Context-based cryptography selection

JP7927969B2Active Publication Date: 2026-10-01RAKUTEN MOBILE INC +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025500316
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-07-13
Filing Date
2022-09-22
Publication Date
2026-10-01
Estimated Expiration
2042-09-22

Smart Images

  • Figure 0007927969000010
    Figure 0007927969000010
  • Figure 0007927969000011
    Figure 0007927969000011
  • Figure 0007927969000012
    Figure 0007927969000012
Patent Text Reader

Abstract

[0009] A system and method for selecting a cryptographic algorithm in a network may include receiving network data from one or more network interfaces or network elements, analyzing the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms, and identifying the cryptographic algorithm from the plurality of cryptographic algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency. Additionally, analyzing the network data to identify the cryptographic algorithm may further include receiving a plurality of identifiers associated with the network data, each of the plurality of identifiers further associated with a significance related to the network security level parameter.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross-Reference to Related Applications This application claims priority based on Indian Patent Application No. 202241040077 filed on July 13, 2022, the entire disclosure of which is incorporated herein by reference.

[0002] The present disclosure described herein relates to context-based cipher selection for energy-efficient operation.

Background Art

[0003] Various standards organizations are focusing on Post Quantum Cryptography (PQC) algorithms that can withstand cryptanalytic attacks by quantum computers due to the availability of quantum computing resources. Various PQC algorithms are being studied by standards organizations such as the National Institute of Standards and Technology (NIST), which is evaluating PQC algorithms as disclosed, for example, in NIST IR 8413, "Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process", issued in July 2022. In addition, Banerjee et al., "Energy Consumption of Candidate Algorithms for NIST PQC Standards", University of Waterloo, pp.1-13, discusses energy consumption analysis of various cryptographic algorithms. Furthermore, multiple proprietary and open-source implementations of PQC algorithms are also available for researchers to study performance characteristics and cryptographic strength.

[0004] Therefore, due to the requirement that PQC algorithms be quantum resistant, the complexity of the cryptographic operations involved in PQC algorithms needs to be enhanced in terms of new mathematical principles, increased key sizes, and algorithmic complexity. The general method proposed by NIST for classifying PQC algorithms in terms of the level of security they provide is as follows:

[0005] Level I: This is at least as difficult as breaking the security of a block cipher using an exhaustive key search with a 128-bit key, such as the Advanced Cryptographic Standard (AES) 128, for example, but not limited to this.

[0006] Level II: It may be at least as difficult to break the security of the hashing function using collision detection with a 256-bit hashed hash algorithm, such as, but not limited to, Secure Hash Algorithm (SHA) 256 / SHA3-256.

[0007] Level III: It may be at least as difficult to break the security of a block cipher using an exhaustive key search with a 192-bit key, such as AES192.

[0008] Level IV: It may be at least as difficult to break the security of the hashing function using collision searching with a 384-bit hashed message digest, such as SHA384 / SHA3-384, but not limited to these.

[0009] Level V: For example, AES256, but not limited to this, is at least as difficult to break using an exhaustive key search with a 256-bit key.

[0010] However, enhanced cryptographic operation imposes higher performance requirements on the computing device's central processing unit (CPU) and memory resources compared to other components, and therefore can lead to higher energy consumption by network elements. Wireless communication networks, such as Open Radio Access Network (O-RAN) elements deployed beyond 5G or 6G, are expected to support zero-trust network design and operation. All network element interfaces may need to provide methods to secure the confidentiality, integrity, and authenticity of operations that must be achieved by the implementation form of PQC cryptographic methods and protocols. While standards specify various PQC algorithms and associated parametric variations, these standards will have different levels of energy consumption signatures. As a result, mobile network operators face the very complex problem of adopting the appropriate encryption algorithm for each network use case, leading to suboptimal or suboptimal selections of PQC algorithms and parameters, thereby resulting in wasted resource and energy consumption. Therefore, it is desirable to address the aforementioned disadvantages or other drawbacks and provide useful alternatives.

[0011] Therefore, what is needed is a method and system for context-based cryptographic selection that requires minimal energy consumption, resource efficiency, and places little burden on computing resources and network elements. [Prior art documents] [Patent Documents]

[0012] [Non-Patent Document 1] NIST IR 8413, “Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process” [Non-Patent Document 2] Banerjee et al. “Energy Consumption of Candidate Algorithms for NIST PQC Standards” University of Waterloo, pp.1-13 [Overview of the Initiative]

[0013] According to exemplary embodiments, a context-based cryptographic selection method and system for energy-efficient operation in wireless communication networks is disclosed. The method and system can provide an optimal and automated process for determining an appropriate PQC cryptographic algorithm based on various parameters, including, but not limited to, the context of network usage, the level of cryptographic protection, and energy consumption. Among other advantages, the method and system of the disclosure described herein enables reduced energy consumption, optimization of the encryption level based on the context of network usage, and associated performance improvements (such as reduced latency) through automation in the decision-making process.

[0014] In other exemplary embodiments, methods and systems for context-based cryptographic selection for energy-efficient operation are disclosed, which may include initializing system parameters, collecting O-Cloud telemetry information via O1 and O2 interfaces, and receiving external system context via an application interface or operator input, which may include network criticality levels and applicable security levels. The methods and systems of the disclosure described herein may also include determining an optimal energy-efficient cryptographic configuration via a reference table, supervised learning, or decision tree technique, and selecting final cryptographic parameters from cryptographic family guidance received via O-Cloud from an rApp and a Service Management and Orchestrator (SMO), where rApp refers to an application hosted on a non-real-time RAN intelligent controller (non-RT-RIC). The methods and systems of the disclosure described herein may also include providing final policy guidance from an rApp security application to the O-Cloud layer and applying the policy to the O-Cloud layer. Furthermore, cryptographic optimization can be more commonly supported through cloud orchestration layers.

[0015] According to other exemplary embodiments, a method for selecting a cryptographic algorithm in a network is disclosed. The method may include receiving network data from one or more network interfaces or network elements, analyzing the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms, and identifying a cryptographic algorithm from a plurality of cryptographic algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency.

[0016] In addition, the step of analyzing network data to identify cryptographic algorithms may further include receiving multiple identifiers associated with the network data, each of which is further associated with a degree of importance related to network security level parameters.

[0017] Furthermore, the step of analyzing network data to identify a cryptographic algorithm may further include receiving multiple identifiers associated with the network data, each of which is further associated with a degree of importance related to the network criticality parameter.

[0018] Furthermore, the step of analyzing network data to identify cryptographic algorithms may further include receiving multiple identifiers associated with the network data, each of which is further associated with a degree of importance related to energy efficiency parameters.

[0019] In addition, the step of receiving network data from one or more network interfaces or network elements within the network is further based on a Service Management and Orchestrator (SMO) framework, the SMO framework including an orchestrator module that communicates with a network infrastructure module.

[0020] Furthermore, the step of analyzing network data to identify a cryptographic algorithm from among multiple cryptographic algorithms may be performed via an orchestrator module.

[0021] Furthermore, the method may include transmitting the identified cryptographic algorithm from the orchestrator module to the network infrastructure module.

[0022] The method may also include receiving a selection of conditions relating to an identified cryptographic algorithm from a network infrastructure module via an orchestrator module.

[0023] In addition, the method may further comprise generating, via an orchestrator module, an encryption policy for the network related to the identified encryption algorithm.

[0024] Furthermore, the method may further comprise transmitting, via the orchestrator module, the encryption policy for the network related to the identified encryption algorithm to a network infrastructure module.

[0025] In another exemplary embodiment, an apparatus for selecting an encryption algorithm in a network is disclosed. The apparatus may comprise a memory storage storing computer-executable instructions, and a processor communicatively coupled to the memory storage, wherein the processor executes the computer-executable instructions and is configured to cause the apparatus to: receive network data from one or more network interfaces or network elements; analyze the network data to identify the encryption algorithm from a plurality of encryption algorithms; and identify the encryption algorithm from the plurality of encryption algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency.

[0026] In addition, when executed by the processor, the computer-executable instructions may further cause the apparatus to receive a plurality of identifiers associated with the network data, wherein each of the plurality of identifiers is further associated with a degree of importance related to a network security level parameter.

[0027] Furthermore, when executed by the processor, the computer-executable instructions may further cause the apparatus to receive a plurality of identifiers associated with the network data, wherein each of the plurality of identifiers is further associated with a degree of importance related to a network criticality parameter.

[0028] Furthermore, when the computer executable instruction is executed by the processor, it can cause the device to receive multiple identifiers associated with network data, each of which is further associated with a degree of importance regarding energy efficiency parameters.

[0029] In addition, the step of receiving network data from one or more network interfaces or network elements within the network may further be based on a service management and orchestrator (SMO) framework, the SMO framework including an orchestrator module that communicates with a network infrastructure module.

[0030] Furthermore, the step of analyzing network data to identify a cryptographic algorithm from among multiple cryptographic algorithms may be performed via an orchestrator module.

[0031] Furthermore, once the computer executable instructions are executed by the processor, the device may also cause the orchestrator module to transmit an identified cryptographic algorithm to the network infrastructure module.

[0032] Furthermore, once the computer-executable instruction is executed by the processor, the device may also receive, via the orchestrator module, a selection of conditions relating to the identified cryptographic algorithm from the network infrastructure module.

[0033] Furthermore, when the computer executable instructions are executed by the processor, the device may, further via an orchestrator module, cause the device to generate a cryptographic policy for the network relating to the identified cryptographic algorithm.

[0034] In other exemplary embodiments, a non-temporary computer-readable medium is disclosed which includes a computer-executable instruction for the device to select a cryptographic algorithm in a network, the computer-executable instruction, when executed by at least one processor of the device, causes the device to: receive network data from one or more network interfaces or network elements; analyze the network data to identify a cryptographic algorithm from a plurality of cryptographic algorithms; and identify a cryptographic algorithm from a plurality of cryptographic algorithms based on at least one of the following parameters: network security level, network criticality, or energy efficiency. [Brief explanation of the drawing]

[0035] The features, advantages, and importance of exemplary embodiments of the disclosed invention will now be described with reference to the attached drawings, where similar reference numerals indicate similar elements.

[0036] [Figure 1] This figure shows a general system architecture of one or more embodiments of the context-based cryptographic selection methods and systems of the disclosure described herein. [Figure 2] A perspective view in three-dimensional space is shown, representing a standardized level of parameters considered for selecting cryptographic algorithms for energy-efficient operation in wireless communication networks, according to one or more embodiments. [Figure 3] Another diagram shows a method, according to one or more embodiments, for enabling O-RAN network-compatible selection of cryptographic algorithms for energy-efficient operation using a service management and orchestrator (SMO). [Figure 4] Process flow diagrams illustrating one or more embodiments of the context-based cryptographic selection method and cryptographic configuration for the system described herein are shown. [Modes for carrying out the invention]

[0037] A detailed description of exemplary embodiments follows with reference to the accompanying drawings. The same reference numerals in different drawings may identify the same or similar elements.

[0038] The above disclosure provides examples and explanations, but is not intended to be exhaustive or to limit implementations to the exact forms disclosed. Modifications and variations are possible in light of the above disclosure or can be derived from the practice of implementations. Furthermore, one or more features or components of one embodiment may be incorporated into or combined with another embodiment (or one or more features of another embodiment). In addition, it should be understood that in the flowcharts and descriptions of operation provided below, one or more operations may be omitted, one or more operations may be added, one or more operations may be performed (at least partially) simultaneously, and the order of one or more operations may be changed.

[0039] It will be apparent that the systems and / or methods described herein may be implemented in different forms of hardware, firmware, or combinations of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods is not limited to any particular implementation. Therefore, the operation and behavior of the systems and / or methods are described herein without reference to specific software code, and it is understood that software and hardware may be designed to implement the systems and / or methods based on the descriptions herein.

[0040] While specific combinations of features are described in the claims and / or disclosed herein, these combinations do not limit the disclosure of possible implementations. In fact, many of these features can be combined in ways not specifically described in the claims and / or disclosed herein. Each of the dependent claims listed below may directly depend on only one claim, but the disclosure of possible implementations includes each dependent claim combined with all other claims in the set of claims.

[0041] Any element, action, or command used herein should not be construed as important or essential unless expressly stated otherwise. Furthermore, as used herein, the articles “a” and “an” are intended to include one or more items and may be used synonymously with “one or more.” When only one item is intended, the term “one” or similar language is used. Also, as used herein, terms such as “has,” “have,” “having,” “include,” and “including” are intended to be open-ended terms. Furthermore, the phrase “based on” should mean “at least partially based on” unless otherwise specified. Additionally, expressions such as “at least one of [A] and [B]” or “at least one of [A] or [B]” should be understood as including only A, only B, or both A and B.

[0042] Throughout this specification, any reference to “one embodiment,” “a certain embodiment,” “a non-limiting exemplary embodiment,” or similar language means that a particular feature, structure, or characteristic described in relation to the embodiment shown is included in at least one embodiment of the present solution. Therefore, throughout this specification, the phrases “in one embodiment,” “in a certain embodiment,” “in one non-limiting exemplary embodiment,” and similar language may, but not necessarily, all refer to the same embodiment.

[0043] Furthermore, the features, advantages, and characteristics described herein can be combined in any suitable manner in one or more embodiments. Those skilled in the art will recognize, in light of the description herein, that the disclosure may be practiced without one or more of the specific features or advantages of a particular embodiment. In other cases, additional features and advantages that may not be present in all embodiments of the disclosure may be recognized in a particular embodiment.

[0044] In one implementation of the disclosure described herein, a display page may contain information residing in the memory of a computing device, which can be transmitted over a network from the computing device to a database center and vice versa. The information may be stored in the memory of the computing device, data storage located at the edge of the network, or a server in the database center. A computing device or mobile device may receive non-temporary computer-readable media, which may contain instructions, logic, data, or code that can be stored in the persistent or temporary memory of the mobile device, or may influence or initiate an action by the mobile device. Similarly, one or more servers may communicate with one or more mobile devices over a network and transmit computer files residing in memory. The network may include, for example, the Internet, a wireless communication network, or any other network for connecting one or more mobile devices to one or more servers.

[0045] Any discussion of computing or mobile devices may also apply to any type of networked device, including but not limited to mobile devices such as mobile phones (e.g., any “smartphone”), personal computers, server computers, or laptop computers, and wireless devices such as personal digital assistants (PDAs), roaming devices such as network-connected roaming devices, wireless email devices, or other devices capable of wireless communication with computer networks, or any other type of network device capable of communicating over a network and handling electronic transactions. Any description of any mobile device mentioned may also apply to other devices, including, among others, ultra-high frequency (UHF) devices, near-field communication (NFC), infrared (IR), and devices with Wi-Fi capabilities.

[0046] The terms and phrases "software," "application," "app," and "firmware" may include any non-temporary computer-readable medium that stores a program that, when executed by a computer, causes the computer to perform a method, function, or control action.

[0047] Words and terms similar to “network” may include one or more data links that enable the transfer of electronic data between computer systems and / or modules. When information is transferred to or provided to a computer via a network or another communication connection (either wired, wireless, or a combination of wired and wireless), the computer uses that connection as a computer-readable medium. Thus, as an example, and not an limitation, a computer-readable medium may also include a network or data link that can be used to carry or store desired program code means in the form of computer-executable instructions or data structures and can be accessed by a general-purpose or dedicated computer.

[0048] The terms and phrases similar to “portal” or “terminal” may include intranet pages, internet pages, locally residing software or applications, mobile device graphical user interfaces, or digital presentations for users. A portal may also be any graphical user interface for accessing the various modules, components, features, options, and / or attributes of the disclosure described herein. For example, a portal may be a web page accessed by a web browser, a mobile device application, or any application or software residing on a computing device.

[0049] Figure 1 shows a diagram of a typical network architecture according to one or more embodiments. Referring to Figure 1, an end user 110, a network support team user 120, and an administrator terminal / dashboard user 130 (collectively referred to herein as users 110, 120, and 130) can communicate bidirectionally with a central server or application server 100 via a secure network according to one or more embodiments. In addition, users 110, 120, and 130 may also communicate directly and bidirectionally with each other via the network system of the disclosure described herein, according to one or more embodiments. Here, user 110 could be any type of customer, network service provider agent, or vendor of a network or communication service provider, such as a user operating computing devices and user terminals A, B, and C. Each of users 110 can communicate with server 100 via their respective terminal or portal, and server 110 may provide or automatically operate the network impact prediction engine system and method of the disclosure described herein. User 120 may include application development members or support agents of a network service provider for developing, integrating, and monitoring the context-based cryptographic selection methods and systems of the Disclosure described herein, including assisting with network events, scheduling / correcting them, and providing support services to end users 110. Administrator terminal / dashboard user 130 may be any type of user with access privileges to access the dashboard or management portal of the Disclosure described herein, the dashboard portal may provide various user tools, GUI information, maps, graphs, and customer support options. Within the scope of the Disclosure described herein, it is intended that either User 110 or 120 may also access the Administrator Terminal / Dashboard 130 of the Disclosure described herein.

[0050] Referring further to Figure 1, in one or more embodiments, the central server 100 of the disclosure described herein can further communicate bidirectionally with a database / third-party server 140, which may also include a user. Here, the server 140 may include vendors and databases on which various ingested, collected, or aggregated data, such as current, real-time, and historical network-related history and KPI data, can be stored and read from for network analysis, prediction, and simulation by the server 100. Furthermore, the server 140 may include various cryptographic family suites or algorithms. However, within the scope of the disclosure described herein, the context-based cryptographic selection methods and systems of the disclosure described herein may include any type of general network architecture.

[0051] Referring further to Figure 1, one or more of the servers or terminals of elements 100 to 140 may include a personal computer (PC), a printed circuit board with a computing device, a minicomputer, a mainframe computer, a microcomputer, a telephone computing device, a wired / wireless computing device (e.g., a smartphone, a personal digital assistant (PDA)), a laptop, a tablet, a smart device, a wearable device, or any other similar functional device.

[0052] In some embodiments, as shown in Figure 1, one or more servers, terminals, and users 100-140 may include a set of components such as a processor, memory, storage components, input components, output components, communication interfaces, and JSON UI rendering components. The set of device components may be coupled together communicatively via a bus.

[0053] The bus may comprise one or more components that enable communication between one or more components from among the server or terminal elements 100 to 140. For example, the bus may be a communication bus, a crossover, a network, etc. The bus may be implemented using one or more (two or more) connections between the set of one or more components from among the server or terminal elements 100 to 140. This disclosure is not limited in this respect.

[0054] One or more of the servers or terminals of element 100 to 140 may comprise one or more processors. One or more processors may be implemented as hardware, firmware, and / or a combination of hardware and software. For example, one or more processors may comprise a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), a microprocessor, a microcontroller, a digital signal processor (DSP), a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a general-purpose single-chip or multi-chip processor, or other programmable logic devices, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, or any conventional processor, controller, microcontroller, or state machine. One or more processors may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors working in conjunction with a DSP core, or any other such configuration. In some embodiments, certain processes and methods may be performed by circuits specific to a given function.

[0055] One or more processors can control the overall operation of one or more servers or terminals from element 100 to 140, and / or a set of components (e.g., memory, storage components, input components, output components, communication interfaces, rendering components) of one or more servers or terminals from element 100 to 140.

[0056] One or more of the servers or terminals of elements 100 to 140 may further include memory. In some embodiments, the memory may include random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM), flash memory, magnetic memory, optical memory, and / or other types of dynamic or static storage devices. The memory can store information and / or instructions for use by the processor (e.g., execution).

[0057] One or more storage components among the servers or terminals of elements 100 to 140 may store information regarding the operation and use of one or more of the servers or terminals of elements 100 to 140, and / or computer-readable instructions and / or code. For example, storage components may include hard disks (e.g., magnetic disks, optical disks, magneto-optical disks, and / or solid-state disks), compact discs (CDs), digital versatile discs (DVDs), universal serial bus (USB) flash drives, Personal Computer Memory Card International Association (PCMCIA) cards, floppy disks, cartridges, magnetic tapes, and / or other types of non-temporary computer-readable media, along with their corresponding drives.

[0058] One or more of the servers or terminals of elements 100 to 140 may further comprise input components. The input components may include one or more components that enable one or more of the servers and terminals 100 to 140 to receive information via user input (e.g., touchscreen, keyboard, keypad, mouse, stylus, button, switch, microphone, camera, etc.). Alternatively or additionally, the input components may include sensors for sensing information (e.g., global positioning system (GPS) components, accelerometer, gyroscope, actuator, etc.).

[0059] Any one or more output components among the servers or terminals of elements 100 to 140 may include one or more components that can provide output information from device 100 (e.g., a display, a liquid crystal display (LCD), a light-emitting diode (LED), an organic light-emitting diode (OLED), a haptic feedback device, a speaker, etc.).

[0060] One or more of the servers or terminals of elements 100 to 140 may further comprise a communication interface. The communication interface may include receiver components, transmitter components, and / or transceiver components. The communication interface may enable one or more of the servers or terminals of elements 100 to 140 to establish connections with other devices (e.g., servers, other devices) and / or transmit communications. Communications may be enabled via wired connections, wireless connections, or a combination of wired and wireless connections. The communication interface may enable one or more of the servers or terminals of elements 100 to 140 to receive information from and / or provide information to other devices. In some embodiments, the communication interface can provide communication with another device over a network such as a local area network (LAN), wide area network (WAN), metropolitan area network (MAN), private network, ad hoc network, intranet, internet, fiber optic network, cellular network (e.g., 5G network, 6G network, long-term evolution (LTE) network, 3G network, code division multiple access (CDMA) network, etc.), public land mobile network (PLMN), telephone network (e.g., public switched telephone network (PSTN)), and / or a combination of these or other types of networks. Alternatively or additionally, the communication interface may enable communication with another device via a device-to-device (D2D) communication link, such as FlashLinQ, WiMedia, Bluetooth, ZigBee, Wi-Fi, LTE, or 5G.In other embodiments, the communication interface may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, and the like.

[0061] Figure 2 shows a three-dimensional space representing the normalized levels of each parameter considered for the selection of a cryptographic algorithm for energy-efficient operation in a wireless communication network, according to one embodiment disclosed herein. Referring to Figure 2, the three-dimensional space optimization of the disclosure described herein is used to assign three normalized levels, namely "low," "medium," and "high," to each parameter considered for the selection of a cryptographic algorithm for energy-efficient operation in a wireless communication network. Each of the normalized levels is represented in ascending order on the respective x, y, and z axes. Furthermore, the context-based parameters considered within the context-based cryptographic selection system and method of the disclosure described herein may include a cryptographic algorithm (or cryptographic family or suite) and the selection of each cryptographic level based on 1) network usage indicating network criticality ("network criticality"), 2) energy consumption or energy efficiency in cryptographic operation / joules ("energy efficiency"), and 3) levels of cryptographic protection and security ("security level"). The above parameters are represented on each axis of the three-dimensional space along with the three normalized levels.

[0062] Here, the methods and systems of the disclosure described herein include the seamless selection of cryptographic algorithms based on context-based parameters and standardized levels for energy-efficient operation in wireless communication networks. The selection of cryptographic algorithms from a family of cryptographic algorithms and corresponding variations can be achieved through statistical or machine learning (ML) based clustering methods. Furthermore, the standardized levels can be extended to finer-grained levels to determine the optimal combination of cryptographic algorithms and parameters for energy-efficient operation. Here, in some exemplary embodiments, the realization of cryptographic algorithm selection optimization is described based on an O-RAN architecture implementation. However, within the scope of the disclosure described herein, the methods and systems disclosed are also intended to be more supported through a cloud orchestration layer.

[0063] Figure 3 is a process flow or signaling diagram illustrating a method for enabling O-RAN network-compatible selection of cryptographic algorithms for energy-efficient operation within a Service Management and Orchestrator (SMO) module or framework 100, according to an example of the present disclosure described herein. In particular, in step 1, the O-Cloud platform module 200 transmits the collected O1 and O2 telemetry data to the SMO module or framework 100, which includes an rApp module 120 and a non-real-time RAN intelligent controller platform module 140 ("non-RT RIC"). Here, the rApp module 120 can be any type of RAN automation application or process, such as network evolution rApp, network deployment rApp, network optimization rApp, network remediation rApp, and automation and artificial intelligence (AI) rApp. Furthermore, the non-RT RIC module 140 can be an orchestration and automation function and can be an element of an open RAN architecture that can control and optimize other RAN elements and resources, in particular by using artificial intelligence and machine learning to enhance the control and optimization of such network resources. In addition, the O-Cloud module 200 may be a general cloud infrastructure network-based module. In step 2, the rApp module 120, hosted within the non-RT RIC platform module 140, can analyze the O1 and O2 telemetry data based on the use case and security level (among other factors) to identify a cipher suite or cipher algorithm family. Here, elements O1 and O2 may be interfaces connecting the SMO module or framework 100 to the rApp module 120 and the non-RT RIC module 140 (and any other RAN management elements). In particular, the O2 interface is generally the way in which the SMO module or framework 100 communicates with the O-Cloud platform module 200.

[0064] Referring further to Figure 3, in step 3, cryptographic policy ("cryptographic policy") guidance information is sent to the O-Cloud platform module 200 for the SMO module or framework 100 to select an energy-efficient cryptographic algorithm, such as Falcon or Crystal Dilithium. Here, the cryptographic policy can refer to rule-based conditions determined in rApp. Furthermore, since there is a predetermined set of cryptographic algorithms in the context of PQC, the application of these rule-based conditions will result in one or more groups of cryptographic algorithms. One way to find this mapping to one or more other groups of cryptographic algorithms may be by table lookup. However, in other embodiments, a more granular method by decision tree / machine learning process may also be used. In step 4, the O-Cloud platform module 200 successfully selects a cryptographic policy, such as a cryptographic policy associated with the Falcon cryptographic algorithm, and the selected cryptographic policy is then sent to the SMO module or framework 100, and furthermore, the rApp / non-RT RIC module receives confirmation of the change in the cryptographic policy selected by the O-Cloud platform module 200.

[0065] Referring further to Figure 3, in step 5, the rApp / non-RT RIC module of the SMO module or framework 100 generates final cryptographic policy guidance data for the O-Cloud platform module 200. Next, in step 6, the SMO module or framework 100 sends the final cryptographic policy guidance information for the cryptographic algorithm and parameters applicable to both the suspended and transitioning data to the O-Cloud platform module 200. As an example, such final cryptographic policy guidance information for the Falcon cryptographic algorithm may include, among other things, Q for the number of queries, λ for the target security level, and n for the ring order. Here, it can be assumed that the system has enabled a previous baseline cryptographic policy before the final cryptographic policy is applied in step 6. For example, the 3GPP® standard treats a cryptographic policy with null encryption even if encryption is disabled. Furthermore, methods for optimizing the cipher suite may be performed within the algorithm implemented in the rApp module 120 hosted in the non-RT RIC platform module 140. Energy consumption telemetry information, network usage context, and algorithm security levels collected from the O-Cloud platform can be used as input to generate cryptographic policies enforced on interfaces (O1, O2, A1, etc.) and the cloud platform (persistent data encryption).

[0066] Still referring to step 6 in Figure 3, as previously disclosed, one embodiment of the final cryptographic policy guidance may include the Falcon cryptographic algorithm family of PQC algorithms. For further illustrative purposes, as shown in Table 2, the algorithms can satisfy the high security, high energy, and high network criticality characteristics. Furthermore, three key parameters of this algorithm class are 1) the maximum number of signature queries Q, 2) the target security level λ, and 3) the degree n of the ring Z. For NIST level I, Q=2^64, n=512, and λ=128, and for NIST level V, n=1024, and λ=256. Thus, for illustrative purposes, the final cryptographic policy and parameters for critical infrastructure networks such as smart grid security in CSV format may be expressed as {(Security-High, Energy-High, Critical-High)(Q=2^64,n=1024,λ=256)}.

[0067] Here, in one exemplary embodiment, some of the exemplary cryptographic algorithm suites or families may be represented in exemplary decisions or truth tables, as shown with respect to Table 1. Here, Table 1 shows some partial exemplary possibilities for context-based cryptographic algorithm or suite selection based on standardized levels (low, medium, high) such as those applied to network security level, energy efficiency, and network criticality. However, in total 3 3 It is construed within the scope of this disclosure as described herein that there may be a possibility of =27. For example, if the desired security level is low and energy efficiency requirements are low, but network criticality requirements or importance are moderate, a DualModeMS cipher family or suite may be selected for efficient energy operation within the network.

[0068] [Table 1]

[0069] Here, the selection of a cryptographic algorithm, suite, scheme, or family may be based further on the energy consumption of key generation operations between various PQC algorithms and their security levels (or families of cryptographic algorithms). In addition, when determining the appropriate PQC algorithm, the energy consumption during public key signing may also be taken into consideration, and this can be considered with respect to various PQC algorithms (or families of cryptographic algorithms).

[0070] Since the energy consumption during each operation may vary depending on the software implementation and hardware platform on which the operation is performed, it is further intended within the scope of this disclosure described herein that there may be other appropriate recommendations dynamically generated for different cryptographic operations, such as those not shown in Table 1. In one exemplary embodiment, an alternative decision function for a public key signature is shown below with respect to Table 2.

[0071] [Table 2]

[0072] In addition, contextual information related to applications, networks, and deployments can be captured during system initialization via either an application programming interface (API) or operator input. In one or more exemplary embodiments, network criticality level mappings are shown in Table 3 below, and network security levels are shown in Table 4 below.

[0073] [Table 3]

[0074] [Table 4]

[0075] Figure 5 shows a flowchart of an exemplary embodiment of a context-based cryptographic selection method for energy-efficient operation and a method for determining a cryptographic configuration for a system, such as logic embedded within xApp when determining the cryptographic configuration. Here, in step 502, the method may include initializing system parameters and collecting telemetry information of the O-Cloud module 200 via the O1 and O2 interfaces. Next, in step 504, the method may include receiving an external system context via an application interface (API) or operator input, which may include network criticality levels and applicable security levels. Here, the external system context may refer to information that may be independent of network operation or security levels themselves. One example of this could be a change in the energy source of network operation, which may result from events such as a power grid failure, among other things. When such an event occurs, the network system may change to an alternative or temporary energy source, such as a change to a sustainable / renewable energy source that reduces power consumption. Under such a scenario of reduced network power consumption, despite predetermined rules for selecting cryptographic policies, the least energy-efficient cryptographic algorithm is selected to comply with the reduced power consumption requirements for the network. Next, in step 506, the method may include determining the optimal energy-efficient cryptographic configuration via table lookup / supervised learning or decision tree techniques. Next, in step 508, the method may include the O-Cloud module 200 selecting final cryptographic parameters from cryptographic family guidance received from the rApp module 120 and the SMO module or framework 100. Next, in step 510, the method may include providing the O-Cloud layer module 200 with final policy guidance via the rApp security application or rApp module 120. Furthermore, in step 512, the final cryptographic policy can be applied to the O-Cloud layer module 200.Here, the aforementioned process in Figure 5 can be achieved in the K8S orchestration layer, particularly for the encryption of the remaining data on the cloud platform.

[0076] Table 5 provides an overview of one exemplary embodiment of configuration parameters that may be used with the context-based selection methods and systems described herein. Here, configuration parameters from Kubernetes' "Encrypting Secret Data at Rest" (May 30, 2022), which are currently available but do not comply with post-quantum cryptography requirements, may be considered to be at a "low" security level.

[0077] [Table 5]

[0078] However, AES with keys longer than 256 is now considered quantum secure and can be supported through extensions to cryptographic libraries in the Kubernetes layer. This can be securely exposed through extensions to the kube-apiserver encryption configuration, i.e., through Kubernetes' "Encrypting Secret Data at Rest" (May 30, 2022). Therefore, the security levels to which AES can be mapped for PQC requirements are provided in Table 6 below.

[0079] [Table 6]

[0080] Furthermore, the ProviderConfiguration API field appears in the ResourceConfiguration API field, and the ProviderConfiguration API field can store the provided configuration for cryptographic providers, such as those provided by Kubernetes, as shown in Table 7.

[0081] [Table 7]

[0082] Here, in the example in Table 7, the PostQuantumEncryption API can be extended to support the ProviderConfiguration API field. The PQCConfiguration API field description may include the algorithm and key used to create cryptographic transformers such as AES 128, 192, and 256-bit keys. The PostQuantumEncryption field contains API configuration information for AES cryptographic transformers, as provided in Table 8.

[0083] [Table 8]

[0084] Here, the Key field may contain the name of the provided key for the cryptographic transformer and the secret data, as provided in Table 9.

[0085] [Table 9]

[0086] It should be understood that the specific order or hierarchy of blocks in the processes / flowcharts disclosed herein is an example of exemplary technique. It should be understood that the specific order or hierarchy of blocks in the processes / flowcharts may be rearranged based on design preferences. Furthermore, some blocks may be combined or omitted. The appended method claims present various block elements in an exemplary order, and are not limited to the specific order or hierarchy presented.

[0087] Some embodiments may relate to systems, methods, and / or computer-readable media in integration at any possible level of technical detail. Furthermore, one or more of the components described above may be implemented as instructions stored on a computer-readable medium and executable by at least one processor (and / or may include at least one processor). The computer-readable medium may include computer-readable non-temporary storage medium (or more mediums) having computer-readable program instructions for causing a processor to perform an operation.

[0088] A computer-readable storage medium can be a tangible device capable of holding and storing instructions for use by an instruction execution device. A computer-readable storage medium may be, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. A non-exhaustive list of more specific examples of computer-readable storage media includes: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital multipurpose disks (DVDs), memory sticks, floppy disks, mechanically encoded devices such as punch cards or grooved structures having instructions recorded therein, and any suitable combination thereof. The computer-readable storage media used herein should not be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses passing through optical fiber cables), or electrical signals transmitted through wires.

[0089] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface within each computing / processing device receives computer-readable program instructions from the network and transfers the computer-readable program instructions for storage in a computer-readable storage medium within each computing / processing device.

[0090] The computer-readable program code / instructions for performing an operation may be source code or an object-oriented programming language written in any combination of one or more programming languages, including assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or object code such as Smalltalk, C++, and procedural programming languages ​​such as the "C" programming language or similar languages. The computer-readable program instructions may run entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or wide area network (WAN), or it may be connected to an external computer (for example, via the Internet using an Internet service provider). In some embodiments, for example, an electronic circuit including a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer-readable program instructions by utilizing state information of computer-readable program instructions for personalizing the electronic circuit in order to perform an action or operation.

[0091] These computer-readable program instructions may be provided to the processor of a general-purpose computer, a dedicated computer, or other programmable data processing device to generate a machine, which in turn generates means for instructions executed via the processor of the computer or other programmable data processing device to implement functions / operations specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can instruct computers, programmable data processing devices, and / or other devices to function in a particular way, which in turn includes a product containing instructions that implements modes of functions / operations specified in one or more blocks of a flowchart and / or block diagram.

[0092] Computer-readable program instructions can also be loaded into a computer, other programmable data processing device, or other device to generate a computer implementation process by causing the instructions executed on the computer, other programmable device, or other device to perform a series of operational steps on the computer, other programmable device, or other device so that they implement a function / operation specified in one or more blocks of a flowchart and / or block diagram.

[0093] The flowcharts and block diagrams in the figures illustrate the architecture, functions, and operation of possible implementations of systems, methods, and computer-readable media according to various embodiments. In this regard, each block in a flowchart or block diagram may represent a module, segment, or part of an instruction containing one or more executable instructions for implementing a specified logical function(s). Methods, computer systems, and computer-readable media may include additional blocks, fewer blocks, different blocks, or blocks arranged differently from those shown in the figures. In some alternative implementations, the functions described in the blocks may be performed in a different order than shown in the figures. For example, two blocks shown consecutively may actually be executed simultaneously or substantially simultaneously, or blocks may sometimes be executed in reverse order depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in a block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs a specified function or operation, or a combination of dedicated hardware and computer instructions.

[0094] It will be apparent that the systems and / or methods described herein may be implemented in different forms of hardware, firmware, or combinations of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods is not limited to any particular implementation. Therefore, the operation and behavior of the systems and / or methods are described herein without reference to specific software code, and it is understood that software and hardware may be designed to implement the systems and / or methods based on the descriptions herein.

Claims

1. A method for selecting a cryptographic algorithm within a network, wherein the method is The Service Management and Orchestrator (SMO) framework in an Open Radio Access Network (O-RAN) receives network data from one or more network interfaces or network elements, The aforementioned SMO analyzes the network data in order to identify an encryption algorithm from among multiple encryption algorithms, The SMO identifies the cryptographic algorithm from the plurality of cryptographic algorithms based on the energy consumption during signing of the public key signature and at least one of the following parameters: network security level, network criticality, or energy efficiency. Methods that include...

2. The method according to claim 1, wherein analyzing the network data to identify the cryptographic algorithm further comprises receiving a plurality of identifiers associated with the network data, each of which is further associated with a degree of importance related to the network security level parameter.

3. The method according to claim 1, wherein analyzing the network data to identify the cryptographic algorithm further comprises receiving a plurality of identifiers associated with the network data, each of which is further associated with a degree of importance related to the network criticality parameter.

4. The method according to claim 1, wherein analyzing the network data to identify the cryptographic algorithm further comprises receiving a plurality of identifiers associated with the network data, each of which is further associated with a degree of importance related to the energy efficiency parameter.

5. The method according to claim 1, wherein the SMO framework includes an orchestrator module that communicates with a network infrastructure module.

6. The method according to claim 5, wherein the analysis of the network data to identify the cryptographic algorithm from the plurality of cryptographic algorithms is performed via the orchestrator module.

7. The method according to claim 6, further comprising transmitting the identified cryptographic algorithm from the orchestrator module to the network infrastructure module.

8. The method according to claim 7, further comprising receiving a selection of conditions relating to the identified cryptographic algorithm from the network infrastructure module via the orchestrator module.

9. The method according to claim 8, further comprising generating a cryptographic policy for the network relating to the identified cryptographic algorithm via the orchestrator module.

10. The method according to claim 9, further comprising transmitting the cryptographic policy for the network relating to the identified cryptographic algorithm to the network infrastructure module via the orchestrator module.

11. A device for selecting an encryption algorithm within a network, Memory storage that stores computer executable instructions, The device comprises a processor that is communicatively coupled to the memory storage, the processor executes the computer executable instructions, and the device The Service Management and Orchestrator (SMO) framework in an Open Radio Access Network (O-RAN) receives network data from one or more network interfaces or network elements, The aforementioned SMO analyzes the network data in order to identify an encryption algorithm from among multiple encryption algorithms, The SMO identifies the cryptographic algorithm from the plurality of cryptographic algorithms based on the energy consumption during signing of the public key signature and at least one of the following parameters: network security level, network criticality, or energy efficiency. A device configured to perform a certain action.

12. When the aforementioned computer executable instruction is executed by the processor, the device further... The apparatus according to claim 11, wherein a plurality of identifiers associated with the network data are received, and each of the plurality of identifiers is further associated with a degree of importance related to the network security level parameter.

13. When the aforementioned computer executable instruction is executed by the processor, the device further... The apparatus according to claim 11, wherein a plurality of identifiers associated with the network data are received, and each of the plurality of identifiers is further associated with a degree of importance related to the network criticality parameter.

14. When the aforementioned computer executable instruction is executed by the processor, the device further... The apparatus according to claim 11, wherein a plurality of identifiers associated with the network data are received, and each of the plurality of identifiers is further associated with an importance related to the energy efficiency parameter.

15. The apparatus according to claim 11, wherein the SMO framework includes an orchestrator module that communicates with a network infrastructure module.

16. The apparatus according to claim 15, wherein the analysis of the network data to identify the cryptographic algorithm from the plurality of cryptographic algorithms is performed via the orchestrator module.

17. When the aforementioned computer executable instruction is executed by the processor, the device further... The apparatus according to claim 16, wherein the identified cryptographic algorithm is transmitted from the orchestrator module to the network infrastructure module.

18. When the aforementioned computer executable instruction is executed by the processor, the device further... The apparatus according to claim 17, wherein the orchestrator module receives the selection of conditions relating to the identified cryptographic algorithm from the network infrastructure module.

19. When the aforementioned computer executable instruction is executed by the processor, it further causes the device to: The apparatus according to claim 18, wherein the orchestrator module generates a cryptographic policy for the network relating to the identified cryptographic algorithm.

20. A non-temporary computer-readable medium containing computer-executable instructions for selecting an encryption algorithm in a network by a device, wherein, when the computer-executable instructions are executed by at least one processor of the device, the device... The Service Management and Orchestrator (SMO) framework in an Open Radio Access Network (O-RAN) receives network data from one or more network interfaces or network elements, The aforementioned SMO analyzes the network data in order to identify an encryption algorithm from among multiple encryption algorithms, The SMO identifies the cryptographic algorithm from the plurality of cryptographic algorithms based on the energy consumption during signing of the public key signature and at least one of the following parameters: network security level, network criticality, or energy efficiency. A non-temporary computer-readable medium that enables the operation of [the process].

Citation Information

Patent Citations

  • Apparatus, method and program for encryption management

    JP2009089044A

  • Encryption management apparatus, decryption management apparatus, and program

    JP2009100462A

  • End-to-end authentication at the service layer using public key mechanism

    JP2018518854A