO) framework, the SMO framework including an orchestrator module in communication with a network infrastructure module.

16. 16. The apparatus of claim 15, wherein the step of analyzing the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms is performed via the orchestrator module.

17. The computer-executable instructions, when executed by the processor, further cause the device to: The apparatus of claim 16 , further comprising causing the identified cryptographic algorithm to be transmitted from the orchestrator module to the network infrastructure module.

18. The computer-executable instructions, when executed by the processor, further cause the device to:

20. The apparatus of claim 17, further comprising: receiving, via the orchestrator module, from the network infrastructure module, a selection of conditions for the identified cryptographic algorithm.

19. The computer-executable instructions, when executed by the processor, further cause the device to:

20. The apparatus of claim 18, further comprising: generating, via the orchestrator module, a cryptographic policy for the network related to the identified cryptographic algorithm.

20. 1. A non-transitory computer-readable medium comprising computer-executable instructions for selecting a cryptographic algorithm in a network by a device, the computer-executable instructions, when executed by at least one processor of the device, causing the device to: receiving network data from one or more network interfaces or network elements; analyzing the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms; identifying the cryptographic algorithm from the plurality of cryptographic algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency; A non-transitory computer-readable medium for causing

Citation Information

Patent Citations

  • Apparatus, method and program for encryption management

    JP2009089044A

  • Encryption management apparatus, decryption management apparatus, and program

    JP2009100462A

  • End-to-end authentication at the service layer using public key mechanism

    JP2018518854A