Method and device for assisting hybrid quantum bit error rate check-based quantum public key infrastructure in quantum communication system
A hybrid quantum bit error rate check-based quantum public key infrastructure addresses the vulnerability of asymmetric key cryptography to quantum algorithms by using the no-cloning theorem and quantum coherence time to ensure secure communication.
Patent Information
- Application Number
- PCT/KR2024/002394
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-23
- Publication Date
- 2025-08-28
AI Technical Summary
The collapse of asymmetric key cryptography systems due to quantum algorithms poses a serious threat to secure communication systems, and transitioning to new security systems entails a significant technical burden, while existing solutions like Harvest-Now-Decrypt-Later attacks remain a vulnerability.
A hybrid quantum bit error rate check-based quantum public key infrastructure is implemented, utilizing the no-cloning theorem and quantum coherence time to provide physical security by periodically updating public keys and verifying qubit validity through hybrid QBER checks.
This approach adaptively prevents trapdoor leakage from quantum algorithms and enhances security by ensuring the validity of public keys, mitigating real-time and delayed plaintext attacks.
Smart Images

Figure KR2024002394_28082025_PF_FP_ABST
Abstract
Description
Method and device for supporting a quantum public key infrastructure based on hybrid quantum bit error rate verification in a quantum communication system
[0001] The present disclosure relates to a device and method for supporting a hybrid quantum bit error rate check-based quantum public key infrastructure in a quantum communication system. The present disclosure proposes a method for achieving physical information security based on the no-cloning theorem and quantum coherence time.
[0002]
[0003] The collapse of asymmetric key cryptography systems due to quantum algorithms poses a serious threat to secure communication systems based on asymmetric key cryptography. To prevent this security threat, Post-Quantum Cryptography (PQC) technology is emerging. However, all asymmetric key systems based on computational complexity inevitably face the risk of being threatened by new quantum algorithms. Furthermore, transitioning to a new security system can entail a significant technical burden, as the new security technology must be applied across all devices.
[0004] Therefore, a method is needed to address the threat of quantum algorithms while maintaining an asymmetric key system. To achieve this, trapdoor leakage caused by quantum algorithms can be adaptively prevented by periodically updating the public key. This prevents real-time leakage even if a plaintext attack is conducted using quantum algorithms. However, even if real-time leakage does not occur, an attacker can still conduct a plaintext attack later using a Harvest-Now-Decrypt-Later (HNDL) attack. Consequently, limiting the validity period of a public key alone cannot achieve fundamental information security.
[0005]
[0006] To solve the above-described problems, the present disclosure provides a device and method for supporting a hybrid quantum bit error rate check based quantum public key infrastructure in a quantum communication system.
[0007] The present disclosure provides a device and method for supporting a hybrid quantum bit error rate check based quantum public key infrastructure that provides physical security based on the no-cloning theorem and quantum coherence time in a quantum communication system.
[0008] The technical problems to be achieved in the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which the present disclosure belongs from the description below.
[0009]
[0010] According to various embodiments of the present disclosure, a method performed by a first node in a communication system comprises the steps of: transmitting at least one synchronization signal to a second node; transmitting control information to the second node; transmitting a quantum public key (QPK) based on a private key to the second node; receiving a hybrid quantum bit error rate check (QBER) check packet related to a result of a hybrid QBER check for first qubits among a plurality of qubits constituting the QPK from the second node; decrypting the hybrid QBER check packet with a classical private key to generate basis matching information of the QPK; transmitting a hybrid QBER check response packet based on the basis matching information to the second node; receiving a verification result of the validity of the QPK from the second node based on the basis matching information; A method is provided, including the step of receiving an encrypted message from the second node based on second qubits among the plurality of qubits that are not used in the hybrid QBER check based on the validity of the QPK.
[0011] According to various embodiments of the present disclosure, a method of operating a second node in a communication system comprises: receiving at least one synchronization signal from a first node; receiving control information from the first node; receiving a quantum public key (QPK) based on a private key from the first node; transmitting a hybrid quantum bit error rate check packet related to a result of a hybrid QBER check for first qubits among a plurality of qubits constituting the QPK to the first node; receiving a hybrid QBER check response packet based on basis matching information of the QPK from the first node; verifying validity of the QPK; transmitting a verification result of the validity of the QPK to the first node; A method is provided, comprising: transmitting an encrypted message to the first node based on second qubits not used for the hybrid QBER test among the plurality of qubits based on the validity of the QPK, wherein the basis matching information is generated by classical private key-based decryption for the hybrid QBER test packet.
[0012] According to various embodiments of the present disclosure, in a communication system, a first node is provided, comprising: a transceiver; at least one processor; and at least one memory operably connectable to the at least one processor and storing instructions that, when executed by the at least one processor, perform operations, wherein the operations include all steps of a method of operating the first node according to various embodiments of the present disclosure.
[0013] According to various embodiments of the present disclosure, in a communication system, a second node is provided, comprising: a transceiver; at least one processor; and at least one memory operably connectable to the at least one processor and storing instructions that, when executed by the at least one processor, perform operations, wherein the operations include all steps of a method of operating the second node according to various embodiments of the present disclosure.
[0014] According to various embodiments of the present disclosure, a control device for controlling a first node in a communication system is provided, comprising: at least one processor; and at least one memory operably connected to the at least one processor, wherein the at least one memory stores instructions for performing operations based on being executed by the at least one processor, wherein the operations include all steps of an operating method of the first node according to various embodiments of the present disclosure.
[0015] According to various embodiments of the present disclosure, a control device for controlling a second node in a communication system is provided, comprising: at least one processor; and at least one memory operably connected to the at least one processor, wherein the at least one memory stores instructions for performing operations based on being executed by the at least one processor, wherein the operations include all steps of an operating method of the second node according to various embodiments of the present disclosure.
[0016] According to various embodiments of the present disclosure, one or more non-transitory computer-readable media storing one or more instructions, wherein the one or more instructions, based on being executed by one or more processors, perform operations, the operations comprising all steps of a method of operating a first node according to various embodiments of the present disclosure, are provided.
[0017] According to various embodiments of the present disclosure, there is provided one or more non-transitory computer-readable media storing one or more instructions, wherein the one or more instructions, when executed by one or more processors, perform operations, the operations comprising all steps of a method of operating a second node according to various embodiments of the present disclosure.
[0018]
[0019] In order to solve the above-described problem, the present disclosure can provide a device and method for supporting a hybrid quantum bit error rate check based quantum public key infrastructure in a quantum communication system.
[0020] The present disclosure may provide a device and method for supporting a hybrid quantum bit error rate check based quantum public key infrastructure that provides physical security based on the no-cloning theorem and quantum coherence time in a quantum communication system.
[0021]
[0022] The accompanying drawings are intended to aid in understanding the present disclosure and, together with detailed descriptions, may provide embodiments of the present disclosure. However, the technical features of the present disclosure are not limited to specific drawings, and the features disclosed in each drawing may be combined with each other to form new embodiments. Reference numerals in each drawing may indicate structural elements.
[0023] Figure 1 is a diagram illustrating an example of physical channels and general signal transmission used in a 3GPP system.
[0024] Figure 2 is a diagram illustrating the system structure of a New Generation Radio Access Network (NG-RAN).
[0025] Figure 3 is a diagram illustrating the functional division between NG-RAN and 5GC.
[0026] Figure 4 is a diagram illustrating an example of a 5G usage scenario.
[0027] Figure 5 is a diagram illustrating an example of a communication structure that can be provided in a 6G system.
[0028] Figure 6 is a schematic diagram illustrating an example of a perceptron structure.
[0029] Figure 7 is a schematic diagram illustrating an example of a multilayer perceptron structure.
[0030] Figure 8 is a schematic diagram illustrating an example of a deep neural network.
[0031] Figure 9 is a schematic diagram illustrating an example of a convolutional neural network.
[0032] Figure 10 is a schematic diagram illustrating an example of a filter operation in a convolutional neural network.
[0033] Figure 11 is a schematic diagram illustrating an example of a neural network structure in which a recurrent loop exists.
[0034] Figure 12 is a diagram schematically illustrating an example of the operating structure of a recurrent neural network.
[0035] Figure 13 is a diagram illustrating an example of the electromagnetic spectrum.
[0036] Figure 14 is a diagram illustrating an example of a THz communication application.
[0037] Fig. 15 is a diagram illustrating an example of an electronic component-based THz wireless communication transmitter and receiver.
[0038] FIG. 16 is a diagram illustrating an example of a method for generating a THz signal based on an optical element.
[0039] Fig. 17 is a diagram illustrating an example of an optical element-based THz wireless communication transceiver.
[0040] Fig. 18 is a diagram illustrating the structure of a photon source-based transmitter.
[0041] Figure 19 is a drawing showing the structure of an optical modulator.
[0042] FIG. 20 is a diagram illustrating an example of a man-in-the-middle attack in a system applicable to the present disclosure.
[0043] FIG. 21 is a diagram illustrating an example of a MAC-based authentication technique in a system applicable to the present disclosure.
[0044] FIG. 22 is a diagram illustrating an example of Wegman & Carter Authentication (WCA) in a system applicable to the present disclosure.
[0045] FIG. 23 is a diagram illustrating an example of collision probability in Wegman & Carter Authentication (WCA) in a system applicable to the present disclosure.
[0046] FIG. 24 is a diagram illustrating an example of a concept of cloning for a qubit in a system applicable to the present disclosure.
[0047] Figure 25 is a diagram illustrating an example of security keys in a 5G network system.
[0048] FIG. 26 is a diagram illustrating an example of an authentication procedure initiation and authentication method selection process in a system applicable to the present disclosure.
[0049] FIG. 27 is a diagram illustrating an example of an authentication procedure initiation and authentication method selection process in a system applicable to the present disclosure.
[0050] FIG. 28 is a diagram illustrating an example of a SUCI structure in a system applicable to the present disclosure.
[0051] FIG. 29 is a diagram illustrating an example of a system output for an elliptic curve integrated encryption scheme profile A applicable to the present disclosure.
[0052] FIG. 30 is a diagram illustrating an example of a system output for an elliptic curve integrated encryption scheme profile B applicable to the present disclosure.
[0053] FIG. 31a is a diagram illustrating an example of modulation by Qubit Rotation in a system applicable to the present disclosure.
[0054] FIG. 31b is a diagram illustrating an example of a Pauli operator in a system applicable to the present disclosure.
[0055] FIG. 32 is a diagram illustrating an example of a Hybrid QBER Check Packet structure in a system applicable to the present disclosure.
[0056] FIG. 33 is a diagram illustrating an example of information transmission for Hybrid QBER Check in a system applicable to the present disclosure.
[0057] FIG. 34 is a diagram illustrating an example of modulation by Qubit Rotation in a system applicable to the present disclosure.
[0058] FIG. 35 is a diagram illustrating an example of a QPKE Packet structure in a system applicable to the present disclosure.
[0059] FIG. 36 is a diagram illustrating an example of a QPKE Control Packet structure in a system applicable to the present disclosure.
[0060] FIG. 37 is a diagram illustrating an example of a QPKE Packet structure in a system applicable to the present disclosure.
[0061] FIG. 38 is a diagram illustrating an example of the operation of quantum channel and classical channel signals performed with Single Qubit based QPK in Hybrid QBER Check based Quantum Public Key Infrastructure (QPKI) in a system applicable to the present disclosure.
[0062] FIG. 39 is a flowchart illustrating the entire process of Hybrid QBER Check based Quantum Public Key Infrastructure (QPKI) in a system applicable to the present disclosure.
[0063] FIG. 40 is a diagram illustrating an example of the operation process of the first node in a system applicable to the present disclosure.
[0064] FIG. 41 is a diagram illustrating an example of the operation process of a second node in a system applicable to the present disclosure.
[0065] FIG. 42 illustrates a communication system (1) applicable to various embodiments of the present disclosure.
[0066] FIG. 43 illustrates a wireless device that can be applied to various embodiments of the present disclosure.
[0067] FIG. 44 illustrates another example of a wireless device that can be applied to various embodiments of the present disclosure.
[0068] Figure 45 illustrates a signal processing circuit for a transmission signal.
[0069] FIG. 46 illustrates another example of a wireless device applicable to various embodiments of the present disclosure.
[0070] FIG. 47 illustrates a mobile device applicable to various embodiments of the present disclosure.
[0071] FIG. 48 illustrates a vehicle or autonomous vehicle applicable to various embodiments of the present disclosure.
[0072] FIG. 49 illustrates a vehicle applicable to various embodiments of the present disclosure.
[0073] FIG. 50 illustrates an XR device applicable to various embodiments of the present disclosure.
[0074] FIG. 51 illustrates a robot applicable to various embodiments of the present disclosure.
[0075] FIG. 52 illustrates an AI device applicable to various embodiments of the present disclosure.
[0076]
[0077] In various embodiments of the present disclosure, “A or B” may mean “only A,” “only B,” or “both A and B.” In other words, in various embodiments of the present disclosure, “A or B” may be interpreted as “A and / or B.” For example, in various embodiments of the present disclosure, “A, B or C” may mean “only A,” “only B,” “only C,” or “any combination of A, B and C.”
[0078] In various embodiments of the present disclosure, a slash ( / ) or a comma may mean "and / or." For example, "A / B" may mean "A and / or B." Accordingly, "A / B" may mean "only A," "only B," or "both A and B." For example, "A, B, C" may mean "A, B, or C."
[0079] In various embodiments of the present disclosure, “at least one of A and B” may mean “only A,” “only B,” or “both A and B.” Furthermore, in various embodiments of the present disclosure, the expressions “at least one of A or B” or “at least one of A and / or B” may be interpreted as equivalent to “at least one of A and B.”
[0080] Additionally, in various embodiments of the present disclosure, “at least one of A, B and C” can mean “only A,” “only B,” “only C,” or “any combination of A, B and C.” Additionally, “at least one of A, B or C” or “at least one of A, B and / or C” can mean “at least one of A, B and C.”
[0081] Additionally, parentheses used in various embodiments of the present disclosure may mean "for example." Specifically, when indicated as "control information (PDCCH)", "PDCCH" may be proposed as an example of "control information." In other words, "control information" in various embodiments of the present disclosure is not limited to "PDCCH", and "PDDCH" may be proposed as an example of "control information." Furthermore, even when indicated as "control information (i.e., PDCCH)", "PDCCH" may be proposed as an example of "control information."
[0082] Technical features individually described in a single drawing in various embodiments of the present disclosure may be implemented individually or simultaneously.
[0083]
[0084] The following technologies can be used in various wireless access systems, such as CDMA, FDMA, TDMA, OFDMA, and SC-FDMA. CDMA can be implemented using wireless technologies such as UTRA (Universal Terrestrial Radio Access) or CDMA2000. TDMA can be implemented using wireless technologies such as GSM (Global System for Mobile communications) / GPRS (General Packet Radio Service) / EDGE (Enhanced Data Rates for GSM Evolution). OFDMA can be implemented using wireless technologies such as IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802-20, and E-UTRA (Evolved UTRA). UTRA is a part of UMTS (Universal Mobile Telecommunications System). 3GPP (3rd Generation Partnership Project) LTE (Long Term Evolution) is a part of E-UMTS (Evolved UMTS) that uses E-UTRA, and LTE-A (Advanced) / LTE-A pro is an evolved version of 3GPP LTE. 3GPP NR (New Radio or New Radio Access Technology) is an evolved version of 3GPP LTE / LTE-A / LTE-A pro. 3GPP 6G may be an evolved version of 3GPP NR.
[0085]
[0086] For clarity, the description is based on 3GPP communication systems (e.g., LTE, NR, etc.), but the technical spirit of the present disclosure is not limited thereto. LTE refers to technology after 3GPP TS 36.xxx Release 8. Specifically, LTE technology after 3GPP TS 36.xxx Release 10 is referred to as LTE-A, and LTE technology after 3GPP TS 36.xxx Release 13 is referred to as LTE-A pro. 3GPP NR refers to technology after TS 38.xxx Release 15. 3GPP 6G may refer to technology after TS Release 17 and / or Release 18. “xxx” refers to a standard document detail number. LTE / NR / 6G may be collectively referred to as a 3GPP system. For background technology, terms, abbreviations, etc. used in the description of the present disclosure, reference may be made to matters described in standard documents published prior to the present disclosure. For example, reference may be made to the following documents.
[0087]
[0088] 3GPP LTE
[0089] - 36.211: Physical channels and modulation
[0090] - 36.212: Multiplexing and channel coding
[0091] - 36.213: Physical layer procedures
[0092] - 36.300: Overall description
[0093] - 36.331: Radio Resource Control (RRC)
[0094] 3GPP NR
[0095] - 38.211: Physical channels and modulation
[0096] - 38.212: Multiplexing and channel coding
[0097] - 38.213: Physical layer procedures for control
[0098] - 38.214: Physical layer procedures for data
[0099] - 38.300: NR and NG-RAN Overall Description
[0100] - 38.331: Radio Resource Control (RRC) protocol specification
[0101]
[0102] Physical Channel and Frame Structure
[0103] Physical channels and general signal transmission
[0104] Figure 1 is a diagram illustrating an example of physical channels and general signal transmission used in a 3GPP system.
[0105] In a wireless communication system, a terminal receives information from a base station via the downlink (DL) and transmits it to the base station via the uplink (UL). The information transmitted and received between the base station and the terminal includes data and various control information, and various physical channels exist depending on the type and purpose of the information being transmitted and received.
[0106]
[0107] When a terminal is powered on or enters a new cell, it performs an initial cell search operation, such as synchronizing with the base station (S11). To this end, the terminal receives a Primary Synchronization Signal (PSS) and a Secondary Synchronization Signal (SSS) from the base station to synchronize with the base station and obtain information such as a cell ID. Afterwards, the terminal can receive a Physical Broadcast Channel (PBCH) from the base station to obtain broadcast information within the cell. Meanwhile, the terminal can receive a Downlink Reference Signal (DL RS) during the initial cell search phase to check the downlink channel status.
[0108]
[0109] A terminal that has completed initial cell search can obtain more specific system information by receiving a physical downlink control channel (PDCCH) and a physical downlink shared channel (PDSCH) based on information contained in the PDCCH (S12).
[0110]
[0111] Meanwhile, when accessing a base station for the first time or when there are no radio resources for signal transmission, the terminal may perform a random access procedure (RACH) for the base station (S13 to S16). To this end, the terminal may transmit a specific sequence as a preamble via a physical random access channel (PRACH) (S13 and S15) and receive a response message (RAR (Random Access Response) message) to the preamble via a PDCCH and a corresponding PDSCH. In the case of a contention-based RACH, a contention resolution procedure may additionally be performed (S16).
[0112]
[0113] The terminal that has performed the procedure described above can then perform PDCCH / PDSCH reception (S17) and physical uplink shared channel (PUSCH) / physical uplink control channel (PUCCH) transmission (S18) as general uplink / downlink signal transmission procedures. In particular, the terminal can receive downlink control information (DCI) through the PDCCH. Here, the DCI includes control information such as resource allocation information for the terminal, and different formats can be applied depending on the purpose of use.
[0114]
[0115] Meanwhile, the control information that the terminal transmits to the base station via the uplink or that the terminal receives from the base station may include downlink / uplink ACK / NACK signals, CQI (Channel Quality Indicator), PMI (Precoding Matrix Index), RI (Rank Indicator), etc. The terminal may transmit the above-described control information such as CQI / PMI / RI via PUSCH and / or PUCCH.
[0116]
[0117] Structure of uplink and downlink channels
[0118] Downlink channel structure
[0119] The base station transmits a related signal to the terminal through a downlink channel described below, and the terminal receives the related signal from the base station through a downlink channel described below.
[0120]
[0121] (1) Physical Downlink Shared Channel (PDSCH)
[0122] PDSCH carries downlink data (e.g., DL-shared channel transport block, DL-SCH TB) and modulation methods such as Quadrature Phase Shift Keying (QPSK), 16 Quadrature Amplitude Modulation (QAM), 64 QAM, and 256 QAM are applied. The TB is encoded to generate a codeword. PDSCH can carry multiple codewords. Scrambling and modulation mapping are performed for each codeword, and the modulation symbols generated from each codeword are mapped to one or more layers (Layer mapping). Each layer is mapped to resources along with a Demodulation Reference Signal (DMRS), generated as an OFDM symbol signal, and transmitted through the corresponding antenna port.
[0123]
[0124] (2) Physical downlink control channel (PDCCH)
[0125] The PDCCH carries downlink control information (DCI) and employs modulation methods such as QPSK. A PDCCH consists of 1, 2, 4, 8, or 16 Control Channel Elements (CCEs), depending on the Aggregation Level (AL). Each CCE is comprised of six Resource Element Groups (REGs). Each REG is defined by one OFDM symbol and one (P)RB.
[0126] The UE acquires DCI transmitted via the PDCCH by performing decoding (also known as blind decoding) on a set of PDCCH candidates. The set of PDCCH candidates decoded by the UE is defined as a PDCCH search space set. The search space set may be a common search space or a UE-specific search space. The UE can acquire DCI by monitoring PDCCH candidates within one or more search space sets established by the MIB or higher layer signaling.
[0127]
[0128] Uplink channel structure
[0129] The terminal transmits a related signal to the base station through the uplink channel described below, and the base station receives the related signal from the terminal through the uplink channel described below.
[0130] (1) Physical Uplink Shared Channel (PUSCH)
[0131] PUSCH carries uplink data (e.g., UL-shared channel transport block, UL-SCH TB) and / or uplink control information (UCI), and is transmitted based on a CP-OFDM (Cyclic Prefix - Orthogonal Frequency Division Multiplexing) waveform, a DFT-s-OFDM (Discrete Fourier Transform - spread - Orthogonal Frequency Division Multiplexing) waveform, etc. When the PUSCH is transmitted based on a DFT-s-OFDM waveform, the UE transmits the PUSCH by applying transform precoding. For example, when transform precoding is disabled (e.g., transform precoding is disabled), the UE transmits the PUSCH based on the CP-OFDM waveform, and when transform precoding is enabled (e.g., transform precoding is enabled), the UE can transmit the PUSCH based on the CP-OFDM waveform or the DFT-s-OFDM waveform. PUSCH transmissions can be dynamically scheduled by UL grants in DCI, or semi-statically scheduled (configured grant) based on higher layer (e.g., RRC) signaling (and / or Layer 1 (L1) signaling (e.g., PDCCH)). PUSCH transmissions can be performed in a codebook-based or non-codebook-based manner.
[0132] (2) Physical Uplink Control Channel (PUCCH)
[0133] PUCCH carries uplink control information, HARQ-ACK and / or scheduling request (SR), and can be divided into multiple PUCCHs depending on the PUCCH transmission length.
[0134]
[0135] Below, we describe new radio access technology (new RAT, NR).
[0136] As more and more communication devices demand greater communication capacity, the need for improved mobile broadband communication compared to existing radio access technology (RAT) is emerging. Furthermore, massive Machine Type Communications (MTC), which connects numerous devices and objects to provide various services anytime, anywhere, is also a key issue to be considered in next-generation communication. Furthermore, communication system design that considers reliability and latency-sensitive services / terminals is being discussed. The introduction of next-generation radio access technologies that take into account enhanced mobile broadband communication, massive MTC, and URLLC (Ultra-Reliable and Low Latency Communication) is being discussed, and in various embodiments of the present disclosure, these technologies are conveniently referred to as new RAT or NR.
[0137]
[0138] Figure 2 is a diagram illustrating the system structure of a New Generation Radio Access Network (NG-RAN).
[0139] Referring to FIG. 2, the NG-RAN may include a gNB and / or an eNB that provides user plane and control plane protocol termination to the UE. FIG. 1 illustrates a case where only a gNB is included. The gNB and eNB are connected to each other via an Xn interface. The gNB and eNB are connected to the 5th generation core network (5G Core Network: 5GC) via the NG interface. More specifically, the gNB is connected to the access and mobility management function (AMF) via the NG-C interface, and the gNB is connected to the user plane function (UPF) via the NG-U interface.
[0140]
[0141] Figure 3 is a diagram illustrating the functional division between NG-RAN and 5GC.
[0142] Referring to FIG. 3, the gNB can provide functions such as inter-cell radio resource management (Inter Cell RRM), radio bearer management (RB control), connection mobility control (Connection Mobility Control), radio admission control (Radio Admission Control), measurement configuration and provision, and dynamic resource allocation. The AMF can provide functions such as NAS security and idle state mobility processing. The UPF can provide functions such as mobility anchoring and PDU processing. The SMF (Session Management Function) can provide functions such as terminal IP address allocation and PDU session control.
[0143]
[0144] Figure 4 is a diagram illustrating an example of a 5G usage scenario.
[0145] The 5G usage scenario illustrated in FIG. 4 is merely exemplary, and the technical features of various embodiments of the present disclosure can also be applied to other 5G usage scenarios not illustrated in FIG. 4.
[0146] Referring to Figure 4, the three key requirement areas for 5G include (1) enhanced mobile broadband (eMBB), (2) massive machine type communication (mMTC), and (3) ultra-reliable and low latency communications (URLLC). Some use cases may require optimization across multiple areas, while others may focus on just one key performance indicator (KPI). 5G supports these diverse use cases in a flexible and reliable manner.
[0147] eMBB focuses on improving data speeds, latency, user density, and overall capacity and coverage of mobile broadband connections. It targets throughputs of around 10 Gbps. eMBB significantly exceeds basic mobile internet access, enabling rich interactive experiences, media and entertainment applications in the cloud, and augmented reality. Data is a key driver of 5G, and for the first time, dedicated voice services may not be available in the 5G era. In 5G, voice is expected to be handled as an application, simply using the data connection provided by the communication system. The increased traffic volume is primarily due to the increasing content size and the growing number of applications that require high data rates. Streaming services (audio and video), interactive video, and mobile internet connectivity will become more prevalent as more devices connect to the internet. Many of these applications require always-on connectivity to push real-time information and notifications to users. Cloud storage and applications are rapidly growing on mobile communication platforms, applicable to both work and entertainment. Cloud storage is a particular use case driving the growth of uplink data rates. 5G is also used for remote work in the cloud, requiring significantly lower end-to-end latency to maintain a superior user experience when tactile interfaces are used. In entertainment, for example, cloud gaming and video streaming are other key factors driving the demand for mobile broadband. Entertainment is essential on smartphones and tablets, regardless of location, including in highly mobile environments like trains, cars, and airplanes. Another use case is augmented reality and information retrieval for entertainment, where augmented reality requires extremely low latency and instantaneous data volumes.
[0148] mMTC is designed to enable communication between a large number of low-cost, battery-powered devices, supporting applications such as smart metering, logistics, field, and body sensors. mMTC targets a battery life of approximately 10 years and / or a population of approximately 1 million devices per square kilometer. mMTC enables seamless connectivity of embedded sensors across all sectors and is one of the most anticipated 5G use cases. The number of IoT devices is projected to reach 20.4 billion by 2020. Industrial IoT is one area where 5G will play a key role, enabling smart cities, asset tracking, smart utilities, agriculture, and security infrastructure.
[0149] URLLC is ideal for vehicle communications, industrial control, factory automation, remote surgery, smart grids, and public safety applications by enabling devices and machines to communicate with high reliability, very low latency, and high availability. URLLC targets latency on the order of 1 ms. URLLC encompasses new services that will transform industries through ultra-reliable, low-latency links, such as remote control of critical infrastructure and autonomous vehicles. This level of reliability and latency is essential for smart grid control, industrial automation, robotics, and drone control and coordination.
[0150] Next, we will look more specifically at a number of usage examples included within the triangle in Fig. 4.
[0151] 5G can complement fiber-to-the-home (FTTH) and cable-based broadband (or DOCSIS) by delivering streams rated at hundreds of megabits per second to gigabits per second. These high speeds may be required to deliver TV at resolutions beyond 4K (6K, 8K, and beyond), as well as virtual reality (VR) and augmented reality (AR). VR and AR applications include near-immersive sports events. Certain applications may require specialized network configurations. For example, for VR gaming, a gaming company may need to integrate its core servers with the network operator's edge network servers to minimize latency.
[0152] Automotive is expected to be a significant new driver for 5G, with numerous use cases for in-vehicle mobile communications. For example, passenger entertainment demands both high capacity and high mobile broadband, as future users will consistently expect high-quality connectivity regardless of their location and speed. Another automotive application is augmented reality dashboards. An AR dashboard allows drivers to identify objects in the dark on top of what they see through the windshield. The AR dashboard overlays information to inform the driver about the distance and movement of objects. In the future, wireless modules will enable vehicle-to-vehicle communication, information exchange between vehicles and supporting infrastructure, and information exchange between vehicles and other connected devices (e.g., devices accompanying pedestrians). Safety systems can guide drivers to safer driving behaviors, reducing the risk of accidents. The next step will be remotely controlled or autonomous vehicles, which require highly reliable and fast communication between different autonomous vehicles and / or between vehicles and infrastructure. In the future, autonomous vehicles will perform all driving tasks, leaving drivers to focus solely on traffic anomalies that the vehicle itself cannot detect. The technological requirements for autonomous vehicles will require ultra-low latency and ultra-high-speed reliability, increasing traffic safety to levels unattainable by humans.
[0153] Smart cities and smart homes, often referred to as smart societies, will be embedded with dense wireless sensor networks. A distributed network of intelligent sensors will identify conditions for cost- and energy-efficient maintenance of cities or homes. Similar setups can be implemented for individual homes. Temperature sensors, window and heating controllers, burglar alarms, and appliances will all be wirelessly connected. Many of these sensors typically require low data rates, low power, and low cost. However, for example, real-time HD video may be required from certain types of devices for surveillance purposes.
[0154] The consumption and distribution of energy, including heat and gas, are becoming increasingly decentralized, requiring automated control of distributed sensor networks. Smart grids interconnect these sensors using digital information and communication technologies to collect and act on information. This information can include the behavior of suppliers and consumers, enabling smart grids to improve efficiency, reliability, economic efficiency, sustainable production, and the automated distribution of fuels like electricity. Smart grids can also be viewed as another low-latency sensor network.
[0155] The health sector has numerous applications that can benefit from mobile communications. Telecommunications systems can support telemedicine, which provides clinical care in remote locations. This can help reduce distance barriers and improve access to health services that are otherwise unavailable in remote rural areas. It can also be used to save lives in critical care and emergency situations. Mobile-based wireless sensor networks can provide remote monitoring and sensors for parameters such as heart rate and blood pressure.
[0156] Wireless and mobile communications are becoming increasingly important in industrial applications. Wiring is expensive to install and maintain. Therefore, the potential to replace cables with reconfigurable wireless links presents an attractive opportunity for many industries. However, achieving this requires wireless connections to operate with similar latency, reliability, and capacity to cables, while simplifying their management. Low latency and extremely low error rates are new requirements for 5G connectivity.
[0157] Logistics and freight tracking are important use cases for mobile communications, enabling the tracking of inventory and packages anywhere using location-based information systems. Logistics and freight tracking typically require low data rates but may require wide-range and reliable location information.
[0158] Below, examples of next-generation communications (e.g., 6G) that can be applied to various embodiments of the present disclosure will be described.
[0159]
[0160] 6G system in general
[0161] The 6G (wireless communication) system aims to achieve (i) very high data rates per device, (ii) a very large number of connected devices, (iii) global connectivity, (iv) very low latency, (v) low energy consumption for battery-free IoT devices, (vi) ultra-reliable connectivity, and (vii) connected intelligence with machine learning capabilities. The vision of the 6G system can be divided into four aspects: intelligent connectivity, deep connectivity, holographic connectivity, and ubiquitous connectivity, and the 6G system can satisfy the requirements as shown in Table 1 below. In other words, Table 1 is a table showing an example of the requirements of a 6G system.
[0162]
[0163] Per device peak data rate1TbpsE2E latency1msMaximum spectral efficiency100bps / HzMobility supportUp to 1000km / hrSatellite integrationFullyAIFullyAutonomous vehicleFullyXRFullyHaptic CommunicationFully
[0164] 6G systems can have key factors such as enhanced mobile broadband (eMBB), ultra-reliable low latency communications (URLLC), massive machine-type communication (mMTC), AI integrated communication, tactile internet, high throughput, high network capacity, high energy efficiency, low backhaul and access network congestion, and enhanced data security.
[0165]
[0166] Figure 5 is a diagram illustrating an example of a communication structure that can be provided in a 6G system.
[0167] 6G systems are expected to have 50 times the simultaneous wireless connectivity of 5G systems. URLLC, a key feature of 5G, will become even more crucial in 6G communications by providing end-to-end latency of less than 1 ms. 6G systems will have significantly higher volumetric spectral efficiency, compared to the commonly used area spectral efficiency. 6G systems can offer extremely long battery life and advanced battery technologies for energy harvesting, eliminating the need for separate charging for mobile devices in 6G systems. New network characteristics in 6G may include:
[0168] - Satellite integrated network: 6G is expected to integrate with satellites to provide a global mobile network. The integration of terrestrial, satellite, and airborne networks into a single wireless communications system is crucial for 6G.
[0169] Connected Intelligence: Unlike previous generations of wireless communication systems, 6G is revolutionary, upgrading the wireless evolution from "connected objects" to "connected intelligence." AI can be applied at every stage of the communication process (or at every signal processing step, as described below).
[0170] - Seamless integration of wireless information and energy transfer: 6G wireless networks will transfer power to charge the batteries of devices such as smartphones and sensors. Therefore, wireless information and energy transfer (WIET) will be integrated.
[0171] - Ubiquitous super 3D connectivity: Access to networks and core network functions of drones and very low Earth orbit satellites will create super 3D connectivity in 6G ubiquitous.
[0172] Some general requirements for the new network characteristics of 6G, such as the above, may be as follows:
[0173] - Small cell networks: The concept of small cell networks was introduced to improve received signal quality in cellular systems by increasing throughput, energy efficiency, and spectral efficiency. Consequently, small cell networks are essential for 5G and beyond-5G (5GB) communication systems. Accordingly, 6G communication systems also adopt the characteristics of small cell networks.
[0174] Ultra-dense heterogeneous networks: Ultra-dense heterogeneous networks will be another key feature of 6G communication systems. Multi-tier networks comprised of heterogeneous networks improve overall QoS and reduce costs.
[0175] High-capacity backhaul: Backhaul connections are characterized by high-capacity backhaul networks to support high-volume traffic. High-speed fiber optics and free-space optics (FSO) systems may be potential solutions to this problem.
[0176] - Radar technology integrated with mobile technology: High-precision localization (or location-based services) through communications is a key feature of 6G wireless communication systems. Therefore, radar systems will be integrated with 6G networks.
[0177] - Softwarization and virtualization: Softwarization and virtualization are two critical features that form the foundation of the design process for 5GB networks to ensure flexibility, reconfigurability, and programmability. Furthermore, billions of devices can be shared on a shared physical infrastructure.
[0178]
[0179] Core implementation technology of 6G systems
[0180]
[0181] Artificial Intelligence
[0182] The most crucial and newly introduced technology for 6G systems is AI. 4G systems did not involve AI. 5G systems will support partial or very limited AI. However, 6G systems will fully support AI for automation. Advances in machine learning will create more intelligent networks for real-time communications in 6G. Incorporating AI into communications can streamline and improve real-time data transmission. AI can use numerous analyses to determine how complex target tasks should be performed. In other words, AI can increase efficiency and reduce processing delays.
[0183] Time-consuming tasks such as handover, network selection, and resource scheduling can be performed instantly using AI. AI can also play a crucial role in machine-to-machine (M2M), machine-to-human, and human-to-machine communications. Furthermore, AI can facilitate rapid communication in brain-computer interfaces (BCIs). AI-based communication systems can be supported by metamaterials, intelligent structures, intelligent networks, intelligent devices, intelligent cognitive radios, self-sustaining wireless networks, and machine learning.
[0184] Recent attempts to integrate AI into wireless communication systems have focused on the application layer, network layer, and especially deep learning in wireless resource management and allocation. However, this research is increasingly evolving to the MAC layer and physical layer, with attempts to combine deep learning with wireless transmission, particularly at the physical layer. AI-based physical layer transmission refers to the application of AI-based signal processing and communication mechanisms, rather than traditional communication frameworks, in the fundamental signal processing and communication mechanisms. For example, this may include deep learning-based channel coding and decoding, deep learning-based signal estimation and detection, deep learning-based MIMO mechanisms, and AI-based resource scheduling and allocation.
[0185] Machine learning can be used for channel estimation and channel tracking, as well as for power allocation and interference cancellation in the physical layer of the downlink (DL). Furthermore, machine learning can be used for antenna selection, power control, and symbol detection in MIMO systems.
[0186] However, the application of DNN for transmission at the physical layer may have the following problems.
[0187] Deep learning-based AI algorithms require a large amount of training data to optimize training parameters. However, due to limitations in obtaining training data from specific channel environments, a large amount of training data is used offline. This means that static training using training data from specific channel environments can create a conflict with the dynamic characteristics and diversity of the wireless channel.
[0188] Furthermore, current deep learning primarily targets real-world signals. However, signals at the physical layer of wireless communications are complex signals. Further research is needed on neural networks that detect complex-domain signals to match the characteristics of wireless communication signals.
[0189] Below, we will look at machine learning in more detail.
[0190] Machine learning refers to a series of operations that train machines to perform tasks that humans can or cannot perform. Machine learning requires data and a learning model. Data learning methods in machine learning can be broadly categorized into three types: supervised learning, unsupervised learning, and reinforcement learning.
[0191] Neural network training aims to minimize output errors. It involves repeatedly inputting training data into a neural network, calculating the neural network output and target error for the training data, and backpropagating the neural network error from the output layer to the input layer to update the weights of each node in the neural network to reduce the error.
[0192] Supervised learning uses labeled training data, while unsupervised learning may not have labeled training data. For example, in the case of supervised learning for data classification, the training data may be data in which each training data category is labeled. The labeled training data is input to a neural network, and the error is calculated by comparing the output (categories) of the neural network with the training data labels. The calculated error is backpropagated through the neural network in the backward direction (i.e., from the output layer to the input layer), and the connection weights of each node in each layer of the neural network can be updated through backpropagation. The amount of change in the connection weights of each updated node can be determined by the learning rate. The neural network's calculation of the input data and the backpropagation of the error can constitute a learning cycle (epoch). The learning rate can be applied differently depending on the number of iterations of the neural network's learning cycle. For example, in the early stages of training a neural network, a high learning rate can be used to quickly allow the network to reach a certain level of performance, thereby improving efficiency. In the later stages of training, a low learning rate can be used to improve accuracy.
[0193] Learning methods may vary depending on the characteristics of the data. For example, if the goal is to accurately predict data transmitted by a transmitter in a communication system, supervised learning is preferable to unsupervised learning or reinforcement learning.
[0194] The learning model corresponds to the human brain, and the most basic linear model can be thought of, but the machine learning paradigm that uses highly complex neural network structures, such as artificial neural networks, as learning models is called deep learning.
[0195] The neural network cores used in learning methods are mainly divided into deep neural networks (DNN), convolutional deep neural networks (CNN), and recurrent boltzmann machines (RNN).
[0196] An artificial neural network is an example of a network of multiple perceptrons.
[0197]
[0198] Figure 6 is a schematic diagram illustrating an example of a perceptron structure.
[0199] Referring to Fig. 6, when an input vector x=(x1,x2,...,xd) is input, the entire process of multiplying each component by a weight (W1,W2,...,Wd), adding up all the results, and then applying the activation function σ(·) is called a perceptron. A large-scale artificial neural network structure can extend the simplified perceptron structure illustrated in Fig. 6 to apply the input vector to perceptrons of different dimensions. For convenience of explanation, input values or output values are called nodes.
[0200] Meanwhile, the perceptron structure illustrated in Fig. 6 can be explained as consisting of a total of three layers based on input and output values. An artificial neural network in which there are H perceptrons of (d+1) dimensions between the 1st layer and the 2nd layer, and K perceptrons of (H+1) dimensions between the 2nd layer and the 3rd layer can be expressed as in Fig. 7.
[0201]
[0202] Figure 7 is a schematic diagram illustrating an example of a multilayer perceptron structure.
[0203] The layer where the input vector is located is called the input layer, the layer where the final output value is located is called the output layer, and all layers located between the input layer and the output layer are called hidden layers. The example in Fig. 7 shows three layers, but when counting the number of layers in an actual artificial neural network, the input layer is excluded, so it can be viewed as a total of two layers. An artificial neural network is composed of perceptrons, which are basic blocks, connected in two dimensions.
[0204] The aforementioned input, hidden, and output layers can be applied jointly not only to multilayer perceptrons but also to various artificial neural network structures, such as CNNs and RNNs, which will be described later. The greater the number of hidden layers, the deeper the artificial neural network. The machine learning paradigm that uses sufficiently deep artificial neural networks as learning models is called deep learning. Furthermore, the artificial neural network used for deep learning is called a deep neural network (DNN).
[0205]
[0206] Figure 8 is a schematic diagram illustrating an example of a deep neural network.
[0207] The deep neural network illustrated in Figure 8 is a multilayer perceptron consisting of eight hidden layers and eight output layers. The multilayer perceptron structure is referred to as a fully connected neural network. In a fully connected neural network, there is no connection between nodes located in the same layer, and there is a connection only between nodes located in adjacent layers. DNN has a fully connected neural network structure and is composed of a combination of multiple hidden layers and activation functions, and can be usefully applied to identify correlation characteristics between inputs and outputs. Here, the correlation characteristic can mean the joint probability of inputs and outputs.
[0208] Meanwhile, depending on how multiple perceptrons are connected to each other, various artificial neural network structures different from the aforementioned DNN can be formed.
[0209]
[0210] Figure 9 is a schematic diagram illustrating an example of a convolutional neural network.
[0211] In DNN, nodes within a single layer are arranged vertically in a one-dimensional manner. However, Fig. 9 can assume a case where nodes are arranged two-dimensionally, with w nodes in width and h nodes in height (the convolutional neural network structure of Fig. 9). In this case, since a weight is added to each connection in the connection process from one input node to the hidden layer, a total of hΥw weights must be considered. Since there are hΥw nodes in the input layer, a total of h2w2 weights are required between two adjacent layers.
[0212] The convolutional neural network of Fig. 9 has a problem in that the number of weights increases exponentially according to the number of connections. Therefore, instead of considering the connections of all modes between adjacent layers, it assumes that there are small filters, and performs weighted sum and activation function operations on the overlapping portions of the filters, as in Fig. 10.
[0213]
[0214] Figure 10 is a schematic diagram illustrating an example of a filter operation in a convolutional neural network.
[0215] Each filter has a weight corresponding to the number of its size, and weight learning can be performed so that a specific feature on the image can be extracted as a factor and output. In Fig. 10, a filter of size 3Y3 is applied to the upper left 3Y3 region of the input layer, and the output value resulting from performing weighted sum and activation function operations on the corresponding node is stored in z22.
[0216] The above filter performs weighted sum and activation function operations while moving at a certain horizontal and vertical interval while scanning the input layer, and places the output value at the current filter position. This operation method is similar to the convolution operation for images in the field of computer vision, so a deep neural network with this structure is called a convolutional neural network (CNN), and the hidden layer generated as a result of the convolution operation is called a convolutional layer. In addition, a neural network with multiple convolutional layers is called a deep convolutional neural network (DCNN).
[0217] In the convolutional layer, the number of weights can be reduced by calculating a weighted sum that includes only the nodes located in the area covered by the filter, starting from the node where the current filter is located. This allows a single filter to focus on features within a local area. Accordingly, CNNs can be effectively applied to image data processing where physical distance in a two-dimensional area is an important criterion for judgment. Meanwhile, CNNs can apply multiple filters immediately before the convolutional layer, and can generate multiple output results through the convolution operation of each filter.
[0218] Meanwhile, depending on the data properties, there may be data for which sequence characteristics are important. Considering the length variability and chronological relationship of such sequence data, a structure that applies a method of inputting one element of the data sequence at each timestep and inputting the output vector (hidden vector) of the hidden layer output at a specific timestep together with the immediately following element in the sequence is called a recurrent neural network structure.
[0219]
[0220] Figure 11 is a schematic diagram illustrating an example of a neural network structure in which a recurrent loop exists.
[0221] Referring to Figure 11, a recurrent neural network (RNN) is a structure that inputs elements (x1(t), x2(t), ,..., xd(t)) of a data sequence at a time point t into a fully connected neural network, and then inputs the hidden vectors (z1(t-1), z2(t-1),..., zH(t-1)) of the immediately preceding time point t-1 together and applies a weighted sum and activation function. The reason for transmitting the hidden vector to the next time point in this way is because the information in the input vectors of the preceding time points is considered to be accumulated in the hidden vector of the current time point.
[0222]
[0223] Figure 12 is a diagram schematically illustrating an example of the operating structure of a recurrent neural network.
[0224] Referring to Figure 12, the recurrent neural network operates in a predetermined order of time for the input data sequence.
[0225] When the input vector (x1(t), x2(t), ,..., xd(t)) at time point 1 is input to the recurrent neural network, the hidden vector (z1(1), z2(1),..., zH(1)) is input together with the input vector (x1(2), x2(2),..., xd(2)) at time point 2, and the vector (z1(2), z2(2),..., zH(2)) of the hidden layer is determined through a weighted sum and an activation function. This process is repeatedly performed until time points 2, 3, ,,, T.
[0226] Meanwhile, when multiple hidden layers are placed within a recurrent neural network, it is called a deep recurrent neural network (DRNN). Recurrent neural networks are designed to be useful for processing sequence data (e.g., natural language processing).
[0227] It is a neural network core used in a learning manner, and includes various deep learning techniques such as DNN, CNN, RNN, Restricted Boltzmann Machine (RBM), Deep Belief Network (DBN), and Deep Q-Network, and can be applied to fields such as computer vision, speech recognition, natural language processing, and speech / signal processing.
[0228] Recent attempts to integrate AI into wireless communication systems have focused on the application layer, network layer, and especially deep learning in wireless resource management and allocation. However, this research is increasingly evolving to the MAC layer and physical layer, with attempts to combine deep learning with wireless transmission, particularly at the physical layer. AI-based physical layer transmission refers to the application of AI-based signal processing and communication mechanisms, rather than traditional communication frameworks, in the fundamental signal processing and communication mechanisms. For example, this may include deep learning-based channel coding and decoding, deep learning-based signal estimation and detection, deep learning-based MIMO mechanisms, and AI-based resource scheduling and allocation.
[0229] THz (Terahertz) communication
[0230] Data rates can be increased by increasing bandwidth. This can be achieved by utilizing sub-THz communications with wide bandwidths and applying advanced massive MIMO technology. THz waves, also known as sub-millimeter waves, typically refer to the frequency range between 0.1 THz and 10 THz, with corresponding wavelengths ranging from 0.03 mm to 3 mm. The 100 GHz to 300 GHz band (sub-THz band) is considered a key part of the THz band for cellular communications. Adding the sub-THz band to the mmWave band will increase the capacity of 6G cellular communications. Among the defined THz bands, 300 GHz to 3 THz lies in the far infrared (IR) frequency band. While part of the optical band, the 300 GHz to 3 THz band lies at the boundary of the optical band, immediately following the RF band. Therefore, this 300 GHz to 3 THz band exhibits similarities to RF.
[0231]
[0232] Figure 13 is a diagram illustrating an example of the electromagnetic spectrum.
[0233] Key characteristics of THz communications include (i) the widely available bandwidth to support very high data rates and (ii) the high path loss that occurs at high frequencies (requiring highly directional antennas). The narrow beamwidths generated by highly directional antennas reduce interference. The small wavelength of THz signals allows for a significantly larger number of antenna elements to be integrated into devices and base stations operating in this band. This enables the use of advanced adaptive array technologies to overcome range limitations.
[0234] Optical wireless technology
[0235] OWC technology is designed for 6G communications, in addition to RF-based communications for all possible device-to-access networks. These networks connect to network-to-backhaul / fronthaul networks. OWC technology has already been used in 4G communication systems, but it will be used more widely to meet the demands of 6G communication systems. OWC technologies such as light fidelity, visible light communication, optical camera communication, and wideband-based FSO communication are already well-known. Communications based on optical wireless technology can provide very high data rates, low latency, and secure communications. LiDAR can also be used for ultra-high-resolution 4D mapping in 6G communications based on wideband.
[0236] FSO backhaul network
[0237] The transmitter and receiver characteristics of an FSO system are similar to those of a fiber-optic network. Therefore, data transmission in an FSO system is similar to that of a fiber-optic system. Therefore, FSO can be a promising technology for providing backhaul connectivity in 6G systems, in conjunction with fiber-optic networks. Using FSO, ultra-long-distance communications are possible, even over distances exceeding 10,000 km. FSO supports high-capacity backhaul connectivity for remote and non-remote areas, such as the ocean, space, underwater, and isolated islands. FSO also supports cellular base station (BS) connections.
[0238] Massive MIMO technology
[0239] One of the key technologies for improving spectral efficiency is the application of MIMO technology. As MIMO technology improves, spectral efficiency also improves. Therefore, massive MIMO technology will be crucial in 6G systems. Because MIMO technology utilizes multiple paths, multiplexing technology must be considered to ensure that data signals can be transmitted along more than one path, as well as beam generation and operation technologies suitable for the THz band.
[0240] Blockchain
[0241] Blockchain will become a crucial technology for managing massive amounts of data in future communication systems. Blockchain is a form of distributed ledger technology. A distributed ledger is a database distributed across numerous nodes or computing devices. Each node replicates and stores an identical copy of the ledger. Blockchains are managed by a peer-to-peer network and can exist without being managed by a central authority or server. Data on a blockchain is collected and organized into blocks. Blocks are linked together and protected using cryptography. Blockchain perfectly complements large-scale IoT with its inherently enhanced interoperability, security, privacy, reliability, and scalability. Therefore, blockchain technology offers several features, such as interoperability between devices, traceability of large amounts of data, autonomous interaction with other IoT systems, and the massive connectivity stability of 6G communication systems.
[0242] 3D networking
[0243] 6G systems integrate terrestrial and airborne networks to support vertically expanded user communications. 3D BS will be provided via low-orbit satellites and UAVs. Adding a new dimension in altitude and associated degrees of freedom, 3D connections differ significantly from existing 2D networks.
[0244] Quantum communication
[0245] Unsupervised reinforcement learning holds promise in the context of 6G networks. Supervised learning approaches cannot label the massive amounts of data generated by 6G networks. Unsupervised learning does not require labeling. Therefore, this technology can be used to autonomously build representations of complex networks. Combining reinforcement learning and unsupervised learning allows for truly autonomous network operation.
[0246] drone
[0247] Unmanned Aerial Vehicles (UAVs), or drones, will be a key element in 6G wireless communications. In most cases, high-speed wireless connections will be provided using UAV technology. BS entities are installed on UAVs to provide cellular connectivity. UAVs offer specific capabilities not found in fixed BS infrastructure, such as easy deployment, robust line-of-sight links, and controlled mobility. During emergencies such as natural disasters, deploying terrestrial communication infrastructure is not economically feasible, and sometimes, volatile environments make it impossible to provide services. UAVs can easily handle these situations. UAVs will become a new paradigm in wireless communications. This technology facilitates three fundamental requirements for wireless networks: enhanced mobile broadband (eMBB), URLLC, and mMTC. UAVs can also support various purposes, such as enhancing network connectivity, fire detection, disaster emergency services, security and surveillance, pollution monitoring, parking monitoring, and accident monitoring. Therefore, UAV technology is recognized as one of the most important technologies for 6G communications.
[0248] Cell-free Communication
[0249] Tight integration of multiple frequencies and heterogeneous communication technologies is crucial in 6G systems. As a result, users will be able to seamlessly move from one network to another without requiring any manual configuration on their devices. The best network will be automatically selected from available communication technologies. This will break the limitations of the cell concept in wireless communications. Currently, user movement from one cell to another in dense networks results in excessive handovers, resulting in handover failures, handover delays, data loss, and a ping-pong effect. 6G cell-free communications will overcome all of these challenges and provide better QoS. Cell-free communications will be achieved through multi-connectivity and multi-tier hybrid technologies, as well as heterogeneous radios on devices.
[0250] Integration of wireless information and energy transmission
[0251] WIET uses the same fields and waves as wireless communication systems. Specifically, sensors and smartphones will be charged using wireless power transfer during communication. WIET is a promising technology for extending the life of battery-powered wireless systems. Therefore, battery-less devices will be supported by 6G communications.
[0252] Integration of sensing and communication
[0253] Autonomous wireless networks are capable of continuously sensing dynamically changing environmental conditions and exchanging information between different nodes. In 6G, sensing will be tightly integrated with communications to support autonomous systems.
[0254] Integration of Access Backhaul Networks
[0255] In 6G, the density of access networks will be enormous. Each access network will be connected to backhaul connections, such as fiber optics and FSO networks. To cope with the enormous number of access networks, there will be tight integration between access and backhaul networks.
[0256] Holographic beam forming
[0257] Beamforming is a signal processing procedure that adjusts an antenna array to transmit a wireless signal in a specific direction. It is a subset of smart antennas or advanced antenna systems. Beamforming technology offers several advantages, including high signal-to-noise ratio, interference avoidance and rejection, and high network efficiency. Holographic beamforming (HBF) is a novel beamforming method that differs significantly from MIMO systems because it uses software-defined antennas. HBF will be a highly effective approach for efficient and flexible signal transmission and reception in multi-antenna communication devices in 6G.
[0258] Big data analysis
[0259] Big data analytics is a complex process for analyzing diverse, large-scale data sets, or "big data." This process uncovers hidden data, unknown correlations, and customer trends, ensuring complete data management. Big data is collected from various sources, such as video, social networks, images, and sensors. This technology is widely used to process massive amounts of data in 6G systems.
[0260] Large Intelligent Surface (LIS)
[0261] THz-band signals have strong linearity, which can create many shadow areas due to obstacles. LIS technology, which enables expanded communication coverage, enhanced communication stability, and additional value-added services by installing LIS near these shadow areas, is becoming increasingly important. LIS is an artificial surface made of electromagnetic materials that can alter the propagation of incoming and outgoing radio waves. While LIS can be viewed as an extension of massive MIMO, it differs from massive MIMO in its array structure and operating mechanism. Furthermore, LIS operates as a reconfigurable reflector with passive elements, passively reflecting signals without using active RF chains, which offers the advantage of low power consumption. Furthermore, because each passive reflector in LIS must independently adjust the phase shift of the incoming signal, this can be advantageous for wireless communication channels. By appropriately adjusting the phase shift via the LIS controller, the reflected signal can be collected at the target receiver to boost the received signal power.
[0262]
[0263] Terahertz (THz) wireless communications in general
[0264]
[0265] THz wireless communication uses THz waves with a frequency of approximately 0.1 to 10 THz (1 THz = 1012 Hz), and can refer to terahertz (THz) band wireless communication using a very high carrier frequency of 100 GHz or higher. THz waves are located between the RF (Radio Frequency) / millimeter (mm) and infrared bands, and (i) compared to visible light / infrared light, they penetrate non-metallic / non-polarizable materials well, and compared to RF / millimeter waves, they have a shorter wavelength, so they have high linearity and can focus beams. In addition, since the photon energy of THz waves is only a few meV, they have the characteristic of being harmless to the human body. The frequency bands expected to be used for THz wireless communication may be the D-band (110 GHz to 170 GHz) or H-band (220 GHz to 325 GHz), which have low propagation loss due to molecular absorption in the air. Discussions on standardization of THz wireless communication are being centered around the IEEE 802.15 THz working group in addition to 3GPP, and standard documents issued by the IEEE 802.15 Task Group (TG3d, TG3e) may specify or supplement the contents described in various embodiments of the present disclosure. THz wireless communication can be applied to wireless cognition, sensing, imaging, wireless communication, THz navigation, etc.
[0266]
[0267] Figure 14 is a diagram illustrating an example of a THz communication application.
[0268] As illustrated in Figure 14, THz wireless communication scenarios can be categorized into macro networks, micro networks, and nanoscale networks. In macro networks, THz wireless communication can be applied to vehicle-to-vehicle and backhaul / fronthaul connections. In micro networks, THz wireless communication can be applied to fixed point-to-point or multi-point connections, such as indoor small cells, wireless connections in data centers, and near-field communications, such as kiosk downloads.
[0269] Table 2 below shows examples of technologies that can be used in THz waves.
[0270] Transceivers DeviceAvailable immature: UTC-PD, RTD and SBDModulation and CodingLow order modulation techniques (OOK, QPSK), LDPC, Reed Soloman, Hamming, Polar, TurboAntennaOmni and Directional, phased array with low number of antenna elementsBandwidth69GHz (or 23 GHz) at 300GHzChannel modelsPartiallyData rate100GbpsOutdoor deploymentNoFree space lossHighCoverageLowRadio Measurements300GHz indoorDevice sizeFew micrometers
[0271]
[0272] THz wireless communications can be categorized based on the methods used to generate and receive THz waves. THz generation methods can be categorized as either optical or electronic-based.
[0273]
[0274] Fig. 15 is a diagram illustrating an example of an electronic component-based THz wireless communication transmitter and receiver.
[0275] Methods for generating THz using electronic components include a method using semiconductor components such as a resonant tunneling diode (RTD), a method using a local oscillator and a multiplier, a MMIC (Monolithic Microwave Integrated Circuits) method using an integrated circuit based on a compound semiconductor HEMT (High Electron Mobility Transistor), and a method using a Si-CMOS-based integrated circuit. In the case of Fig. 15, a multiplier (doubler, tripler, multiplier) is applied to increase the frequency, and it passes through a subharmonic mixer and is radiated by an antenna. Since the THz band forms a high frequency, a multiplier is essential. Here, the multiplier is a circuit that has an output frequency that is N times that of the input, and matches it to the desired harmonic frequency and filters out all remaining frequencies. In addition, beamforming can be implemented by applying an array antenna or the like to the antenna of Fig. 15. In Fig. 15, IF represents intermediate frequency, tripler and multiplexer represent multipliers, PA represents power amplifier, LNA represents low noise amplifier, and PLL represents phase-locked loop.
[0276]
[0277] FIG. 16 is a diagram illustrating an example of a method for generating a THz signal based on an optical element.
[0278] Fig. 17 is a diagram illustrating an example of an optical element-based THz wireless communication transceiver.
[0279] Optical component-based THz wireless communication technology refers to a method of generating and modulating THz signals using optical components. Optical component-based THz signal generation technology generates an ultra-high-speed optical signal using a laser and an optical modulator, and converts it into a THz signal using an ultra-high-speed photodetector. Compared to technologies that use only electronic components, this technology can easily increase the frequency, generate high-power signals, and obtain flat response characteristics over a wide frequency band. As illustrated in Figure 16, optical component-based THz signal generation requires a laser diode, a wideband optical modulator, and an ultra-high-speed photodetector. In the case of Figure 16, the light signals of two lasers with different wavelengths are combined to generate a THz signal corresponding to the wavelength difference between the lasers. In Fig. 16, an optical coupler refers to a semiconductor device that transmits an electrical signal using optical waves to provide electrical isolation and coupling between circuits or systems, and a UTC-PD (Uni-Travelling Carrier Photo-Detector) is a type of photodetector that uses electrons as active carriers and reduces the travel time of electrons with bandgap grading. The UTC-PD is capable of detecting light at 150 GHz or higher. In Fig. 17, an EDFA (Erbium-Doped Fiber Amplifier) represents an erbium-doped fiber amplifier, a PD (Photo Detector) represents a semiconductor device that can convert an optical signal into an electrical signal, an OSA represents an optical module (Optical Sub Assembly) that modularizes various optical communication functions (photoelectric conversion, electro-optical conversion, etc.) into a single component, and a DSO represents a digital storage oscilloscope.
[0280]
[0281] The structure of a photoelectric converter (or photoelectric converter) is described with reference to FIGS. 18 and 19.
[0282] Fig. 18 is a diagram illustrating the structure of a photon source-based transmitter.
[0283] Figure 19 is a drawing showing the structure of an optical modulator.
[0284] In general, the phase of a signal can be changed by passing the optical source of a laser through an optical wave guide. At this time, data is loaded by changing the electrical characteristics through a microwave contact, etc. Therefore, the optical modulator output is formed as a modulated waveform. An opto-electrical modulator (O / E converter) can generate THz pulses by optical rectification operation by a nonlinear crystal, photoelectric conversion by a photoconductive antenna, emission from a bunch of relativistic electrons, etc. Terahertz pulses generated in the above manner can have a length in units of femtoseconds to picoseconds. An optical / electronic converter (O / E converter) performs down conversion by utilizing the non-linearity of the device.
[0285] Considering the THz spectrum usage, it is likely that THz systems will use multiple contiguous gigahertz bands for fixed or mobile service purposes. Based on the outdoor scenario criteria, the available bandwidth can be classified based on the oxygen attenuation of 10^2 dB / km in the spectrum up to 1 THz. Accordingly, a framework in which the available bandwidth is composed of multiple band chunks can be considered. As an example of the above framework, if the THz pulse length for one carrier is set to 50 ps, the bandwidth (BW) becomes approximately 20 GHz.
[0286] Effective down-conversion from the infrared band (IR band) to the terahertz band (THz band) depends on how to utilize the nonlinearity of the optical / electrical converter (O / E converter). In other words, to down-convert to the desired terahertz band (THz band), it is necessary to design an optical / electrical converter (O / E converter) with the most ideal non-linearity for transferring to the corresponding terahertz band (THz band). If an optical / electrical converter (O / E converter) that is not suitable for the target frequency band is used, errors are likely to occur in the amplitude and phase of the corresponding pulse.
[0287] In a single-carrier system, a terahertz transmission and reception system can be implemented using a single optical-to-electrical converter. Depending on the channel environment, in a multi-carrier system, the number of optical-to-electrical converters may be equal to the number of carriers. This phenomenon will be particularly noticeable in a multi-carrier system that utilizes multiple broadbands according to the aforementioned spectrum usage plan. In this regard, a frame structure for the multi-carrier system may be considered. A signal down-converted using an optical-to-electrical converter may be transmitted in a specific resource region (e.g., a specific frame). The frequency region of the specific resource region may include multiple chunks. Each chunk may be composed of at least one component carrier (CC).
[0288]
[0289] Specific descriptions of various embodiments of the present disclosure
[0290] Hereinafter, various embodiments of the present disclosure will be described in more detail.
[0291]
[0292] The present disclosure relates to a method and apparatus for supporting a quantum coherent time-based quantum public key infrastructure with a hybrid approach in a quantum communication system.
[0293]
[0294] Background to various embodiments of the present disclosure
[0295] User authentication technology
[0296] FIG. 20 is a diagram illustrating an example of a man-in-the-middle attack in a system applicable to the present disclosure.
[0297] In quantum communication systems, the security of information transmitted via a quantum channel is guaranteed by the non-cloning theorem, a quantum mechanical property. This allows for the security of transmitted messages to be determined through a QBER (Quantum Bit Error Rate) estimation process, utilizing a portion of the information transmitted via the quantum channel. This allows for the detection of eavesdropping by a third party. Therefore, the security of the transmitted message can be guaranteed. However, as shown in Figure 20, if Eve, a third party, exists between Alice (the sender) and Bob (the receiver), attempting a man-in-the-middle attack by pretending to be the receiver to Alice and the sender to Bob, the QBER estimation results from the information transmission between Alice and Eve, and Eve and Bob, cannot be used to detect Eve's presence. This allows Eve to access all the transmitted data while relaying it, and could even attempt to falsify or modify it. Therefore, to prevent this, a user authentication process is required, verifying that both the sender and receiver, the parties exchanging information, are authorized users.
[0298] Existing authentication techniques can be divided into hash function-based methods that incorporate cryptographic strengths and methods based on security from an information-theoretic perspective. First, cryptographic hash function-based methods are used as authentication techniques based on the computational complexity of the hash function's collision probability. Among current cryptographic techniques, the SHA technique is known as a representative hash function-based technique. However, because this technique relies on computational complexity, it is highly likely that its security will be threatened in the future with the advent of quantum computers. To strengthen security, current quantum cryptography communication systems use a family of keyed hash functions that combine symmetric keys and hash functions based on information-theoretic security as an authentication technique. Furthermore, quantum communication standards organizations such as ETSI have adopted this method as a standard authentication method. This method uses a hash function called Strongly Universal Hashing as a Message Authentication Code (MAC) algorithm to generate a Message Authentication Code (MAC) to be used in the authentication process, and additionally uses a symmetric key used as a one-time pad (OTP) in the generation process. Since it is very unlikely that information can be recovered through the reverse process from the MAC without knowing the key information, it is currently known to have the highest level of security. A representative method is the Wegman & Carter Authentication (WCA) technique proposed by M. Wegman and J. Carter. Currently, authentication techniques of the WCA series are applied as standard authentication methods for quantum information transmission techniques such as QKD, and the detailed structure of WCA is as follows.
[0299]
[0300] Classical authentication method: Message authentication code (MAC) by Wegman & Carter
[0301] FIG. 21 is a diagram illustrating an example of a MAC-based authentication technique in a system applicable to the present disclosure.
[0302] MAC is used to verify the integrity of a message. As shown in Figure 21, it is difficult for a third party who does not know the one-time symmetric key information previously shared between the sender and receiver to determine which MAC algorithm was used when generating the MAC. Before the authentication process, the sender and receiver share the same symmetric key information and MAC algorithm. When the sender inputs the plaintext message to be used for authentication into the MAC algorithm, the MAC algorithm to be used is selected based on the pre-shared key value. Next, when the plaintext is input into the selected MAC algorithm, a MAC is generated as the output value. To generate the MAC for the receiver, the sender transmits the plaintext message and MAC it generated via a classical channel. The receiver passes the received plaintext message through its MAC algorithm. Since the receiver possesses the same pre-shared key as the sender, it can generate the MAC using the same MAC algorithm. Finally, the MAC transmitted by the sender is compared with the MAC generated by the receiver to determine if they match. If the two values match, authentication is successful. If the two values do not match, authentication fails. In the MAC method, the pre-shared symmetric key information is ultimately not transmitted over a traditional channel, but is held only by the agreed-upon sender and receiver. Therefore, even if a third party were to obtain the message information without securing the symmetric key, they would not be able to determine which MAC algorithm is being applied. Therefore, this method guarantees security. Therefore, the security of this technique is higher as the number of MAC algorithm configuration methods increases.
[0303]
[0304] FIG. 22 is a diagram illustrating an example of Wegman & Carter Authentication (WCA) in a system applicable to the present disclosure.
[0305] The quantum key distribution (QKD) protocol, which is currently being applied as a security technology for 4G LTE / 5G, uses the WCA technique proposed by Wegman and Carter as a standard authentication technology, and uses the method of Fig. 22 to generate a tag with a MAC to be used for authentication using a symmetric key generated in the form of a one time pad and a Strongly Universal Hash class.
[0306] This technique can be applied to both user authentication to check whether the sender and receiver have changed during message transmission and message authentication to check whether the content and order of message information have changed. Here, similar to MAC, tag information that acts as a MAC is generated using a pre-shared key and MAC algorithm. The MAC algorithm used here uses the hash function set H of the Strongly Universal Hash class. In addition, the pre-shared key information in the sender and receiver plays a role in selecting which hash function h_k to use in H, and the length of the pre-shared key is assigned as log2|H| bits, where |H| means the number of hash functions that constitute the hash function set. Next, the tag information is T=h k (m) is denoted as a hash function h selected from a pre-shared key as an input value for the message m of the authentication process. k It is obtained from the result obtained after passing. Finally, the tag information transmitted from the transmitter and the message received from the receiver are compared with the tag information of the receiver obtained from the receiver's pre-shared key and hash function to check if they match and then determine whether authentication is necessary.
[0307] As mentioned earlier, the Wegman & Carter authentication scheme uses a hash function as a MAC algorithm. A hash function is a function that takes information of any length and outputs a fixed-length hash value. It is also called a message digest because it reduces a sentence of the original length to a fixed size. The reason the hash function is used as a MAC in the authentication process is because it has the following three characteristics.
[0308] (1) 1st Preimage resistance: For any given output value y, it is computationally impossible to find an input value x that satisfies y = h(x).
[0309] (2) 2nd Preimage resistance: When there is h(x) for a given input value x and h(x)=h(x`), it is computationally infeasible to find another input value x` that satisfies x≠x`.
[0310] (3) Collision resistance: It is computationally infeasible to find two input values x and x` that satisfy the hash value h(x) = h(x`).
[0311]
[0312] FIG. 23 is a diagram illustrating an example of collision probability in Wegman & Carter Authentication (WCA) in a system applicable to the present disclosure.
[0313] WCA is a Man-in-the-middle attack. When Eve replaces message m with m' and guesses and sends a tag, Eve does not know which hash function the sender and receiver used, so she selects a random hash function to guess the tag, and the success probability is 1 / |T|. (Here, |T| represents the number of tags.) In other words, the number of tags is determined by the number of types of hash functions |H| used, so the more types of hash functions are used, the lower the possibility that Eve will guess the tag. In other words, as in the collision probability formula in Fig. 23, the larger the number of hash functions, the lower the collision probability.
[0314] Ref. 1) T. Krovetz and W. Dai (2007). "VMAC: Message Authentication Code using Universal Hashing". CFRG Working Group. IETF. Retrieved 2010-08-12
[0315] Ref. 2) J. Carter; Wegman, M. (1977). “Universal classes of hash functions”. Proceedings of the Ninth Annual ACM Symposium on Theory of Computing. ACM: 106?112.
[0316] Ref. 3) J. Carter; Wegman, M. (1981). “New hash functions and their use in authentication and set equality”. Journal of Computer and System Sciences. 22 (3): 265-279.
[0317]
[0318] Quantum No-cloning Theorem
[0319] FIG. 24 is a diagram illustrating an example of a concept of cloning for a qubit in a system applicable to the present disclosure.
[0320] The uncloning of quantum states, utilized in quantum communication, is a key theoretical principle that ensures the security of quantum communication. In physics, it states that it is impossible to create independent and identical copies of any unknown quantum state. Originating from James Park's No-go Theorem in 1970, the No-cloning Theorem was announced by Wootters and Zurek in 1982. Since then, development and experimentation with quantum cloning technologies have continued. However, rather than creating completely independent and identical copies, these studies focus on creating clones in an entangled state with some fidelity, thus not violating the No-cloning Theorem.
[0321] Copying a Qubit means changing the Input State Original State through Quantum Dynamics Wow Clone State This means outputting . If diagrammed, it is as shown in Figure 24.
[0322] If the Unitary Transform above is configured as a CNOT Gate, the Ancilla State When doing this, it can be expressed by the following mathematical formula 1.
[0323]
[0324] Therefore, the purpose is It is not possible to derive the state of . To make it more general, if there exists an arbitrary Unitary Transform that copies a qubit, then the Input State or Let's assume that. Then, the following relationship appears as mathematical equation 2.
[0325]
[0326] Then, the Input State is an arbitrary Quantum State When this happens, a relationship similar to the following mathematical expression 3 appears.
[0327]
[0328] That is, there cannot be any arbitrary Unitary Transform that completely copies a qubit.
[0329] Therefore, even if an attacker steals a qubit in quantum communication, it is impossible to copy that qubit and use it for an attack.
[0330]
[0331] Quantum Coherence Time
[0332] Qubits utilized in quantum communication, similar to classical communication, can also be affected by imperfections in the real-world environment, affecting the quality of transmitted information. This interaction with the environment can cause irreversible changes to the quantum state, a process known as decoherence. Environmental decoherence is a major cause of quantum state corruption, and can occur not only in quantum memory but also during quantum transmission or quantum processing. In particular, unlike classical communication, qubits are based on a single-photon state, corresponding to a very low energy level. Therefore, they are highly sensitive to environmental factors (temperature, vibration, atmospheric conditions, devices, etc.). Therefore, a quantum state can lose its original properties after a certain period of time by losing its quantum superposition state. The time it takes for a quantum state to maintain its original quantum superposition state while retaining its original properties is called coherence time.
[0333] Therefore, in quantum communication, qubit-based communication must occur within the coherence time. Furthermore, the transmission, computation, and measurement operations required for communication must be completed within this time frame to ensure that the sender can accurately convey the intended information to the receiver.
[0334]
[0335] The symbols / abbreviations / terms used in this disclosure are as follows.
[0336] - QA: Quantum Authentication
[0337]
[0338] Technical problems to be solved in this disclosure
[0339] Authentication with Key Distribution in Classical Communication
[0340] Figure 25 is a diagram illustrating an example of security keys in a 5G network system.
[0341] When considering the 5G Network in the 3GPP standard among existing communication systems, security keys to be used for communication can be obtained using a method such as that shown in Fig. 25.
[0342] In Fig. 25, the UDM / ARPF (Unified Data Management / Authentication credential Repository Processing Function) on the Network Side and the USIM (Universal Subscriber Identity Module) on the UE Side share the Root Key K through a predefined method. The Root Key is a user-specific information key corresponding to 128 bits or 256 bits depending on the operator's selection, and through the Root Key, the user authentication process, 5G AKA or EAP-AKA', is performed through the Ciphering Key or Integrity Key, and the Anchor Key corresponding to KSEAF is generated at the same time as the user authentication. Through the above process, the UE is authenticated as a user to the Network, and shares the Anchor Key for generating keys to be applied to secure communication such as encryption in subsequent communications.
[0343]
[0344] The 5G AKA or EAP-AKA process that operates for user authentication above can be summarized as follows.
[0345] (3GPP TS 33.501) 6.1.2 Initiation of authentication and selection of authentication method
[0346] FIG. 26 is a diagram illustrating an example of an authentication procedure initiation and authentication method selection process in a system applicable to the present disclosure.
[0347] Specifically, Figure 26 shows (3GPP TS 33.501 v18.1) Figure 6.1.2-1: Initiation of authentication procedure and selection of authentication method.
[0348] To perform the user authentication process, the UE transmits a Registration Request Message containing subscriber identity information, SUCI (Subscription Concealed Identifier) or temporary identity information, 5G-GUTI (5G-Globally Unique Temporary Identity), to SEAF (Security Anchor Function) / AMF (Access and Mobility Management Function) as an N1 Message. 5G-GUTI is used when the UE has been granted 5G-GUTI from the AMF after successful authentication in the previous registration process, and the 5G-GUTI is converted to a SUPI (Subscription Permanent Identifier) mapped by the AMF. If the UE does not have a 5G-GUTI or receives an Identity Request message from the AMF, it must request authentication via SUCI.
[0349] Upon receiving the registration request, the SEAF obtains the mobile carrier information that the terminal is subscribed to based on the SUCI or SUPI, and sends an authentication request message along with the information of the currently connected network (SN) to the AUSF (Authentication Server Function) of the corresponding mobile network (HN). The AUSF then sends it to the UDM (Unified Data Management). In the UDM, the Subscription Identifier De-concealing Function (SIDF) is used to decrypt the SUCI into SUPI to verify the user and select the authentication method 5G-AKA or EAP-AKA.
[0350]
[0351] (3GPP TS 33.501) 6.1.3 Authentication Procedures
[0352] FIG. 27 is a diagram illustrating an example of an authentication procedure initiation and authentication method selection process in a system applicable to the present disclosure.
[0353] Specifically, Figure 27 shows (3GPP TS 33.501 v18.1) Figure 6.1.3.2-1: Authentication procedure for 5G AKA.
[0354]
[0355] The authentication procedure for 5G AKA works as follows, cf. also Figure 6.1.3.2-1:
[0356] 1. For each Nudm_Authenticate_Get Request, the UDM / ARPF shall create a 5G HE AV. The UDM / ARPF does this by generating an AV with the Authentication Management Field (AMF) separation bit set to "1" as defined in TS 33.102. The UDM / ARPF shall then derive KAUSF (as per Annex A.2) and calculate XRES* (as per Annex A.4). Finally, the UDM / ARPF shall create a 5G HE AV from RAND, AUTN, XRES*, and KAUSF.
[0357] 2. The UDM shall then return the 5G HE AV to the AUSF together with an indication that the 5G HE AV is to be used for 5G AKA in a Nudm_UEAuthentication_Get Response. In case SUCI was included in the Nudm_UEAuthentication_Get Request, UDM will include the SUPI in the Nudm_UEAuthentication_Get Response after deconcealment of SUCI by SIDF.
[0358] If a subscriber has an AKMA subscription, the UDM shall include the AKMA indication and Routing indicator in the Nudm_UEAuthentication_Get Response.
[0359] 3. The AUSF shall store the XRES* temporarily together with the received SUCI or SUPI.
[0360] 4. The AUSF shall then generate the 5G AV from the 5G HE AV received from the UDM / ARPF by computing the HXRES* from XRES* (according to Annex A.5) and KSEAF from KAUSF (according to Annex A.6), and replacing the XRES* with the HXRES* and KAUSF with KSEAF in the 5G HE AV.
[0361] 5. The AUSF shall then remove the KSEAF and return the 5G SE AV (RAND, AUTN, HXRES*) to the SEAF in a Nausf_UEAuthentication_Authenticate Response.
[0362] 6. The SEAF shall send RAND, AUTN to the UE in a NAS message Authentication Request. This message shall also include the ngKSI that will be used by the UE and AMF to identify the KAMF and the partial native security context that is created if the authentication is successful. This message shall also include the ABBA parameter. The SEAF shall set the ABBA parameter as defined in Annex A.7.1. The ME shall forward the RAND and AUTN received in NAS message Authentication Request to the USIM.
[0363] NOTE 2: The ABBA parameter is included to enable the bidding down protection of security features.
[0364] 7. At receipt of the RAND and AUTN, the USIM shall verify the freshness of the received values by checking whether AUTN can be accepted as described in TS 33.102. If so, the USIM computes a response RES. The USIM shall return RES, CK, IK to the ME. If the USIM computes a Kc (i.e. GPRS Kc) from CK and IK using conversion function c3 as described in TS 33.102 , and sends it to the ME, then the ME shall ignore such GPRS Kc and not store the GPRS Kc on USIM or in ME. The ME then shall compute RES* from RES according to Annex A.4. The ME shall calculate KAUSF from CK||IK according to clause A.2. The ME shall calculate KSEAF from KAUSF according to clause A.6. An ME accessing 5G shall check during authentication that the "separation bit" in the AMF field of AUTN is set to 1. The "separation bit" is bit 0 of the AMF field of AUTN.
[0365] NOTE 3: This separation bit in the AMF field of AUTN cannot be used anymore for operator specific purposes as described by TS 33.102, Annex F.
[0366] 8. The UE shall return RES* to the SEAF in a NAS message Authentication Response.
[0367] 9. The SEAF shall then compute HRES* from RES* according to Annex A.5, and the SEAF shall compare HRES* and HXRES*. If they coincide, the SEAF shall consider the authentication successful from the serving network point of view. If not, the SEAF proceed as described in sub-clause 6.1.3.2.2. If the UE is not reached, and the RES* is never received by the SEAF, the SEAF shall consider authentication as failed, and indicate a failure to the AUSF.
[0368] 10. The SEAF shall send RES*, as received from the UE, in a Nausf_UEAuthentication_Authenticate Request message to the AUSF.
[0369] 11. When the AUSF receives as authentication confirmation the Nausf_UEAuthentication_Authenticate Request message including a RES* it may verify whether the 5G AV has expired. If the 5G AV has expired, the AUSF may consider the authentication as unsuccessful from the home network point of view. Upon successful authentication, the AUSF stores the KAUSF based on the home network operator's policy according to clause 6.1.1.1. AUSF shall compare the received RES* with the stored XRES*. If the RES* and XRES* are equal, the AUSF shall consider the authentication as successful from the home network point of view. AUSF shall inform UDM about the authentication result (see sub-clause 6.1.4 of the present document for linking with the authentication confirmation).
[0370] NOTE 4: It is left to implementation to temporarily store the KAUSF received in step 2 in AUSF until the RES* verification is done successfully (i.e., at step 11).
[0371] 12. The AUSF shall indicate to the SEAF in the Nausf_UEAuthentication_Authenticate Response whether the authentication was successful or not from the home network point of view. If the authentication was successful, the KSEAF shall be sent to the SEAF in the Nausf_UEAuthentication_Authenticate Response. In case the AUSF received a SUCI from the SEAF in the authentication request (see sub-clause 6.1.2 of the present document), and if the authentication was successful, then the AUSF shall also include the SUPI in the Nausf_UEAuthentication_Authenticate Response message.
[0372] The authentication procedure for 5G AKA is as follows or Figure 6.1.3.2-1.
[0373] 1. For each Nudm_Authenticate_Get request, the UDM / ARPF shall generate a 5G HE AV. The UDM / ARPF does this by generating an AV with the Authentication Management Field (AMF) separator bit set to "1" as defined in TS 33.102. The UDM / ARPF then derives the KAUSF (according to Annex A.2) and computes the XRES* (according to Annex A.4). Finally, the UDM / ARPF shall generate a 5G HE AV from the RAND, AUTN, XRES*, and KAUSF.
[0374] 2. Then, the UDM shall return the 5G HE AV to the AUSF in the Nudm_UEAuthentication_Get response with an indication that the 5G HE AV is used for 5G AKA. If SUCI was included in the Nudm_UEAuthentication_Get request, the UDM shall include SUCI in the Nudm_UEAuthentication_Get response after the SUCI is unmasked by the SIDF.
[0375] If the subscriber has an AKMA subscription, UDM must include the AKMA indication and routing indication in the Nudm_UEAuthentication_Get response.
[0376] 3. AUSF must temporarily store XRES* along with the received SUCI or SUPI.
[0377] 4. Then, AUSF shall generate 5G AV from 5G HE AV received from UDM / ARPF by calculating HXRES* from XRES* (according to Annex A.5) and KSEAF from KAUSF (according to Annex A.6). In 5G HE AV, XRES* is replaced with HXRES* and KAUSF is replaced with KSEAF.
[0378] 5. Then, AUSF shall remove KSEAF and return 5G SE AV (RAND, AUTN, HXRES*) to SEAF via Nausf_UEAuthentication_Authenticate response.
[0379] 6. SEAF shall send RAND and AUTN to the UE via NAS message authentication request. This message also includes the ngKSI, which the UE and AMF will use to identify the KAMF, and the partial default security context created if authentication is successful. This message also includes ABBA parameters. SEAF shall set the ABBA parameters as defined in Appendix A.7.1. The ME shall forward the RAND and AUTN received in the NAS message authentication request to the USIM.
[0380] Note 2: The ABBA parameter is included to enable bid-down protection for security features.
[0381] 7. Upon receiving RAND and AUTN, the USIM shall verify the up-to-dateness of the received values by checking whether it can accept the AUTN as described in TS 33.102. If so, the USIM shall compute the response RES. The USIM shall return RES, CK, and IK to the ME. If the USIM computes Kc (i.e., GPRS Kc) from CK and IK using the conversion function c3 as described in TS 33.102 and sends it to the ME, the ME shall ignore such GPRS Kc and shall not store the GPRS Kc on the USIM or in the ME. The ME shall then compute RES* from RES according to Annex A.4. The ME shall compute KAUSF from CK||IK according to Clause A.2. The ME shall compute KSEAF from KAUSF according to Clause A.6. MEs connecting to 5G must ensure that the "separation bit" in the AMF field of the AUTN is set to 1 during authentication. The "separation bit" is bit 0 of the AMF field of the AUTN.
[0382] NOTE 3: This separation bit in the AMF field of the AUTN is no longer available for operator-specific purposes as described in TS 33.102, Annex F.
[0383] 8. The UE must return RES* to SEAF in the NAS message authentication response.
[0384] 9. SEAF shall then calculate HRES* from RES* according to Appendix A.5, and compare HRES* with HXRES*. If they match, SEAF shall consider authentication successful from the service network perspective. Otherwise, SEAF shall proceed as described in subsection 6.1.3.2.2. If the UE is not reached and RES* is not received by SEAF, SEAF shall consider authentication to have failed and indicate a failure to AUSF.
[0385] 10. SEAF shall forward the RES* received from the UE to AUSF in the Nausf_UEAuthentication_Authenticate request message.
[0386] 11. When the AUSF receives a Nausf_UEAuthentication_Authenticate Request message containing RES* as an authentication confirmation, it can check whether the 5G AV has expired. If the 5G AV has expired, the AUSF can consider it as an authentication failure from the home network perspective. If the authentication is successful, the AUSF stores the KAUSF according to the home network operator's policy as per Section 6.1.1.1. The AUSF compares the received RES* with the stored XRES*. If the RES* and XRES* are identical, the AUSF shall consider the authentication as a success from the home network perspective. The AUSF shall notify the UDM about the authentication result (see subsection 6.1.4 of this document for connection with the authentication confirmation).
[0387] NOTE 4: It is implementation dependent to temporarily store the KAUSF received in Step 2 of the AUSF until the RES* verification is successfully completed (i.e., in Step 11).
[0388] 12. The AUSF shall indicate to SEAF whether authentication was successful from the home network perspective via the Nausf_UEAuthentication_Authenticate response. If authentication was successful, KSEAF shall forward the Nausf_UEAuthentication_Authenticate response to SEAF. If the AUSF received SUCI from SEAF in the authentication request (see subsection 6.1.2 of this document) and authentication was successful, the AUSF shall also include SUPI in the Nausf_UEAuthentication_Authenticate response message.
[0389] When the Authentication Method is selected as 5G AKA, the user authentication process is performed as shown in the above diagram. Based on the decrypted user information, the AUSF (Authentication Server Function) Key and 5G HE AV (Home Environment Authentication Vector) are generated using the user's top-level key value stored in the ARPF (Authentication Credential Repository Processing Function). The AUSF generates a 5G AV from the 5G HE AV received from the UDM (Unified Data Management) and transmits the 5G SE AV (Serving Environment Authentication Vector) excluding the SEAF Key to the SEAF. The SEAF transmits an Authenticate Request message including the value excluding the HXRES* value of the 5G SE AV to the terminal. The terminal generates an AUTN using the received RAND value and the top-level key stored in the terminal's USIM, and authenticates the network by verifying whether this value is the same as the AUTN received from the SEAF. Next, the RES* value to be used for terminal authentication and the AUSF Key and SEAF Key to be used in the terminal are sequentially generated, and then the RES* is transmitted to SEAF via the Authenticate Response message. SEAF obtains HRES* using the RES* transmitted by the terminal, and authenticates the terminal by comparing it with the HXRES* value of the 5G SE AV transmitted from the AUSF. In other words, the terminal is authenticated from the perspective of the network (SN) that provides the service to the terminal. After completing terminal authentication, SEAF transmits the RES* received from the terminal back to the AUSF, and the AUSF re-authenticates the terminal from the perspective of the home network (HN) by comparing it with the XRES* value of the 5G HE AV transmitted from the UDM.After successful authentication, AUSF transmits the subscriber's identity information, SUPI and SEAF Key, to the SEAF of the network (SN) to which the terminal is connected, and reports the authentication result to the UDM.
[0390] The 5G-AKA procedure is characterized by complementing the weaknesses of the 4G EPS-AKA procedure. First, it prevents theft of subscriber identity information in the initial wireless section by using SUCI. In addition, authentication is further strengthened by simultaneously receiving authentication from both the network (SN) to which the terminal is connected and receiving services, as well as the home network (HN) to which the terminal is subscribed. In addition, the subscriber identity information, SUPI, is transmitted to the network (SN) to which the terminal is connected only after authentication by the home network is completed, and the AMF Key can be generated only with this SUPI. This prevents a series of abnormal procedures from occurring, in which the network to which the terminal is connected completes the authentication procedure independently and proceeds with the subsequent key sharing and security context setup procedure without home network authentication.
[0391]
[0392] FIG. 28 is a diagram illustrating an example of a SUCI structure in a system applicable to the present disclosure.
[0393] Specifically, Figure 28 shows (3GPP TS 23.003 v18.2) Figure 2.2B-1: Structure of SUCI.
[0394] To prevent theft of subscriber identity information in the initial wireless section in the operation of Figure 27, the terminal must, in advance, hold the HN's public key in a reliable manner and, by public key encryption of the subscriber identity information to be sent, construct SUCI. The SUCI information is constructed as shown in Figure 28.
[0395] The SUCI is composed of the following parts:
[0396] 1) SUPI Type, consisting in a value in the range 0 to 7. It identifies the type of the SUPI concealed in the SUCI. The following values are defined:
[0397] - 0: IMSI
[0398] - 1: Network Specific Identifier (NSI)
[0399] - 2: Global Line Identifier (GLI)
[0400] - 3: Global Cable Identifier (GCI)
[0401] - 4 to 7: spare values for future use.
[0402] 2) Home Network Identifier, identifying the home network of the subscriber.
[0403] When the SUPI Type is an IMSI, the Home Network Identifier is composed of two parts:
[0404] - Mobile Country Code (MCC), consisting of three decimal digits. The MCC identifies uniquely the country of domicile of the mobile subscription;
[0405] - Mobile Network Code (MNC), consisting of two or three decimal digits. The MNC identifies the home PLMN or SNPN of the mobile subscription.
[0406] When the SUPI type is a Network Specific Identifier (NSI), a GLI or a GCI, the Home Network Identifier consists of a string of characters with a variable length representing a domain name as specified in clause 2.2 of IETF RFC 7542. For a GLI or a GCI, the domain name shall correspond to the realm part specified in the NAI format for SUPI in clauses 28.15.2 and 28.16.2.
[0407] 3) Routing Indicator, consisting of 1 to 4 decimal digits assigned by the home network operator and provisioned in the USIM, that allow together with the Home Network Identifier to route network signalling with SUCI to AUSF and UDM instances capable to serve the subscriber.
[0408] Each decimal digit present in the Routing Indicator shall be regarded as meaningful (e.g. value "012" is not the same as value "12"). If no Routing Indicator is configured on the USIM or the ME, this data field shall be set to the value 0 (i.e. only consist of one decimal digit of "0").
[0409] 4) Protection Scheme Identifier, consisting in a value in the range of 0 to 15 (see Annex C.1 of 3GPP TS 33.501). It represents the null scheme or a non-null scheme specified in Annex C of 3GPP TS 33.501 or a protection scheme specified by the HPLMN; the null scheme shall be used if the SUPI type is a GLI or GCI.
[0410] 5) Home Network Public Key Identifier, consisting in a value in the range 0 to 255. It represents a public key provisioned by the HPLMN or SNPN and it is used to identify the key used for SUPI protection. This data field shall be set to the value 0 if and only if null protection scheme is used;
[0411] 6) Scheme Output, consisting of a string of characters with a variable length or hexadecimal digits, dependent on the used protection scheme, as defined below. It represents the output of a public key protection scheme specified in Annex C of 3GPP TS 33.501 or the output of a protection scheme specified by the HPLMN.
[0412] SUCI consists of the following parts:
[0413] 1) SUPI type, consisting of values in the range 0 to 7. Identifies the SUPI type hidden in SUCI. The following values are defined.
[0414] - 0: IMSI
[0415] - 1: Network Specific Identifier (NSI)
[0416] - 2: Global Line Identifier (GLI)
[0417] - 3: Global Cable Identifier (GCI)
[0418] - 4 ~ 7: Reserved values for future use.
[0419] 2) Home network identifier, identifies the subscriber's home network.
[0420] If the SUPI type is IMSI, the home network identifier consists of two parts:
[0421] - The Mobile Country Code (MCC) consists of three decimal places. The MCC uniquely identifies the country of residence of a mobile subscriber.
[0422] - The Mobile Network Code (MNC) consists of two or three decimal digits. The MNC identifies the home PLMN or SNPN of the mobile subscription.
[0423] If the SUPI type is a Network Specific Identifier (NSI), a GLI, or a GCI, the home network identifier consists of a variable-length string representing the domain name specified in Section 2.2 of IETF RFC 7542. For a GLI or a GCI, the domain name must match the area part specified in the NAI format for SUPI in Sections 28.15.2 and 28.16.2.
[0424] 3) A routing indicator consisting of a 1- to 4-digit decimal number assigned by the home network operator and provided to the USIM. Using the SUCI along with the home network identifier, network signals can be routed to AUSF and UDM instances capable of providing service to subscribers.
[0425] Each decimal digit in the routing indicator is considered significant (e.g., the value "012" is not the same as the value "12"). If no routing indicator is configured on the USIM or ME, this data field must be set to the value 0 (i.e., it consists of only one decimal digit, "0").
[0426] 4) A protection scheme identifier (see Annex C.1 of 3GPP TS 33.501) consisting of values in the range 0 to 15. It indicates the null scheme, non-null scheme, or protection scheme specified in Annex C of 3GPP TS 33.501, or the protection scheme specified by HPLMN. The null scheme must be used when the SUPI type is GLI or GCI.
[0427] 5) Home network public key identifier, consisting of a value between 0 and 255. This represents the public key provided by the HPLMN or SNPN and is used to identify the key used for SUPI protection. This data field should be set to 0 only when the null protection scheme is used.
[0428] 6) Scheme output consisting of a string of variable length or hexadecimal digits, depending on the protection scheme used as defined below. This represents the output of the public key protection scheme specified in Annex C of 3GPP TS 33.501 or the output of the protection scheme specified by HPLMN.
[0429]
[0430] The content corresponding to the Scheme Output part above may be configured differently depending on the protection scheme, and may be configured as in Fig. 29 or Fig. 30 when the Elliptic Curve Integrated Encryption Scheme is used.
[0431] FIG. 29 is a diagram illustrating an example of a system output for an elliptic curve integrated encryption scheme profile A applicable to the present disclosure.
[0432] Specifically, Figure 29 shows (3GPP TS 23.003 v18.2) Figure 2.2B-3: Scheme Output for Elliptic Curve Integrated Encryption Scheme Profile A.
[0433] FIG. 30 is a diagram illustrating an example of a system output for an elliptic curve integrated encryption scheme profile B applicable to the present disclosure.
[0434] Specifically, Figure 30 shows (3GPP TS 23.003 v18.2) Figure 2.2B-4: Scheme Output for Elliptic Curve Integrated Encryption Scheme Profile B.
[0435] In the above SUCI structure, the entity that can decrypt the ciphertext value is the SIDF of UDM, which holds the private key of HN. However, due to the development of quantum computers and quantum algorithms, the security of systems using the above public key encryption may be threatened. It has been theoretically proven that encryption methods based on RSA (RIVEST? SHAMIR? ADLEMAN) or ECC (Elliptic Curve Cryptography), which are commonly used in asymmetric key-based security systems, can be deciphered within the valid time by parallel operation of the Shor Algorithm. For RSA 2048 bit, factoring is possible within 8 hours by 20 million noisy qubits [“How to factor 2048-bit RSA integers in 8 hours using 20 million noisy qubits” Quantum 5, 433 (2021)], and a study analyzing factoring within 177 days with only 13,436 qubits based on multi-parallel quantum memory [“Factoring 2048-bit RSA Integers in 177 Days with 13,436 Qubits and a Multimode Memory” PRL, (2021)] has been published. The collapse of an asymmetric key encryption system by such a quantum algorithm poses a serious threat to secure communication systems based on asymmetric key encryption.
[0436] To prevent these security threats, Post-Quantum Cryptography (PQC) technology is emerging. However, all asymmetric key systems based on computational complexity inevitably face the risk of being threatened by new quantum algorithms. Furthermore, transitioning to a new security system can entail a significant technical burden, as the new security technology must be applied across the entire device.
[0437] Therefore, a method is needed to address the threat of quantum algorithms while maintaining an asymmetric key system. To achieve this, trapdoor leakage caused by quantum algorithms can be adaptively prevented by periodically updating the public key. This prevents real-time leakage even if a plaintext attack is conducted using quantum algorithms. However, even if real-time leakage does not occur, an attacker can still conduct a plaintext attack later using a Harvest-Now-Decrypt-Later (HNDL) attack. Consequently, limiting the validity period of a public key alone cannot achieve fundamental information security.
[0438] In this disclosure, we propose a method for achieving physical information security based on the no-cloning theorem and quantum coherence time.
[0439]
[0440] Composition of various embodiments of the present disclosure
[0441] Quantum Coherence Time based Quantum Public Key Infrastructure
[0442] In this disclosure, we propose a Quantum Public Key Infrastructure (QPKI) system that provides physical security based on the No-cloning Theorem and Hybrid Quantum Bit Error Rate Check.
[0443]
[0444] The technology proposed in this disclosure provides physical security through quantum public key encryption by verifying the quantum public key in combination with a classical PKI system while sharing the quantum public key in real time rather than in advance. Man-in-the-middle attacks are prevented through classical PKI verification of the quantum public key. Even as quantum coherence time increases due to advancements in quantum memory, harvest-now-decrypt-later (HNDL) attacks are prevented through quantum error rate checks.
[0445] In the technology proposed in this disclosure, 1) it is assumed that the Classical PKI system has shared the Classical Public Key in a reliable manner. Here, sharing the initial Classical Public Key in a reliable manner generally means obtaining the Classical Public Key by Out-of-verification. For example, in a 3GPP communication system, the Classical Public Key of the HN is obtained at the initial USIM registration stage of the terminal. (TS 33.501 5.2.5 subscriber privacy: The Home Network Public Key shall be stored in the USIM.) 2) it is assumed that the Classical PKI system can renew a new Public Key in a reliable manner. 3. It is assumed that the minimum required time until the trapdoor of a specific Classical Public Key K of a specific Classical PKI system A is leaked by a quantum algorithm, etc. is X. 4. It is assumed that the quantum coherence time of the quantum state is maintained for a maximum of Y hours. 4. The quantum coherence time is increased by the development of quantum memory, so that the relationship is X < Y.
[0446]
[0447] 1. (HN-UE) Sharing and Renewing Classical Public Keys in a Reliable Way
[0448] HN and UE share the Classical Public Key in a reliable way, and renew it within X hours.
[0449] Sharing a Classical Public Key in a reliable manner means obtaining the Classical Public Key through out-of-verification. For example, in a 3GPP communication system, the HN's Classical Public Key is obtained during the initial USIM registration phase of the terminal.
[0450] A reliable way to update a Classical Public Key is through the Public Key Update System. The Public Key Update System can be comprised of five steps, as follows:
[0451] (1) (Step 1) (HN) Setting the public key validity period T and the public key update cycle R
[0452] HN sets the Public Key validity time Threshold T to be less than the time X that it takes to threaten the stability of the Public Key. The validity time Threshold T can be determined in real time by HN and stored in the UDM.
[0453] HN sets the Update Period R of the Public Key. Update Period R can be determined in real time by HN and stored in the UDM.
[0454] (2) (Step 2) (HN) Periodic Key Pair Generation
[0455] HN is the Key Pair of the public key system being used (e.g., Elliptic Curve Integrated Encryption Scheme (ECIES) in 3GPP TS 33.501). is generated periodically. Here, means the Secret Key (or Private Key) of the nth Key Pair, means the public key of the nth key pair.
[0456] Periodically generated key pairs are stored in the HN's UDM in the order of generation. (TS 33.501 5.8.2 Subscriber privacy-related requirements to UDM and SIDF: The Home Network Private Key used for subscriber privacy shall be protected from physical attacks in the UDM. The UDM shall hold the Home Network Public Key Identifier(s) for the private / public key pair(s) used for subscriber privacy.)
[0457] The time stamp for the generation time of the key pair generated in HN is stored in UDM.
[0458] The time stamp for the expired time of the key pair generated in HN is stored in UDM.
[0459] Key Pairs generated by HN may be limited to Key Pairs that have not been used before.
[0460] The generation of the Key Pair above may differ from the Key Update cycle R. For example, Key Pair generation may be performed and stored continuously within the UDM regardless of the Key Update cycle. Key Pairs for Public Key Update may sequentially use Key Pairs stored sequentially within the UDM.
[0461] (3) (Step 3) (HN) Updated Public Key Encryption
[0462] HN is the Secret Key of the Key Pair that was previously disclosed and used. Public Key to be disclosed from the newly created Key Pair Encrypts and creates a Renewal Key Block (RKB). The RKB can contain the following information.
[0463] (3-1) Renewal Key Block (RKB)
[0464] (3-1-1) Home Network Identifier
[0465] (3-1-1-1) It tells you which HN's public key to renew using the Home Network identifier.
[0466] (3-1-2) Protection Scheme ID (Protection Scheme Identifier)
[0467] (3-1-2-1) The encryption methods are defined in advance as identifiers for the encryption methods that encrypt / decrypt the updated public key.
[0468] (3-1-3) Home Network Public Key ID (Home Network Public Key Identifier)
[0469] (3-1-3-1) The identifier for the Home Network Public Key indicates which key among the Home Network Public Keys is being renewed.
[0470] (3-1-4) Basis P-Key (Basis Public Key)
[0471] (3-1-4-1) This is the Basis P-Key used when decrypting the Updated P-Key. It corresponds to the Home Network Public Key ID and is the Public Key of the HN used in the previous cycle.
[0472] (3-1-4-2) For example, if the Index indicating the current Public Key cycle is n, the Public Key of HN corresponding to the previous cycle is am.
[0473] (3-1-5) Encrypted P-Key (Encrypted Public Key)
[0474] (3-1-5-1) Basis Secret is an encryption technique corresponding to the Protection Scheme ID. Updated Public Key of HN encrypted by am.
[0475] (3-1-5-1-1) Here, Is by This means that it has been encrypted.
[0476] (3-1-5-2) Encrypted P-Key is decrypted with Basis P-key underneath, You can get it.
[0477] (3-1-5-2-1) Here, Is by This means that it has been decrypted.
[0478] (3-1-6) Validity Information
[0479] (3-1-6-1) Validity Information indicates the time for which the information in the Renewal Key Block is valid.
[0480] (4) (Step 4) (HN) Updated Public Key Broadcasting
[0481] The Renewal Key Block (RKB) generated and managed by UDM is broadcast to all users via public channels. The RKB generated by UDM can be announced to all users via the gNB via SEAF.
[0482] Here, the public channel may be a physical channel that carries a physical layer message. For example, it may be a physical broadcast channel (PBCH) that carries a master information block (MIB) or a physical downlink shared channel (PDSCH) that carries a system information block (SIB).
[0483] Alternatively, the public channel may be an upper layer channel that carries upper layer messages.
[0484] (5) (Step 5) (UE) Renewal Public Key Decryption
[0485] All UEs receive the broadcasted RKB and decrypt the RKB's Encrypted P-Key using the existing HN's Public Key.
[0486] (5-1) All UEs check whether their Home Network ID is correct in the received RKB and compare the Public Key of the HN they previously had with the Basis Public Key of the RKB to check whether they match.
[0487] (5-1-1) If the existing HN Public Key and the RKB Basis Public Key match, the Encrypted P-Key is decrypted using the Protection Scheme and Basis Public Key indicated by the RKB.
[0488] (5-1-1-1) The existing HN Public Key is replaced with the decrypted Updated P-Key.
[0489] (5-1-2) If the existing HN Public Key and the RKB Basis Public Key do not match, an updated public key is received through a separate Out-of-Verification.
[0490] Therefore, HN and UE can perform data encryption using Classical Public Key for X time, and security is not threatened during this time. However, it does not prevent HNDL Attack.
[0491]
[0492] 2. (UE) Request Quantum Public Key
[0493] When a UE needs to transmit secure information to the HN, it requests the HN to transmit a quantum public key. The request for the quantum public key can be made through a classical channel or a public channel (not a secure channel). The public channel can be a physical channel that carries physical layer messages. For example, it can be a physical uplink shared channel (PUSCH) or a physical uplink control channel (PUCCH). Alternatively, it can be an upper layer channel that carries upper layer messages.
[0494] Since the request for transmission of the Quantum Public Key can be received through the Serving Network (SN), the request can include information about the HN in order to request the Quantum Public Key of the HN.
[0495] A request to transmit a Quantum Public Key may be made including the length of the required Quantum Public Key.
[0496]
[0497] 3. (HN) Generation of Quantum Public Key
[0498] HN generates a Quantum Public Key to be shared with the UE. The Quantum Public Key is generated from a Private Key, which can be logical information. The Quantum Public Key represents a quantum state generated in one of two types, as follows:
[0499] (1) Single Qubit based Public Key
[0500] (1-1) HN creates a single qubit with an initial quantum state.
[0501] (1-1-1) For example, Initial Quantum State or can be set to .
[0502] (1-2) HN holds the Logical Information generated through the Random Number Generator as a Private Key. This information is Secret Information that is not disclosed to the outside world.
[0503] (1-2-1) For example, we can select any natural number n, where n is a number less than a predefined specific Threshold N.
[0504] (1-2-2) The Random Number Generator above can generate a Pure Random Number through a Quantum Random Number Generator, etc.
[0505]
[0506] FIG. 31a is a diagram illustrating an example of modulation by Qubit Rotation in a system applicable to the present disclosure.
[0507] (1-3) HN modulates the Initial Quantum State based on an arbitrary natural number n to create a Quantum Public Key Creates.
[0508] (1-3-1) For example, if the Initial Quantum State is When , modulate the Qubit Rotation corresponding to the natural number n: .
[0509] (1-3-1-1) Here, It means Unitary operation for Qubit Rotation.
[0510] (1-3-1-2) Qubit Rotation is Initial Quantum State and Orthogonal Quantum State It means Phase Rotation between.
[0511] (1-3-1-3) Here, Qubit Rotation is Initial Quantum State class It means that the z-axis phase rotation occurs between them. At this time, the axes that can be used are all x, y, and z. However, Initial Quantum State class If you are on this z-axis, you can also use only x-axis or y-axis rotation.
[0512] (1-4) Public Key modified by Private Key n Save to UDM.
[0513] (1-5) Multiple Private Keys in the same way and Public Key Create and save.
[0514] (1-6) Here, i is the index of the key.
[0515] (2) Entanglement based Public Key
[0516] (2-1) HN creates an Entanglement State with an Initial Bell State.
[0517] (2-1) For example, the Initial Bell State can be set to one of four Bell States.
[0518] (2-1-1)
[0519] (2-1-2)
[0520] (2-1-3)
[0521] (2-1-4)
[0522] (2-2) In the above, A means the first particle of the Qubit Pair (or Bell Pair) that constitutes the Bell State, and B means the second particle.
[0523] (2-2) HN holds the Logical Information generated through the Random Number Generator as a Private Key. This information is Secret Information that is not disclosed to the outside world.
[0524] (2-2-1) For example, we can select any natural number n, where n is a number less than a predefined threshold N.
[0525] (2-2-2) The Random Number Generator above can generate a Pure Random Number through a Quantum Random Number Generator, etc.
[0526]
[0527] FIG. 31b is a diagram illustrating an example of a Pauli operator in a system applicable to the present disclosure.
[0528] (2-3) HN generates a Quantum Public Key by modulating the Initial Bell State based on an arbitrary natural number n.
[0529] (2-3-1) For example, Initial Bell State When , a Unitary operation corresponding to the natural number n is applied to one Particle.
[0530] (2-3-1-1) For example, if the particle you want to use as a public key is the first particle, unitary operation is performed only on the first particle. Apply.
[0531] (2-3-1-2) Here, the Unitary operation can be a Pauli operation. A Pauli operation is an operation represented by Pauli X, Y, Z, and I, and means modulation of a quantum state.
[0532] (2-3-1-3) Pauli operators X, Y, and Z correspond to the measured values of spin along the x, y, and z axes, and are expressed as in Fig. 31b. Fig. 31b shows Pauli operators. Each operator has the following properties. The X operator performs a classical not operation (bit flip), Z performs an operation that converts the phase, and Y (=XZ) performs a combination operation of the two.
[0533]
[0534] (2-3-2) Or for example, one Initial Bell State And another Initial Bell State When , a Permutation operation corresponding to a natural number n is applied to two or more Initial Bell State operations.
[0535] (2-4) Key modified by Private Key n Save to UDM.
[0536] (2-4-1) Here, I stands for Pauli I. Initial Bell State Is and It can be written by dividing it into means the first particle of the Initial Bell State, where, refers to the second particle of the Initial Bell State.
[0537] (2-4-2) Here, is the first particle of the modified Bell State and is a Quantum Public Key, is the second unmodified Particle, which is the Quantum Secret Key.
[0538] (2-5) Multiple Quantum Secret Keys and Quantum Public Key Pairs in the same way Create and save.
[0539] (2-5-1) Here, i is the index of the key.
[0540] The Quantum Public Key generated by the above generation of the Quantum Public Key can always be limited to one of N states. For example, N can be 4. At this time, the Quantum State of the Quantum Public Key can be composed of a basis representing four polarization states. The polarization states can be expressed in four ways: 0°, 45°, 90°, and 135°. 0° and 90° can be represented as + in the orthogonal basis, and 45° and 135° can be represented as × in the cross basis.
[0541] In the above, generation of the Quantum Public Key can be performed at the time of receiving a Request of Quantum Public Key from the UE.
[0542] In the above, the generation of the Quantum Public Key may be generated in advance by the HN and stored in the Quantum Memory, regardless of the time of receiving the Request for Quantum Public Key from the UE.
[0543]
[0544] 4. (HN-UE) Transmission of Quantum Public Key
[0545] HN sends the Quantum Public Key to the UE. At this time, the Quantum Public Key It can be the first particle of a single qubit based public key or an entanglement based public key. Here, the quantum public key transmission is transmitted through a quantum channel.
[0546] Quantum Public Key transmission can be transmitted with the Quantum Public Key length set based on the length information of the Quantum Public Key included in the UE's Request of Quantum Public Key.
[0547] Quantum Public Key transmission can be performed by setting the Quantum Public Key length in units of a predefined length in the system. Here, the predefined length unit can be transmitted as header information along with the signal transmitting the Quantum Public Key.
[0548]
[0549] 5. (UE) Qubit and Measurement Basis Selection for Hybrid QBER Check
[0550] The UE performs Qubit Selection and Measurement Basis Selection among all Quantum Public Keys received from the HN for Hybrid QBER Check.
[0551] The number of qubits selected for the UE's Hybrid QBER Check can be predetermined for the entire quantum public key length. For example, the number of qubits corresponding to x% of the entire quantum public key length L can be selected randomly. The Qubit Index (or Quantum Public Key Index) selected for Hybrid QBER Check is can be expressed as . Here, I S is the Qubit Index Set selected for Hybrid QBER Check, and I is the Index Set of the entire Quantum Public Key.
[0552] The selection of the measurement basis for the Hybrid QBER Check of the UE determines which basis to use for the measurement of each of the above-selected qubits. Here, the type of basis can be agreed upon in advance between the transmitter and receiver. For example, let the quantum state of the quantum public key selected for the Hybrid QBER Check be the orthogonal basis of 0°, 90° or the diagonal basis of 45°, 135°, which represent four polarization states. The quantum state of the quantum public key selected for the Hybrid QBER Check is measured by randomly selecting either the orthogonal basis or the diagonal basis. The measurement basis of the quantum public key selected for the Hybrid QBER Check is can be expressed as . Here, B S is the measurement basis index set of the qubit selected for Hybrid QBER Check, + represents an orthogonal basis, and × represents a diagonal basis.
[0553] In the above, the random selection can be performed through a random number generator, etc., and the random number generator can generate a pure random number through a quantum random number generator, etc.
[0554]
[0555] 6. (UE) Qubit Measurement and Quantum Public Key Storage for Hybrid QBER Check
[0556] The UE measures the quantum public key selected for Hybrid QBER Check with the selected measurement basis, and the UE stores the quantum public key not selected for Hybrid QBER Check in the quantum memory.
[0557] UE selects Quantum Public Key Index Set I for Hybrid QBER Check above. S Quantum Public Key corresponding to is measured by the Basis Index Set B^S:
[0558]
[0559] Here, silver It means that the quantum state of B1 is measured by Qubit Rotation. That is, in terms of implementation, Initial State of When B1 is an orthogonal basis, if B1 corresponds to polarization 0°, is the Identity Operator, and if B1 is a diagonal basis, then for the polarization axis Here, Silver is selected I n The second Quantum Public Key B n As a result of measuring on the basis of am.
[0560] The UE is not selected for the Hybrid QBER Check in the Quantum Public Key Index Set above. Quantum Public Key corresponding to Store in Quantum Memory.
[0561]
[0562] 7. (UE) Encryption of Hybrid QBER Check Information
[0563] The UE encrypts the Quantum Public Key Index information and measurement basis information selected for Hybrid QBER Check based on the Classical Public Key previously shared and updated with HN.
[0564] UE1. (HN-UE) A reliable way to share and update Classical Public Keys shared and updated by HN. Based on 5. (UE) The Qubit for Hybrid QBER Check and the Quantum Public Key Index information and the Measurement Basis information selected in Measurement Basis Selection are encrypted. At this time, the encryption method uses the Classical Public Key Encryption method agreed upon in advance. Encrypted Hybrid QBER Check Information: is obtained. Here, Is Ro I S Wow B S This means that it has been encrypted, and I S Wow B S 5. (UE) Information Vector that includes the Qubit for Hybrid QBER Check and the Quantum Public Key Index Set information selected for Hybrid QBER Check in Measurement Basis Selection, and the entire Measurement Basis Set information of the Quantum Public Key selected for Hybrid QBER Check: .
[0565]
[0566] 8. (UE-HN) Hybrid QBER Check Packet Transmission
[0567] FIG. 32 is a diagram illustrating an example of a Hybrid QBER Check Packet structure in a system applicable to the present disclosure.
[0568] The UE transmits a Hybrid QBER Check Packet containing Encrypted Hybrid QBER Check Information to the HN through a classical channel.
[0569] (1) When transmitting a Hybrid QBER Check Packet through a classical channel, the structure of the Hybrid QBER Check Packet is as shown in Figure 32.
[0570] (1-1) Hybrid QBER Check Packet consists entirely of classical information and can be composed of RF signals or optical signals.
[0571] (1-1-1) For example, ON / Off Keying (OOK) or Phase / Amplitude / Polarization Modulation methods can be used.
[0572] (1-1-2) The fields of the Hybrid QBER Check Packet can have a field size that is agreed upon in advance between the transmitter and receiver.
[0573] (1-2) Protection Scheme ID is a field that indicates the encryption method of the Encrypted Hybrid QBER Check Information of the Hybrid QBER Check Packet.
[0574] (1-2-1) An identifier for an encryption method that encrypts / decrypts the Encrypted Hybrid QBER Check Information of the Hybrid QBER Check Packet. The encryption methods are defined in advance.
[0575] (1-2-2) For example, the Protection Scheme Identifier of the SUCI structure of 3GPP TS 33.501 can be followed. (3GPP TS 23.003 2.2B and 33.501 Annex C.1)
[0576] (1-2-3) The encryption method can be predefined and shared in HN.
[0577] (1-2-4) Protection Scheme ID may not be used if it is agreed upon between the sender and receiver in a single manner.
[0578] (1-2-5) Protection Scheme ID can be set to the default value 0 if it is agreed upon between the transmitter and receiver in a single manner.
[0579] (1-3) Home Network Public Key ID is a field that indicates the Classical Public Key ID used in the Encrypted Hybrid QBER Check Information of the Hybrid QBER Check Packet.
[0580] (1-3-1) This identifies the Classical Public Key of the Home Network and indicates which key among the Classical Public Keys was used.
[0581] (1-3-2) For example, the Home Network Public Key Identifier of the SUCI structure of 3GPP TS 33.501 can be followed. (3GPP TS 23.003 2.2B)
[0582] (1-4) Encrypted Hybrid QBER Check Information is a data field for Hybrid QBER Check Information encrypted by HN's Classical Public Key using an encryption technique corresponding to the Protection Scheme ID.
[0583] (1-4-1) Encrypted Hybrid QBER Check Information is HN’s Classical Public Key Hybrid QBER Check Information encrypted by Contains information.
[0584]
[0585] 9. (HN) Decryption of Hybrid QBER Check Information
[0586] HN decrypts the Hybrid QBER Check Packet received from the UE to obtain Hybrid QBER Check Information.
[0587] Based on the Home Network Public Key ID of the Hybrid QBER Check Packet, HN decrypts the encrypted Hybrid QBER Check Information using the Classical Private Key corresponding to the Trapdoor of the Classical Public Key held by HN. At this time, the decryption method is performed based on the Protection Scheme ID of the Hybrid QBER Check Packet.
[0588] For example, Encrypted Hybrid QBER Check Information Is Private Key, which is Trapdoor Decryption by Quantum Public Key Index information I selected by the UE corresponding to Hybrid QBER Check Information S and Measurement Basis Information B S Obtain .
[0589]
[0590] 10. (HN) Basis Matching for Hybrid QBER Check
[0591] HN selects quantum public keys using the same basis based on the Hybrid QBER Check Information of the Hybrid QBER Check Packet received from the UE, compared with the quantum public key generation information, and defines the quantum state of the selected quantum public key as bit information.
[0592] Since HN possesses accurate information about the quantum state of each quantum public key during the quantum public key generation phase, it compares the basis information of the generated quantum public key corresponding to the quantum public key index of the Hybrid QBER Check Information received from the UE with the measured basis information of the Hybrid QBER Check Information. If the same basis is selected and transmitted from the UE, it determines that the basis of HN and the UE match and selects the matching quantum public key index:
[0593]
[0594] Here, I Mis an index set of Hybrid QBER Check Information with matching basis, and I S is the Qubit Index Set selected for Hybrid QBER Check. Silver I S Among them, I of the Qubit with matching basis S It means the index within the set. For example, If, When, am.
[0595] Since HN has accurate information about the quantum state of each quantum public key at the stage of generating a quantum public key, it defines the measurement information (or quantum state information) of the matched quantum public key as a bit message as in the following mathematical expression 4:
[0596]
[0597] Here, is a Bit Message of the Quantum Public Key with a Matched Basis.
[0598] For example, when the above Quantum Public Key is composed of four polarization states of 0°, 45°, 90°, and 135°, 0° of the orthogonal basis is defined as Bit 0, 90° as Bit 1, 45° of the diagonal basis is defined as Bit 0, and 135° as Bit 1. Then, And, When, am.
[0599]
[0600] 11. (HN-UE) Hybrid QBER Check Response Packet
[0601] HN transmits a Hybrid QBER Check Response Packet containing the Quantum Public Key Index using the same Basis and the Bit information of the Quantum Public Key using the same Basis to the UE through the classical channel.
[0602] Hybrid QBER Check Response Packet is 10. (HN) Index information of Hybrid QBER Check Information whose basis is matched in Basis Matching for Hybrid QBER Check Bit Message of Quantum Public Key Matched with Includes Hybrid QBER Check Response Packet. S Since the matching index in the set has been redefined, I S Except for the UE that generated the information of HN and I^S that can decrypt the information, the corresponding Quantum Public Key Index cannot be confirmed within X hours, so it can be transmitted through a public channel without separate encryption.
[0603] Index information of Hybrid QBER Check Information whose basis is matched in the Hybrid QBER Check Response Packet above Bit Message of Quantum Public Key Matched with Additional security can be provided through separate encryption. In this case, since the HN encrypts and the UE decrypts, the encryption method for separate encryption may be private key-based rather than public key-based. In this case, similar to the Hybrid QBER Check Packet, the Protection Scheme ID information and HN Public Key ID can be transmitted together.
[0604]
[0605] 12. (UE) Hybrid QBER Check
[0606] The UE performs Hybrid QBER Check based on the Hybrid QBER Check Response Packet received from the HN.
[0607] (1) The UE checks whether the Hybrid QBER Check Response Packet has been received within the Hybrid QBER Check Time τ predefined in the system.
[0608] (2) The UE performs QBER Estimation and checks whether the QBER is within the QBER Threshold β predefined in the system.
[0609] If both of the above conditions are satisfied, the UE determines that the Quantum Public Key of the HN received in 2.1.4 is valid.
[0610] If the UE determines that the HN's Quantum Public Key received in 2.1.4 is valid, it transmits the HN a validation result indication signal of 'OK' to the Quantum Channel or Classical Channel.
[0611] If the UE does not satisfy either of the above two conditions, it determines that the Quantum Public Key of the HN received in 2.1.4 is invalid, and transmits the validation result indication signal to the HN as 'Not-OK' through the Quantum Channel or Classical Channel.
[0612] If the UE determines that the Quantum Public Key of the HN received in 2.1.4 is invalid, it discards the Quantum Public Key and restarts the QPKI Protocol.
[0613]
[0614] In the above, the UE uses the Index information I of the Hybrid QBER Check Information with Basis Matched in the Hybrid QBER Check Response Packet for QBER Estimation. M Based on I S The Quantum Public Key Index is verified using the following mathematical formula 5:
[0615]
[0616] UE6. (UE) Measurement information for Hybrid QBER Check and Qubit Measurement and Quantum Public Key Storage, where the basis is matched to the measured information. Bit Message of Matched Quantum Public Key of Hybrid QBER Check Response Packet Compare. The entire basis is compared with the matched message and measurement information, and if the value is different, it is recorded as an error. QBER is defined as the number of errors among the total number of matched basis, as shown in the following mathematical equation 6:
[0617]
[0618] Index information of Hybrid QBER Check Information whose basis matches in the Hybrid QBER Check Response Packet received by the UE above Bit Message of Quantum Public Key Matched with If the HN is encrypted with the Private Key to provide additional security, the UE performs Decryption based on the Public Key of the HN to obtain information for Hybrid QBER Check.
[0619]
[0620] In the above 5. (UE) Hybrid QBER Check for Qubit and Measurement Basis Selection, the Hybrid QBER Check process of 12. (UE) Hybrid QBER Check is explained from the perspective of a single qubit based quantum public key, but it is self-evident that it can be performed based on the same procedure even when an entanglement based quantum public key is used.
[0621]
[0622] Example) When determining the validity of a Quantum Public Key by using 4 Qubits out of 8 Quantum Public Keys for Hybrid QBER Check
[0623]
[0624] Referring to Table 3, Alice (HN) generates 8 Quantum Public Keys, and each Quantum Public Key is generated in an orthogonal (+) or diagonal (x) basis, and is defined as follows: if it is horizontal, the message is 0, if it is vertical, the message is 1, if it is +45°, the message is 0, and if it is -45° (or 135°), the message is 1.
[0625] Bob (UE) selects Index {2, 4, 6, 7} for Hybrid QBER Check, and selects Basis {+, +, x, x} for the selected Index, and the result of measuring the quantum state is {0, 1, 0, 1}.
[0626] FIG. 33 is a diagram illustrating an example of information transmission for Hybrid QBER Check in a system applicable to the present disclosure.
[0627] Bob encrypts the Index information {2, 4, 6, 7} and Basis information {+, +, x, x} selected for Hybrid QBER Check using the Classical Public Key and sends them to Alice.
[0628] Alice decrypts the information received from Bob using the Classical Private Key to obtain the Index information {2, 4, 6, 7} and the Basis information {+, +, x, x}.
[0629] Alice compares the Index information {2, 4, 6, 7} and Basis information {+, +, x, x} with the 8 Quantum Public Key information Alice generated, selects Index {2, 6} that uses the same Basis, and derives Message information {0, 0}.
[0630] Alice derives a new index information {1, 3} corresponding to Index {2, 6} using the same basis from the index information transmitted by Bob.
[0631] Alice sends the derived Index information {1, 3} and Message information {0, 0} to Bob.
[0632] Based on the Index information {1, 3} received from Alice, Bob selects the first and third Indexes {2, 6} from the Index information {2, 4, 6, 7} sent to Alice.
[0633] Bob performs QBER Estimation by comparing the message information {0, 0} received from Alice with the quantum state measurement information {0, 0} corresponding to the selected Index {2, 6} (QBER=0).
[0634] While the above example assumes an error-free quantum channel environment, it is clear that the system can be designed to include errors that may occur in real-world environments. For example, the system can be configured to determine that the quantum public key is intact if the Hybrid QBER is below a certain threshold β.
[0635]
[0636] 13. (UE) Quantum Public Key-based Data Encryption
[0637] FIG. 34 is a diagram illustrating an example of modulation by Qubit Rotation in a system applicable to the present disclosure.
[0638] The UE encrypts the data it wants to transmit to the HN using the Quantum Public Key, which has been validated through Hybrid QBER Check.
[0639] (1) Single Qubit based Public Key & Entanglement based Public Key
[0640] (1-1) The UE receives the Quantum Public Key from the HN based on the Data d to be sent, and stores the Quantum Public Key that is not used for Hybrid QBER Check and is stored in the Quantum Memory. Data encryption is performed by modifying the following: Notation for Let me explain it in a simplified way.
[0641] (1-1) For example, Quantum Public Key When , modulate the Qubit Rotation corresponding to Data d: .
[0642] (1-1-1) Here, It means Unitary operation for Qubit Rotation.
[0643] (1-1-2) Here, Qubit Rotation is Quantum Public Key For the z-axis, if d is 0, no rotation occurs, and if it is 1, π rotation occurs.
[0644] (1-1-3) Here, d is assumed to be bit information, 0 or 1.
[0645] (1-1-4) In the above, Qubit Rotation is a Quantum Public Key It can be a Pauli Operation. Here, if d is 0, the Pauli Operation does not occur, and if it is 1, the Pauli Operation occurs.
[0646] (1-1-5) In the above, the Pauli Operation can be agreed upon in advance between the transmitter and receiver as one of X, Y, and Z.
[0647] In the same way, all Quantum Public Keys About each Data can be modified. Here, i is the index of the Data Index and the Quantum Public Key.
[0648] Here, Data Encryption can be set differently in a pre-arranged manner.
[0649] Here, data encryption can be set differently depending on the type of Quantum Public Key in a pre-agreed manner.
[0650]
[0651] 14. (UE-HN) Transmission of Quantum Public Key Encrypted (QPKE) Packets
[0652] The UE transmits a Quantum Public Key Encrypted (QPKE) Packet containing encrypted data to the HN via a quantum channel or via a classical channel and a quantum channel.
[0653] FIG. 35 is a diagram illustrating an example of a QPKE Packet structure in a system applicable to the present disclosure.
[0654] (1) Quantum channel-based QPKE packet transmission
[0655] (1-1) Transmit a QPKE Packet containing control information and security information through a quantum channel.
[0656] (1-2) When transmitting a QPKE Packet through a quantum channel, the QPKE Packet structure is as shown in Fig. 35.
[0657] (1-2-1) All QPKE Packets are generated in Quantum State, and fields (Protection Scheme ID, Home Network Public Key ID) excluding Encrypted Data can be composed of Optical Signals. At this time, the Optical Signal can be an Optical Signal at the Single Photon level or a Field composed of Multiple Photons.
[0658] (1-2-1-1) Fields composed of optical signals do not require security, and signals can be composed in a way agreed upon in advance between the transmitter and receiver.
[0659] (1-2-1-2) For example, ON / Off Keying (OOK) or Phase / Amplitude / Polarization Modulation methods can be used.
[0660] (1-2-1-3) Fields composed of optical signals can have a field size defined in advance between the transmitter and receiver.
[0661] (1-2-2) Protection Scheme ID is a field that indicates the encryption method of the encrypted data of the QPKE Packet.
[0662] (1-2-2-1) Protection Scheme ID can be indicated by specifying a different encryption method.
[0663] (1-2-2-2) Protection Scheme ID can be made to function as a single identifier when the encryption method is specified in the same way.
[0664] (1-2-2-3) Protection Scheme ID can include the Type of Quantum Public Key.
[0665] (1-2-2-4) Protection Scheme ID may not be used if it is agreed upon between the sender and receiver in a single manner.
[0666] (1-2-2-5) Protection Scheme ID can be set to the default value 0 if it is agreed upon between the sender and receiver in a single manner.
[0667] (1-2-3) Home Network Public Key ID is a field that indicates the Quantum Public Key ID for the encrypted data of the QPKE Packet.
[0668] (1-2-3-1) Home Network Public Key ID represents the Quantum Public Key Index.
[0669] (1-2-3-1-1) If the Quantum Public Key used for Encrypted Data is composed of multiple Quantum States, it can indicate the first Index among the entire Quantum Public Key.
[0670] (1-2-3-1-2) If the Quantum Public Key used for Encrypted Data is composed of multiple Quantum States, it can represent the Index range of the entire Quantum Public Key.
[0671] (1-2-4) Encrypted Data is a data field encrypted with a Quantum Public Key expressed as a Home Network Public Key ID.
[0672] (1-2-4-1) This is a Quantum State that encrypts data using the encryption method indicated in the Protection Scheme ID using the Quantum Public Key.
[0673] (1-2-4-2) When multiple data are encrypted using multiple Quantum Public Keys, the encrypted data may be a Quantum State Stream.
[0674] (1-2-4-3) The Encrypted Data Field composed of Quantum State Stream can have a field size defined in advance between the sender and receiver.
[0675]
[0676] FIG. 36 is a diagram illustrating an example of a QPKE Control Packet structure in a system applicable to the present disclosure.
[0677] (2) QPKE Packet Transmission Based on Classical Channel and Quantum Channel
[0678] (2-1) A QPKE Control Packet that transmits control information related to a QPKE Packet is transmitted through a classical channel, and a QPKE Packet that contains only security information is transmitted through a quantum channel.
[0679] (2-2) When transmitting a QPKE Control Packet through a classic channel, the structure of the QPKE Control Packet is as shown in Figure 36.
[0680] (2-2-1) QPKE Control Packet consists entirely of classical information and can be composed of RF Signal or Optical Signal.
[0681] (2-2-1-1) The fields of the QPKE Control Packet are not information requiring security, and are control information transmitted in a method agreed upon in advance between the transmitter and receiver.
[0682] (2-2-1-2) For example, ON / Off Keying (OOK) or Phase / Amplitude / Polarization Modulation methods can be used.
[0683] (2-2-1-3) The fields of the QPKE Control Packet can have a field size that is agreed upon in advance between the transmitter and receiver.
[0684] (2-2-2) Synchronization Header is synchronization information for linking information with QPKE Control Packet transmitted through a classical channel and QPKE Packet transmitted through a quantum channel.
[0685] (2-2-2-1) The Synchronization Header of the QPKE Control Packet transmitted through the classical channel and the Synchronization Header of the QPKE Packet transmitted through the quantum channel consist of the same information.
[0686] (2-2-2-2) Synchronization Header can be a Synchronization Code promised in a predefined manner.
[0687] (2-2-2-2-1) For example, the Synchronization Code can be an Index indicating the order of the QPKE Packet, and the Synchronization Code can be defined as a Sequence structure that can be detected at the receiving end.
[0688] (2-2-2-2-2) Even though the Synchronization Code above is an index indicating the order of the QPKE Packet, it is defined as a Sequence structure with a length that can perform information separation among multiple users.
[0689] (2-2-2-3) Synchronization Header can be a randomly generated Synchronization Code.
[0690] (2-2-2-3-1) For example, it can be a sequence of random numbers generated through QRNG, etc.
[0691] (2-2-2-3-2) The length of the sequence consisting of random numbers corresponding to the synchronization code is agreed upon in advance between the transmitting and receiving ends.
[0692] (2-2-3) Protection Scheme ID is a field that indicates the encryption method of the encrypted data of the QPKE Packet controlled by the QPKE Control Packet.
[0693] (2-2-3-1) Protection Scheme ID can be displayed by specifying a different encryption method.
[0694] (2-2-3-2) Protection Scheme ID can be made to function as a single identifier when the encryption method is specified in the same way.
[0695] (2-2-3-3) Protection Scheme ID can include the Type of Quantum Public Key.
[0696] (2-2-3-4) Protection Scheme ID may not be used if it is agreed upon between the sender and receiver in a single manner.
[0697] (2-2-3-5) Protection Scheme ID can be set to the default value 0 if it is agreed upon between the transmitter and receiver in a single manner.
[0698] (2-2-4) Home Network Public Key ID is a field that indicates the Quantum Public Key ID for the encrypted data of the QPKE Packet controlled by the QPKE Control Packet.
[0699] (2-2-4-1) Home Network Public Key ID represents the Quantum Public Key Index.
[0700] (2-2-4-1-1) If the Quantum Public Key used for Encrypted Data is composed of multiple Quantum States, it can indicate the first Index among the entire Quantum Public Key.
[0701] (2-2-4-1-2) If the Quantum Public Key used for Encrypted Data is composed of multiple Quantum States, it can represent the Index range of the entire Quantum Public Key.
[0702]
[0703] FIG. 37 is a diagram illustrating an example of a QPKE Packet structure in a system applicable to the present disclosure.
[0704] (2-3) When transmitting a QPKE Packet through a quantum channel, the QPKE Packet structure is as shown in Fig. 37.
[0705] (2-3-1) All QPKE Packets are generated as Quantum States, and the Synchronization Header can be composed of an Optical Signal. At this time, the Optical Signal can be an Optical Signal at the Single Photon level or a Field composed of Multiple Photons.
[0706] (2-3-1-1) The Synchronization Header composed of an optical signal is not information requiring security, and the signal can be composed in a method agreed upon in advance between the transmitting and receiving ends.
[0707] (2-3-1-2) For example, ON / Off Keying (OOK) or Phase / Amplitude / Polarization Modulation methods can be used.
[0708] (2-3-2) Synchronization Header is synchronization information for linking information with QPKE Control Packet transmitted through a classical channel and QPKE Packet transmitted through a quantum channel.
[0709] (2-3-2-1) The Synchronization Header of the QPKE Control Packet transmitted through the classical channel and the Synchronization Header of the QPKE Packet transmitted through the quantum channel consist of the same information.
[0710] (2-3-2-2) Synchronization Header can be a Synchronization Code promised in a predefined manner.
[0711] (2-3-2-2-1) For example, the Synchronization Code can be an Index indicating the order of the QPKE Packet, and the Synchronization Code can be defined as a Sequence structure that can be detected at the receiving end.
[0712] (2-3-2-2-2) Even though the Synchronization Code above is an index indicating the order of the QPKE Packet, it is defined as a Sequence structure with a length that can perform information separation among multiple users.
[0713] (2-3-2-3) Synchronization Header can be a randomly generated Synchronization Code.
[0714] (2-3-2-3-1) For example, it can be a sequence of random numbers generated through QRNG, etc.
[0715] (2-3-2-3-2) The length of the sequence consisting of random numbers corresponding to the synchronization code is agreed upon in advance between the transmitting and receiving ends.
[0716] (2-3-3) Encrypted Data is a data field encrypted with a Quantum Public Key expressed as a Home Network Public Key ID.
[0717] (2-3-3-1) This is a Quantum State that encrypts data using the encryption method indicated in the Protection Scheme ID using the Quantum Public Key.
[0718] (2-3-3-2) When multiple data are encrypted using multiple Quantum Public Keys, the encrypted data may be a Quantum State Stream.
[0719] (2-3-3-3) The Encrypted Data Field composed of Quantum State Stream can have a field size defined in advance between the sender and receiver.
[0720]
[0721] 15. (HN) Decryption of Quantum Public Key Encrypted (QPKE) Packet
[0722] HN decrypts the encrypted data of the Quantum Public Key Encrypted (QPKE) Packet received through the quantum channel.
[0723] (1) Single Qubit based Public Key System
[0724] (1-1) When HN receives a quantum channel-based QPKE packet, it decrypts the public key information of the encrypted data into private key information based on the Protection Scheme ID and the Home Network Public Key ID. When the Home Network Public Key ID is i, HN decrypts the i-th Quantum Public Key Generation information (or Private Key) Because I know Compensation for Perform.
[0725] For example, if the Protection Scheme is Qubit Rotation, can be expressed as . Therefore, the received information to If you do, can be written as, In addition, in the case of the Qubit Rotation method, since the Qubit Rotation is commutative with respect to the same axis, it can be expressed as in the following mathematical expression 7.
[0726]
[0727] That is, as a decrypted quantum state, the initial state About the i-th Data information can be obtained. Therefore, by measuring the Decrypted quantum state, the Decrypted Data d_i can be obtained. In the same way, by performing Decryption and quantum state measurement on the entire Encrypted Data, the entire Data can be obtained.
[0728] (1-2) HN receives a QPKE Control Packet based on a classical channel, and when a QPKE Packet is received based on a quantum channel, it detects and compares the Synchronization Header of the QPKE Control Packet and the QPKE Packet, and ties packets with the same Synchronization Code.
[0729] Based on the Protection Scheme ID and Home Network Public Key ID of the QPKE Control Packet, the Quantum Public Key information of the encrypted data of the tied QPKE Packet is decrypted into Private Key information. When the Home Network Public Key ID is i, HN is the i-th Quantum Public Key Generation information (or Private Key) Because I know Compensation for Perform. By measuring the Decrypted quantum state compensated by , we can obtain the Decrypted Data d_i. In the same way, by performing Decryption and quantum state measurement on the entire Encrypted Data, we can obtain the entire Data.
[0730] (2) Entanglement based Public Key System
[0731] (2-1) When HN receives a quantum channel-based QPKE Packet, it decrypts the quantum public key information of the encrypted data into private key information based on the Protection Scheme ID and the Home Network Public Key ID. When the Home Network Public Key ID is i, HN decrypts the i-th quantum public key Generation information (or Private Key) Because I know Compensation for Perform.
[0732] For example, if the Protection Scheme is a Pauli Operation method, can be expressed as performing the same Pauli Operation. Therefore, the received information to If you do, can be written as, In addition, in the case of the Pauli Operation method, since the same Pauli Operation is commutative, it can be expressed as in the following mathematical expression 8.
[0733]
[0734] That is, as the first particle of the Decrypted Bell state, the first particle of the initial Bell State About the i-th Data information can be obtained. Therefore, the first Particle in the Decrypted Bell state The second particle corresponding to the Quantum Secret Key that HN possessed If measured by Bell State Measurement (BSM), Decrypted Data can be obtained. If Decryption and BSM are performed on the entire Encrypted Data in the same way, the entire Data can be obtained.
[0735] (2-2) HN receives a QPKE Control Packet based on a classical channel, and when a QPKE Packet is received based on a quantum channel, it detects and compares the Synchronization Header of the QPKE Control Packet and the QPKE Packet, and ties packets with the same Synchronization Code.
[0736] Based on the Protection Scheme ID and Home Network Public Key ID of the QPKE Control Packet, the Quantum Public Key information of the encrypted data of the tied QPKE Packet is decrypted into private key information. When the Home Network Public Key ID is i, HN is the i-th Public Key Generation information (or Private Key) Because I know Compensation for Perform. By performing BSM on the Quantum Secret Key corresponding to the first and second Particles of the Decrypted Bell state, the Decrypted Data d_i can be obtained. In the same way, by performing Decryption and BSM on the entire Encrypted Data, the entire Data can be obtained.
[0737]
[0738] FIG. 38 is a diagram illustrating an example of the operation of quantum channel and classical channel signals performed with Single Qubit based QPK in Hybrid QBER Check based Quantum Public Key Infrastructure (QPKI) in a system applicable to the present disclosure.
[0739] Alice generates a Classical Public Key (CP) using her Classical Private Key (CS) and shares it with Bob in advance through a trusted network (Provisioning).
[0740] (1) When Bob has a message (m) he wants to send, he requests Alice's Quantum Public Key.
[0741] (2) When Alice is asked for a Quantum Public Key from Bob, she generates a Quantum Public Key (p) using her Private Key (s) and sends it to Bob in real time.
[0742] (3) Bob selects Qubits (p2, p4) for Hybrid QBER Check from the entire Quantum Public Key and performs Hybrid QBER Check with Alice.
[0743] (3-1) Bob determines that the Hybrid QBER Check must be completed within the Hybrid QBER Check Time, and that the Quantum Public Key received from Alice is valid when QBER is within a specific threshold.
[0744] (4) If the Hybrid QBER Check passes, Bob encrypts the message (m1, m2) with the quantum public key (p1, p3) that was not used in the Hybrid QBER Check.
[0745] (5) Alice compensates for the information of the Quantum Public Key (p1, p3) using the Private Key (s1, s3) for the Encrypted Message among the received signals, leaving only the Message (m1, m2) information.
[0746] (6) Alice obtains the target Message (m) information by measuring the quantum state that only leaves the Message (m1, m2) information.
[0747]
[0748] FIG. 39 is a flowchart illustrating the entire process of Hybrid QBER Check based Quantum Public Key Infrastructure (QPKI) in a system applicable to the present disclosure.
[0749] Alice generates a Classical Public Key using her Classical Private Key.
[0750] Alice and Bob share a classic public key via a certificated infrastructure.
[0751] Alice receives a Request Quantum Public Key from Bob.
[0752] Alice performs QPK Generation.
[0753] Alice performs Transmit Quantum Public Key to Bob.
[0754] Alice and Bob perform a Hybrid QBER Check.
[0755] Bob performs basis selection based on the selected index and selected basis.
[0756] Bob performs a Measurement and then Store Unselected QPK.
[0757] Bob performs basis encryption.
[0758] Alice receives a Hybrid QBER Check Packet from Bob.
[0759] Alice performs basis decryption.
[0760] Alice performs basis matching.
[0761] Alice sends a Hybrid QBER Check Response Packet to Bob.
[0762] Bob determines the QBER Check Time and whether the QBER condition is met. If the condition is not met, the protocol restarts. (If NOT, Protocol Restart)
[0763] Bob sends Alice the result of the QPK validation based on the QBER Check Time and whether the QBER conditions are satisfied.
[0764] Bob performs message encryption via a plaintext message.
[0765] Alice receives a QPKE packet from Bob.
[0766] Alice performs message decryption.
[0767] Alice performs message detection.
[0768] Alice sends an ACK to Bob.
[0769]
[0770] The QPKE Control Packet or QPKE Packet mentioned in this disclosure is described in terms of the relationship between a UE and an HN, but it is self-evident that it can be applied in the same manner between nodes of the same level. For example, the UE can be Node A, and the HN can be Node B, and they can configure Quantum Public Key Encrypted Packets in the same manner to exchange Encapsulated & Encrypted Data. In this case, the Home Network Public Key ID can be renamed and operated as the Public Key ID of the other Node.
[0771] In this disclosure, all general signal information transmitted via classical channels can also be transmitted via quantum channels. However, unlike information transmitted via quantum channels, information that can be transmitted via classical channels may not have physical security requirements.
[0772] In the Hybrid QBER Check-based Quantum Public Key Infrastructure System proposed in this disclosure, the Classical Public Key System is not limited to encryption methods based on Public Key Encryption, such as RSA (RIVEST-SHAMIR-ADLEMAN) or ECC (Elliptic Curve Cryptography). It is self-evident that the Classical Public Key System in the proposed Quantum Public Key Infrastructure System can correspond to any encryption method utilizing asymmetric keys. For example, it is self-evident that the same method can be applied to the Post Quantum Cryptography (PQC) encryption method developed to counter quantum algorithms.
[0773]
[0774] Effects of various embodiments of the present disclosure
[0775] The expected effects of various embodiments of the present disclosure are as follows.
[0776] (1) You can share QPK and configure a QPKI system using QPKE.
[0777] (2) Physical security is provided through QPK to counter threats to existing PKI systems caused by quantum algorithms.
[0778] (2-1) Even without an ideal assumption on quantum memory, the MitM attack problem on QPKE is prevented by verifying the validity of the quantum public key through the Hybrid QBER Check process.
[0779] (2-2) Physically defend against HNDL Attack by performing QPKE based on a valid Quantum Public Key.
[0780] (3) Physical security is provided through QPKI for the transmission of subscriber identity information in existing communication systems.
[0781] (4) Define Data Field and Signaling to operate in 3GPP Standard.
[0782]
[0783] Characteristic configurations of various embodiments of the present disclosure are as follows.
[0784] (1) Hybrid QBER Check Procedure
[0785] (2) Hybrid QBER Check Packet and Hybrid QBER Check Response Packet and Linking Procedure
[0786] (3) Quantum Public Key Validity Determination Procedure by Hybrid QBER Check
[0787] (4) Method and procedure for performing encryption using a valid quantum public key
[0788]
[0789] [Description of the first node claim]
[0790] The embodiments described below are specifically described with reference to FIG. 40 in terms of the operation of the first node. The methods described below are distinguished for convenience of explanation, and it is understood that some components of one method may be substituted for or combined with some components of another method, as long as they are not mutually exclusive.
[0791] FIG. 40 is a diagram illustrating an example of the operation process of the first node in a system applicable to the present disclosure.
[0792] According to various embodiments of the present disclosure, a method performed by a first node in a communication system is provided.
[0793] According to various embodiments of the present disclosure, each of the first node and the second node may correspond to either a terminal or a base station in a wireless communication system. According to various embodiments of the present disclosure, the first node may correspond to either Alice, HN, or BS.
[0794] The embodiment of FIG. 40 may further include, before step S4001, one or more of the following steps: a step in which the first node transmits one or more synchronization signals to the second node; a step in which the first node transmits system information to the second node; a step in which the first node transmits configuration information to the second node; and a step in which the first node transmits control information to the second node.
[0795] The embodiment of FIG. 40 may further include, before step S4001, one or more of the following steps: a first node receiving a random access preamble from a second node; a first node transmitting a random access response (RAR) to the second node; a first node receiving a random access message 3 from the second node; and a first node transmitting a contention resolution message to the second node. Message 3 is a first PUSCH transmission scheduled by RAR together with an RAR UL grant.
[0796] In step S4001, the first node sends a quantum public key (QPK) based on a private key to the second node.
[0797] In step S4002, the first node receives a hybrid QBER check packet related to the result of a hybrid QBER check (hybrid quantum bit error rate check) for the first qubits among the plurality of qubits constituting the QPK from the second node.
[0798] In step S4003, the first node decrypts the hybrid QBER check packet with a classical private key to generate basis matching information of the QPK.
[0799] At step S4004, the first node transmits a hybrid QBER check response packet based on the base matching information to the second node.
[0800] In step S4005, the first node receives a verification result of the validity of the QPK from the second node based on the base matching information.
[0801] In step S4006, the first node receives an encrypted message from the second node based on the validity of the QPK, based on second qubits among the plurality of qubits that are not used in the hybrid QBER check.
[0802]
[0803] According to various embodiments of the present disclosure, the basis matching information may be based on whether the basis information of the generated quantum public key corresponding to the quantum public key index of the hybrid QBER test information matches the measured basis information of the hybrid QBER test information.
[0804] According to various embodiments of the present disclosure, the hybrid QBER check information may be based on decryption of the hybrid QBER check packet.
[0805] According to various embodiments of the present disclosure, the validity of the QPK may be based on a comparison of the result of the hybrid QBER check reported in the hybrid QBER check response packet with a predefined threshold value.
[0806] According to various embodiments of the present disclosure, the embodiment of FIG. 40 may further include a step of discarding the QPK and transmitting a newly generated second QPK to the second node when the hybrid QBER check response packet indicates a QBER greater than a predetermined threshold value.
[0807] According to various embodiments of the present disclosure, the embodiment of FIG. 40 may further include a step of obtaining information of the message based on the private key.
[0808] According to various embodiments of the present disclosure, decryption of the encrypted message may be based on compensation via the private key for information of the second qubits.
[0809]
[0810] According to various embodiments of the present disclosure, a first node is provided in a communication system. The first node includes a transceiver and at least one processor, wherein the at least one processor may be configured to perform the operating method of the first node according to FIG. 40.
[0811]
[0812] According to various embodiments of the present disclosure, a device for controlling a first node in a communication system is provided. The device includes at least one processor and at least one memory operably connected to the at least one processor. The at least one memory may be configured to store instructions for performing an operating method of the first node according to FIG. 40 based on instructions executed by the at least one processor.
[0813]
[0814] According to various embodiments of the present disclosure, one or more non-transitory computer-readable media (CRM) storing one or more instructions are provided. The one or more instructions, when executed by one or more processors, perform operations, and the operations may include the operating method of the first node according to FIG. 40.
[0815]
[0816] [Description of the second node claim]
[0817] The embodiments described below are specifically described with reference to FIG. 41 in terms of the operation of the second node. The methods described below are distinguished for convenience of explanation, and it is understood that some components of one method may be substituted for or combined with some components of another method, as long as they are not mutually exclusive.
[0818] FIG. 41 is a diagram illustrating an example of the operation process of a second node in a system applicable to the present disclosure.
[0819] According to various embodiments of the present disclosure, a method performed by a second node in a communication system is provided.
[0820] According to various embodiments of the present disclosure, each of the first node and the second node may correspond to either a terminal or a base station in a wireless communication system. According to various embodiments of the present disclosure, the second node may correspond to either Bob or a UE.
[0821] The embodiment of FIG. 41 may further include, before step S4101, one or more of the following steps: a step in which the second node receives one or more synchronization signals from the first node; a step in which the second node receives system information from the first node; a step in which the second node receives configuration information from the first node; and a step in which the second node receives control information from the first node.
[0822] The embodiment of FIG. 41 may further include, before step S4101, one or more of the following steps: a step in which the second node transmits a random access preamble to the first node; a step in which the second node receives a random access response (RAR) from the first node; a step in which the second node transmits a random access message 3 to the first node; and a step in which the second node receives a contention resolution message from the first node. Message 3 is a first PUSCH transmission scheduled by RAR together with an RAR UL grant.
[0823] At step S4101, the second node receives a quantum public key (QPK) based on a private key from the first node.
[0824] In step S4102, the second node transmits a hybrid QBER check packet related to the result of a hybrid QBER check (hybrid quantum bit error rate check) for the first qubits among the plurality of qubits constituting the QPK to the first node.
[0825] At step S4103, the second node receives a hybrid QBER check response packet based on the basis matching information of the QPK from the first node.
[0826] At step S4104, the second node verifies the validity of the QPK based on the hybrid QBER check response packet.
[0827] In step S4105, the second node transmits the result of verification of the validity of the QPK to the first node.
[0828] In step S4106, the second node transmits an encrypted message to the first node based on the second qubits that are not used in the hybrid QBER check among the plurality of qubits, based on the validity of the QPK.
[0829] According to various embodiments of the present disclosure, the base matching information is generated by classical private key-based decryption of the hybrid QBER check packet.
[0830]
[0831] According to various embodiments of the present disclosure, the basis matching information may be based on whether the basis information of the generated quantum public key corresponding to the quantum public key index of the hybrid QBER test information matches the measured basis information of the hybrid QBER test information.
[0832] According to various embodiments of the present disclosure, the hybrid QBER check information may be based on decryption of the hybrid QBER check packet.
[0833] According to various embodiments of the present disclosure, the validity of the QPK may be based on a comparison of the result of the hybrid QBER check reported in the hybrid QBER check response packet with a predefined threshold value.
[0834] According to various embodiments of the present disclosure, the embodiment of FIG. 41 may further include a step of discarding the QPK and receiving a newly generated second QPK from the second node if the hybrid QBER check response packet indicates a QBER greater than a predetermined threshold value.
[0835] According to various embodiments of the present disclosure, decoding of the message can be performed based on the private key.
[0836] According to various embodiments of the present disclosure, decryption of the encrypted message may be based on compensation via the private key for information of the second qubits.
[0837]
[0838] According to various embodiments of the present disclosure, a second node is provided in a communication system. The second node includes a transceiver and at least one processor, wherein the at least one processor may be configured to perform the operating method of the second node according to FIG. 41.
[0839]
[0840] According to various embodiments of the present disclosure, a device for controlling a first node in a communication system is provided. The device includes at least one processor and at least one memory operably connected to the at least one processor. The at least one memory may be configured to store instructions for performing an operating method of a second node according to FIG. 41 based on instructions executed by the at least one processor.
[0841]
[0842] According to various embodiments of the present disclosure, one or more non-transitory computer-readable media (CRM) storing one or more instructions are provided. The one or more instructions, when executed by one or more processors, perform operations, and the operations may include the operating method of a second node according to FIG. 41.
[0843]
[0844] Communication system applicable to the present disclosure
[0845] FIG. 42 illustrates a communication system (1) applicable to various embodiments of the present disclosure.
[0846] Referring to FIG. 42, a communication system (1) applicable to various embodiments of the present disclosure includes a wireless device, a base station, and a network. Here, the wireless device refers to a device that performs communication using a wireless access technology (e.g., 5G NR (New RAT), LTE (Long Term Evolution), 6G wireless communication), and may be referred to as a communication / wireless / 5G device / 6G device. Although not limited thereto, the wireless device may include a robot (100a), a vehicle (100b-1, 100b-2), an XR (eXtended Reality) device (100c), a hand-held device (100d), a home appliance (100e), an IoT (Internet of Things) device (100f), and an AI device / server (400). For example, the vehicle may include a vehicle equipped with a wireless communication function, an autonomous vehicle, a vehicle capable of performing vehicle-to-vehicle communication, etc. Here, the vehicle may include an Unmanned Aerial Vehicle (UAV) (e.g., a drone). XR devices include AR (Augmented Reality) / VR (Virtual Reality) / MR (Mixed Reality) devices, and may be implemented in the form of a Head-Mounted Device (HMD), a Head-Up Display (HUD) installed in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, digital signage, a vehicle, a robot, etc. Mobile devices may include a smartphone, a smart pad, a wearable device (e.g., a smart watch, smart glasses), a computer (e.g., a laptop, etc.), etc. Home appliances may include a TV, a refrigerator, a washing machine, etc. IoT devices may include a sensor, a smart meter, etc. For example, a base station and a network may also be implemented as a wireless device, and a specific wireless device (200a) may act as a base station / network node to other wireless devices.
[0847] Wireless devices (100a to 100f) can be connected to a network (300) via a base station (200). Artificial Intelligence (AI) technology can be applied to the wireless devices (100a to 100f), and the wireless devices (100a to 100f) can be connected to an AI server (400) via the network (300). The network (300) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, or a 6G network. The wireless devices (100a to 100f) can communicate with each other via the base station (200) / network (300), but can also communicate directly (e.g., sidelink communication) without going through the base station / network. For example, vehicles (100b-1, 100b-2) can communicate directly (e.g., V2V (Vehicle to Vehicle) / V2X (Vehicle to Everything) communication). In addition, IoT devices (e.g., sensors) can communicate directly with other IoT devices (e.g., sensors) or other wireless devices (100a to 100f).
[0848] Wireless communication / connection (150a, 150b, 150c) can be established between wireless devices (100a~100f) / base stations (200), and base stations (200) / base stations (200). Here, wireless communication / connection can be achieved through various wireless access technologies (e.g., 5G NR) such as uplink / downlink communication (150a), sidelink communication (150b) (or D2D communication), and communication between base stations (150c) (e.g., relay, IAB (Integrated Access Backhaul). Through wireless communication / connection (150a, 150b, 150c), wireless devices and base stations / wireless devices, and base stations and base stations can transmit / receive wireless signals to each other. For example, wireless communication / connection (150a, 150b, 150c) can transmit / receive signals through various physical channels. To this end, at least some of various configuration information setting processes for transmitting / receiving wireless signals, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), and resource allocation processes can be performed based on various proposals of various embodiments of the present disclosure.
[0849] Meanwhile, NR supports multiple numerologies (or subcarrier spacing (SCS)) to support various 5G services. For example, an SCS of 15 kHz supports a wide area in traditional cellular bands; an SCS of 30 kHz / 60 kHz supports dense urban areas, lower latency, and wider carrier bandwidth; and an SCS of 60 kHz or higher supports a bandwidth greater than 24.25 GHz to overcome phase noise.
[0850] The NR frequency band can be defined by two types of frequency ranges (FR1, FR2). The numerical values of the frequency ranges can be changed, and for example, the frequency ranges of the two types (FR1, FR2) can be as shown in Table 4 below. For convenience of explanation, among the frequency ranges used in the NR system, FR1 can mean the "sub 6 GHz range", and FR2 can mean the "above 6 GHz range" and can be called millimeter wave (mmW).
[0851]
[0852] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR1450MHz-6000MHz15, 30, 60kHzFR224250MHz-52600MHz60, 120, 240kHz
[0853] As described above, the numerical value of the frequency range of the NR system can be changed. For example, FR1 may include a band from 410 MHz to 7125 MHz, as shown in Table 5 below. That is, FR1 may include a frequency band above 6 GHz (or 5850, 5900, 5925 MHz, etc.). For example, the frequency band above 6 GHz (or 5850, 5900, 5925 MHz, etc.) included within FR1 may include an unlicensed band. The unlicensed band may be used for various purposes, such as for vehicular communications (e.g., autonomous driving).
[0854] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR141MHz-7125MHz15, 30, 60kHzFR224250MHz-52600MHz60, 120, 240kHz
[0855] According to various embodiments of the present disclosure, the communication system (1) can support terahertz (THz) wireless communication. THz wireless communication is a wireless communication using THz waves having a frequency of approximately 0.1 to 10 THz (1 THz = 1012 Hz), and may refer to terahertz (THz) band wireless communication using a very high carrier frequency of 100 GHz or higher. The frequency band expected to be used for THz wireless communication may be a D-band (110 GHz to 170 GHz) or H-band (220 GHz to 325 GHz) band where propagation loss due to absorption of molecules in the air is small.
[0856]
[0857] Wireless devices applicable to the present disclosure
[0858] Below, examples of wireless devices to which various embodiments of the present disclosure are applied are described.
[0859] FIG. 43 illustrates a wireless device that can be applied to various embodiments of the present disclosure.
[0860] Referring to FIG. 43, the first wireless device (100) and the second wireless device (200) can transmit and receive wireless signals via various wireless access technologies (e.g., LTE, NR). Here, {the first wireless device (100), the second wireless device (200)} can correspond to {the wireless device (100x), the base station (200)} and / or {the wireless device (100x), the wireless device (100x)} of FIG. 42.
[0861] A first wireless device (100) includes one or more processors (102) and one or more memories (104), and may further include one or more transceivers (106) and / or one or more antennas (108). The processor (102) controls the memories (104) and / or the transceivers (106), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this document. For example, the processor (102) may process information in the memory (104) to generate first information / signal, and then transmit a wireless signal including the first information / signal via the transceiver (106). In addition, the processor (102) may receive a wireless signal including second information / signal via the transceiver (106), and then store information obtained from signal processing of the second information / signal in the memory (104). The memory (104) may be connected to the processor (102) and may store various information related to the operation of the processor (102). For example, the memory (104) may perform some or all of the processes controlled by the processor (102), or may store software code including commands for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. Here, the processor (102) and the memory (104) may be part of a communication modem / circuit / chip designed to implement a wireless communication technology (e.g., LTE, NR). The transceiver (106) may be connected to the processor (102) and may transmit and / or receive wireless signals via one or more antennas (108). The transceiver (106) may include a transmitter and / or a receiver. The transceiver (106) may be used interchangeably with an RF (Radio Frequency) unit. In various embodiments of the present disclosure, a wireless device may mean a communication modem / circuit / chip.
[0862] The second wireless device (200) includes one or more processors (202), one or more memories (204), and may further include one or more transceivers (206) and / or one or more antennas (208). The processor (202) controls the memories (204) and / or the transceivers (206), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this document. For example, the processor (202) may process information in the memory (204) to generate third information / signals, and then transmit a wireless signal including the third information / signals via the transceivers (206). Furthermore, the processor (202) may receive a wireless signal including fourth information / signals via the transceivers (206), and then store information obtained from signal processing of the fourth information / signals in the memory (204). The memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, the memory (204) may perform some or all of the processes controlled by the processor (202), or may store software code including commands for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. Here, the processor (202) and the memory (204) may be part of a communication modem / circuit / chip designed to implement wireless communication technology (e.g., LTE, NR). The transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals via one or more antennas (208). The transceiver (206) may include a transmitter and / or a receiver. The transceiver (206) may be used interchangeably with an RF unit. In various embodiments of the present disclosure, a wireless device may also mean a communication modem / circuit / chip.
[0863] Hereinafter, the hardware elements of the wireless device (100, 200) will be described in more detail. Although not limited thereto, one or more protocol layers may be implemented by one or more processors (102, 202). For example, one or more processors (102, 202) may implement one or more layers (e.g., functional layers such as PHY, MAC, RLC, PDCP, RRC, SDAP). One or more processors (102, 202) may generate one or more Protocol Data Units (PDUs) and / or one or more Service Data Units (SDUs) according to the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. One or more processors (102, 202) may generate messages, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. One or more processors (102, 202) can generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data or information according to the functions, procedures, proposals and / or methods disclosed herein, and provide the signals to one or more transceivers (106, 206). One or more processors (102, 202) can receive signals (e.g., baseband signals) from one or more transceivers (106, 206) and obtain PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed herein.
[0864] One or more processors (102, 202) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer. One or more processors (102, 202) may be implemented by hardware, firmware, software, or a combination thereof. For example, one or more Application Specific Integrated Circuits (ASICs), one or more Digital Signal Processors (DSPs), one or more Digital Signal Processing Devices (DSPDs), one or more Programmable Logic Devices (PLDs), or one or more Field Programmable Gate Arrays (FPGAs) may be included in one or more processors (102, 202). The descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this document may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. The descriptions, functions, procedures, suggestions, methods and / or operation flowcharts disclosed in this document may be implemented using firmware or software configured to perform one or more processors (102, 202) or stored in one or more memories (104, 204) and executed by one or more processors (102, 202). The descriptions, functions, procedures, suggestions, methods and / or operation flowcharts disclosed in this document may be implemented using firmware or software in the form of codes, instructions and / or sets of instructions.
[0865] One or more memories (104, 204) may be coupled to one or more processors (102, 202) and may store various forms of data, signals, messages, information, programs, codes, instructions, and / or commands. The one or more memories (104, 204) may be configured as ROM, RAM, EPROM, flash memory, hard drives, registers, cache memory, computer-readable storage media, and / or combinations thereof. The one or more memories (104, 204) may be located internally and / or externally to the one or more processors (102, 202). Additionally, the one or more memories (104, 204) may be coupled to the one or more processors (102, 202) via various technologies, such as wired or wireless connections.
[0866] One or more transceivers (106, 206) can transmit user data, control information, wireless signals / channels, etc., as mentioned in the methods and / or flowcharts of this document, to one or more other devices. One or more transceivers (106, 206) can receive user data, control information, wireless signals / channels, etc., as mentioned in the descriptions, functions, procedures, proposals, methods and / or flowcharts of this document, from one or more other devices. For example, one or more transceivers (106, 206) can be connected to one or more processors (102, 202) and can transmit and receive wireless signals. For example, one or more processors (102, 202) can control one or more transceivers (106, 206) to transmit user data, control information, or wireless signals to one or more other devices. Additionally, one or more processors (102, 202) may control one or more transceivers (106, 206) to receive user data, control information, or wireless signals from one or more other devices. Additionally, one or more transceivers (106, 206) may be coupled to one or more antennas (108, 208), and one or more transceivers (106, 206) may be configured to transmit and receive user data, control information, wireless signals / channels, or the like, as referred to in the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein, via one or more antennas (108, 208). In this document, one or more antennas may be multiple physical antennas or multiple logical antennas (e.g., antenna ports). One or more transceivers (106, 206) can convert received user data, control information, wireless signals / channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc. using one or more processors (102, 202).One or more transceivers (106, 206) may convert user data, control information, wireless signals / channels, etc. processed by one or more processors (102, 202) from baseband signals to RF band signals. For this purpose, one or more transceivers (106, 206) may include an (analog) oscillator and / or filter.
[0867] FIG. 44 illustrates another example of a wireless device that can be applied to various embodiments of the present disclosure.
[0868] According to FIG. 44, the wireless device may include at least one processor (102, 202), at least one memory (104, 204), at least one transceiver (106, 206), and one or more antennas (108, 208).
[0869] The difference between the example of the wireless device described in FIG. 43 and the example of the wireless device in FIG. 44 is that in FIG. 43, the processor (102, 202) and the memory (104, 204) are separated, but in the example of FIG. 44, the memory (104, 204) is included in the processor (102, 202).
[0870] Here, the specific description of the processor (102, 202), memory (104, 204), transceiver (106, 206), and one or more antennas (108, 208) is as described above, so in order to avoid unnecessary repetition of description, the description of the repeated description is omitted.
[0871] Below, examples of signal processing circuits to which various embodiments of the present disclosure are applied are described.
[0872] Figure 45 illustrates a signal processing circuit for a transmission signal.
[0873] Referring to FIG. 45, the signal processing circuit (1000) may include a scrambler (1010), a modulator (1020), a layer mapper (1030), a precoder (1040), a resource mapper (1050), and a signal generator (1060). Although not limited thereto, the operations / functions of FIG. 45 may be performed in the processor (102, 202) and / or the transceiver (106, 206) of FIG. 43. The hardware elements of FIG. 45 may be implemented in the processor (102, 202) and / or the transceiver (106, 206) of FIG. 43. For example, blocks 1010 to 1060 may be implemented in the processor (102, 202) of FIG. 43. Additionally, blocks 1010 to 1050 may be implemented in the processor (102, 202) of FIG. 43, and block 1060 may be implemented in the transceiver (106, 206) of FIG. 43.
[0874] The codeword can be converted into a wireless signal through the signal processing circuit (1000) of FIG. 45. Here, the codeword is an encoded bit sequence of an information block. The information block can include a transport block (e.g., an UL-SCH transport block, a DL-SCH transport block). The wireless signal can be transmitted through various physical channels (e.g., a PUSCH or a PDSCH).
[0875] Specifically, the codeword can be converted into a bit sequence scrambled by a scrambler (1010). The scramble sequence used for scrambling is generated based on an initialization value, and the initialization value may include ID information of the wireless device, etc. The scrambled bit sequence can be modulated into a modulation symbol sequence by a modulator (1020). The modulation method may include pi / 2-BPSK (pi / 2-Binary Phase Shift Keying), m-PSK (m-Phase Shift Keying), m-QAM (m-Quadrature Amplitude Modulation), etc. The complex modulation symbol sequence can be mapped to one or more transmission layers by a layer mapper (1030). The modulation symbols of each transmission layer can be mapped to the corresponding antenna port(s) by a precoder (1040) (precoding). The output z of the precoder (1040) can be obtained by multiplying the output y of the layer mapper (1030) by a precoding matrix W of N*M. Here, N is the number of antenna ports, and M is the number of transmission layers. Here, the precoder (1040) can perform precoding after performing transform precoding (e.g., DFT transform) on complex modulation symbols. In addition, the precoder (1040) can perform precoding without performing transform precoding.
[0876] The resource mapper (1050) can map modulation symbols of each antenna port to time-frequency resources. The time-frequency resources can include multiple symbols (e.g., CP-OFDMA symbols, DFT-s-OFDMA symbols) in the time domain and multiple subcarriers in the frequency domain. The signal generator (1060) generates a wireless signal from the mapped modulation symbols, and the generated wireless signal can be transmitted to another device through each antenna. To this end, the signal generator (1060) can include an Inverse Fast Fourier Transform (IFFT) module, a Cyclic Prefix (CP) inserter, a Digital-to-Analog Converter (DAC), a frequency uplink converter, etc.
[0877] The signal processing process for receiving signals in a wireless device can be configured in reverse order of the signal processing process (1010 to 1060) of FIG. 45. For example, a wireless device (e.g., 100, 200 of FIG. 43) can receive wireless signals from the outside through an antenna port / transceiver. The received wireless signals can be converted into baseband signals through a signal restorer. For this purpose, the signal restorer can include a frequency downlink converter, an analog-to-digital converter (ADC), a CP remover, and a fast Fourier transform (FFT) module. Thereafter, the baseband signal can be restored to a codeword through a resource demapper process, a postcoding process, a demodulation process, and a descrambling process. The codewords can be restored to the original information blocks through decoding. Accordingly, a signal processing circuit (not shown) for a received signal may include a signal restorer, a resource de-mapper, a postcoder, a demodulator, a de-scrambler, and a decoder.
[0878] Below, examples of wireless device utilization to which various embodiments of the present disclosure are applied are described.
[0879] Figure 46 illustrates another example of a wireless device applicable to various embodiments of the present disclosure. The wireless device may be implemented in various forms depending on the use case / service (see Figure 42).
[0880] Referring to FIG. 46, the wireless device (100, 200) corresponds to the wireless device (100, 200) of FIG. 43 and may be composed of various elements, components, units, and / or modules. For example, the wireless device (100, 200) may include a communication unit (110), a control unit (120), a memory unit (130), and an additional element (140). The communication unit may include a communication circuit (112) and a transceiver(s) (114). For example, the communication circuit (112) may include one or more processors (102, 202) and / or one or more memories (104, 204) of FIG. 43. For example, the transceiver(s) (114) may include one or more transceivers (106, 206) and / or one or more antennas (108, 208) of FIG. 43. The control unit (120) is electrically connected to the communication unit (110), the memory unit (130), and the additional elements (140) and controls the overall operation of the wireless device. For example, the control unit (120) may control the electrical / mechanical operation of the wireless device based on the program / code / command / information stored in the memory unit (130). In addition, the control unit (120) may transmit information stored in the memory unit (130) to an external device (e.g., another communication device) via a wireless / wired interface through the communication unit (110), or store information received from an external device (e.g., another communication device) via a wireless / wired interface in the memory unit (130).
[0881] The additional element (140) may be configured in various ways depending on the type of the wireless device. For example, the additional element (140) may include at least one of a power unit / battery, an input / output unit (I / O unit), a driving unit, and a computing unit. Although not limited thereto, the wireless device may be implemented in the form of a robot (Fig. 42, 100a), a vehicle (Fig. 42, 100b-1, 100b-2), an XR device (Fig. 42, 100c), a portable device (Fig. 42, 100d), a home appliance (Fig. 42, 100e), an IoT device (Fig. 42, 100f), a digital broadcasting terminal, a hologram device, a public safety device, an MTC device, a medical device, a fintech device (or a financial device), a security device, a climate / environmental device, an AI server / device (Fig. 42, 400), a base station (Fig. 42, 200), a network node, etc. Wireless devices may be mobile or stationary depending on the use / service.
[0882] In FIG. 46, various elements, components, units / parts, and / or modules within the wireless device (100, 200) may be entirely interconnected via a wired interface, or at least some may be wirelessly connected via a communication unit (110). For example, within the wireless device (100, 200), the control unit (120) and the communication unit (110) may be wired, and the control unit (120) and a first unit (e.g., 130, 140) may be wirelessly connected via the communication unit (110). In addition, each element, component, unit / part, and / or module within the wireless device (100, 200) may further include one or more elements. For example, the control unit (120) may be composed of one or more processor sets. For example, the control unit (120) may be composed of a set of a communication control processor, an application processor, an electronic control unit (ECU), a graphics processing processor, a memory control processor, etc. As another example, the memory unit (130) may be composed of RAM (Random Access Memory), DRAM (Dynamic RAM), ROM (Read Only Memory), flash memory, volatile memory, non-volatile memory, and / or a combination thereof.
[0883] Below, the implementation example of Fig. 46 is described in more detail with reference to the drawings.
[0884] Figure 47 illustrates a mobile device applicable to various embodiments of the present disclosure. The mobile device may include a smartphone, a smart pad, a wearable device (e.g., a smartwatch, smartglasses), or a portable computer (e.g., a laptop, etc.). The mobile device may be referred to as a Mobile Station (MS), a User Terminal (UT), a Mobile Subscriber Station (MSS), a Subscriber Station (SS), an Advanced Mobile Station (AMS), or a Wireless Terminal (WT).
[0885] Referring to FIG. 47, the portable device (100) may include an antenna unit (108), a communication unit (110), a control unit (120), a memory unit (130), a power supply unit (140a), an interface unit (140b), and an input / output unit (140c). The antenna unit (108) may be configured as a part of the communication unit (110). Blocks 110 to 130 / 140a to 140c correspond to blocks 110 to 130 / 140 of FIG. 46, respectively.
[0886] The communication unit (110) can transmit and receive signals (e.g., data, control signals, etc.) with other wireless devices and base stations. The control unit (120) can control components of the mobile device (100) to perform various operations. The control unit (120) can include an AP (Application Processor). The memory unit (130) can store data / parameters / programs / codes / commands required for operating the mobile device (100). In addition, the memory unit (130) can store input / output data / information, etc. The power supply unit (140a) supplies power to the mobile device (100) and can include a wired / wireless charging circuit, a battery, etc. The interface unit (140b) can support connection between the mobile device (100) and other external devices. The interface unit (140b) can include various ports (e.g., audio input / output ports, video input / output ports) for connection with external devices. The input / output unit (140c) can input or output video information / signals, audio information / signals, data, and / or information input from a user. The input / output unit (140c) may include a camera, a microphone, a user input unit, a display unit (140d), a speaker, and / or a haptic module.
[0887] For example, in the case of data communication, the input / output unit (140c) obtains information / signals (e.g., touch, text, voice, image, video) input by the user, and the obtained information / signals can be stored in the memory unit (130). The communication unit (110) converts the information / signals stored in the memory into wireless signals, and can directly transmit the converted wireless signals to other wireless devices or to a base station. In addition, the communication unit (110) can receive wireless signals from other wireless devices or base stations, and then restore the received wireless signals to the original information / signals. The restored information / signals can be stored in the memory unit (130) and then output in various forms (e.g., text, voice, image, video, haptic) through the input / output unit (140c).
[0888] FIG. 48 illustrates a vehicle or autonomous vehicle applicable to various embodiments of the present disclosure.
[0889] Vehicles or autonomous vehicles can be implemented as mobile robots, cars, trains, manned or unmanned aerial vehicles (AVs), ships, etc.
[0890] Referring to FIG. 48, a vehicle or autonomous vehicle (100) may include an antenna unit (108), a communication unit (110), a control unit (120), a driving unit (140a), a power supply unit (140b), a sensor unit (140c), and an autonomous driving unit (140d). The antenna unit (108) may be configured as a part of the communication unit (110). Blocks 110 / 130 / 140a to 140d correspond to blocks 110 / 130 / 140 of FIG. 46, respectively.
[0891] The communication unit (110) can transmit and receive signals (e.g., data, control signals, etc.) with external devices such as other vehicles, base stations (e.g., base stations, road side units, etc.), and servers. The control unit (120) can control elements of the vehicle or autonomous vehicle (100) to perform various operations. The control unit (120) can include an ECU (Electronic Control Unit). The drive unit (140a) can drive the vehicle or autonomous vehicle (100) on the ground. The drive unit (140a) can include an engine, a motor, a power train, wheels, brakes, a steering device, etc. The power supply unit (140b) supplies power to the vehicle or autonomous vehicle (100) and can include a wired / wireless charging circuit, a battery, etc. The sensor unit (140c) can obtain vehicle status, surrounding environment information, user information, etc. The sensor unit (140c) may include an IMU (inertial measurement unit) sensor, a collision sensor, a wheel sensor, a speed sensor, an incline sensor, a weight detection sensor, a heading sensor, a position module, a vehicle forward / backward sensor, a battery sensor, a fuel sensor, a tire sensor, a steering sensor, a temperature sensor, a humidity sensor, an ultrasonic sensor, an illuminance sensor, a pedal position sensor, etc. The autonomous driving unit (140d) may implement a technology for maintaining a driving lane, a technology for automatically controlling speed such as adaptive cruise control, a technology for automatically driving along a set path, a technology for automatically setting a path and driving when a destination is set, etc.
[0892] For example, the communication unit (110) can receive map data, traffic information data, etc. from an external server. The autonomous driving unit (140d) can generate an autonomous driving route and driving plan based on the acquired data. The control unit (120) can control the drive unit (140a) so that the vehicle or autonomous vehicle (100) moves along the autonomous driving route according to the driving plan (e.g., speed / direction control). During autonomous driving, the communication unit (110) can irregularly / periodically acquire the latest traffic information data from an external server and can acquire surrounding traffic information data from surrounding vehicles. In addition, during autonomous driving, the sensor unit (140c) can acquire vehicle status and surrounding environment information. The autonomous driving unit (140d) can update the autonomous driving route and driving plan based on newly acquired data / information. The communication unit (110) can transmit information regarding the vehicle location, autonomous driving route, driving plan, etc. to the external server. External servers can predict traffic information data in advance using AI technology or other technologies based on information collected from vehicles or autonomous vehicles, and provide the predicted traffic information data to the vehicles or autonomous vehicles.
[0893] Figure 49 illustrates a vehicle applicable to various embodiments of the present disclosure. The vehicle may also be implemented as a means of transportation, a train, an aircraft, a ship, or the like.
[0894] Referring to FIG. 49, the vehicle (100) may include a communication unit (110), a control unit (120), a memory unit (130), an input / output unit (140a), and a position measurement unit (140b). Here, blocks 110 to 130 / 140a to 140b correspond to blocks 110 to 130 / 140 of FIG. 46, respectively.
[0895] The communication unit (110) can transmit and receive signals (e.g., data, control signals, etc.) with other vehicles or external devices such as base stations. The control unit (120) can control components of the vehicle (100) to perform various operations. The memory unit (130) can store data / parameters / programs / codes / commands that support various functions of the vehicle (100). The input / output unit (140a) can output AR / VR objects based on information in the memory unit (130). The input / output unit (140a) can include a HUD. The position measurement unit (140b) can obtain position information of the vehicle (100). The position information can include absolute position information of the vehicle (100), position information within a driving line, acceleration information, position information with respect to surrounding vehicles, etc. The position measurement unit (140b) can include GPS and various sensors.
[0896] For example, the communication unit (110) of the vehicle (100) can receive map information, traffic information, etc. from an external server and store them in the memory unit (130). The location measurement unit (140b) can obtain vehicle location information through GPS and various sensors and store the information in the memory unit (130). The control unit (120) can create a virtual object based on the map information, traffic information, and vehicle location information, and the input / output unit (140a) can display the created virtual object on the vehicle window (1410, 1420). In addition, the control unit (120) can determine whether the vehicle (100) is being driven normally within the driving line based on the vehicle location information. If the vehicle (100) abnormally deviates from the driving line, the control unit (120) can display a warning on the vehicle window through the input / output unit (140a). Additionally, the control unit (120) can broadcast a warning message regarding driving abnormalities to surrounding vehicles through the communication unit (110). Depending on the situation, the control unit (120) can transmit vehicle location information and information regarding driving / vehicle abnormalities to relevant authorities through the communication unit (110).
[0897] Figure 50 illustrates an XR device applicable to various embodiments of the present disclosure. The XR device may be implemented as an HMD, a head-up display (HUD) installed in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, digital signage, a vehicle, a robot, and the like.
[0898] Referring to FIG. 50, the XR device (100a) may include a communication unit (110), a control unit (120), a memory unit (130), an input / output unit (140a), a sensor unit (140b), and a power supply unit (140c). Here, blocks 110 to 130 / 140a to 140c correspond to blocks 110 to 130 / 140 of FIG. 46, respectively.
[0899] The communication unit (110) can transmit and receive signals (e.g., media data, control signals, etc.) with external devices such as other wireless devices, portable devices, or media servers. The media data can include videos, images, sounds, etc. The control unit (120) can control components of the XR device (100a) to perform various operations. For example, the control unit (120) can be configured to control and / or perform procedures such as video / image acquisition, (video / image) encoding, metadata generation and processing, etc. The memory unit (130) can store data / parameters / programs / codes / commands required for driving the XR device (100a) / generating XR objects. The input / output unit (140a) can obtain control information, data, etc. from the outside, and output the generated XR objects. The input / output unit (140a) can include a camera, a microphone, a user input unit, a display unit, a speaker, and / or a haptic module, etc. The sensor unit (140b) can obtain the XR device status, surrounding environment information, user information, etc. The sensor unit (140b) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an RGB sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, and / or a radar. The power supply unit (140c) supplies power to the XR device (100a) and may include a wired / wireless charging circuit, a battery, etc.
[0900] For example, the memory unit (130) of the XR device (100a) may include information (e.g., data, etc.) required for creating an XR object (e.g., AR / VR / MR object). The input / output unit (140a) may obtain a command to operate the XR device (100a) from the user, and the control unit (120) may operate the XR device (100a) according to the user's operating command. For example, when a user attempts to watch a movie, news, etc. through the XR device (100a), the control unit (120) may transmit content request information to another device (e.g., a mobile device (100b)) or a media server through the communication unit (130). The communication unit (130) may download / stream content such as movies and news from another device (e.g., a mobile device (100b)) or a media server to the memory unit (130). The control unit (120) controls and / or performs procedures such as video / image acquisition, (video / image) encoding, and metadata generation / processing for content, and can generate / output an XR object based on information about surrounding space or real objects acquired through the input / output unit (140a) / sensor unit (140b).
[0901] In addition, the XR device (100a) is wirelessly connected to the mobile device (100b) through the communication unit (110), and the operation of the XR device (100a) can be controlled by the mobile device (100b). For example, the mobile device (100b) can act as a controller for the XR device (100a). To this end, the XR device (100a) can obtain three-dimensional position information of the mobile device (100b), and then generate and output an XR object corresponding to the mobile device (100b).
[0902] Figure 51 illustrates robots applicable to various embodiments of the present disclosure. Robots may be classified into industrial, medical, household, military, and other categories depending on their intended use or field.
[0903] Referring to FIG. 51, the robot (100) may include a communication unit (110), a control unit (120), a memory unit (130), an input / output unit (140a), a sensor unit (140b), and a driving unit (140c). Here, blocks 110 to 130 / 140a to 140c correspond to blocks 110 to 130 / 140 of FIG. 46, respectively.
[0904] The communication unit (110) can transmit and receive signals (e.g., driving information, control signals, etc.) with external devices such as other wireless devices, other robots, or control servers. The control unit (120) can control components of the robot (100) to perform various operations. The memory unit (130) can store data / parameters / programs / codes / commands that support various functions of the robot (100). The input / output unit (140a) can obtain information from the outside of the robot (100) and output information to the outside of the robot (100). The input / output unit (140a) can include a camera, a microphone, a user input unit, a display unit, a speaker, and / or a haptic module. The sensor unit (140b) can obtain internal information of the robot (100), surrounding environment information, user information, etc. The sensor unit (140b) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, a radar, etc. The driving unit (140c) may perform various physical operations such as moving the robot joints. In addition, the driving unit (140c) may enable the robot (100) to drive on the ground or fly in the air. The driving unit (140c) may include an actuator, a motor, wheels, brakes, propellers, etc.
[0905] FIG. 52 illustrates an AI device applicable to various embodiments of the present disclosure.
[0906] AI devices can be implemented as fixed or mobile devices, such as TVs, projectors, smartphones, PCs, laptops, digital broadcasting terminals, tablet PCs, wearable devices, set-top boxes (STBs), radios, washing machines, refrigerators, digital signage, robots, and vehicles.
[0907] Referring to FIG. 52, the AI device (100) may include a communication unit (110), a control unit (120), a memory unit (130), an input / output unit (140a / 140b), a learning processor unit (140c), and a sensor unit (140d). Blocks 110 to 130 / 140a to 140d correspond to blocks 110 to 130 / 140 of FIG. 46, respectively.
[0908] The communication unit (110) can transmit and receive wired and wireless signals (e.g., sensor information, user input, learning models, control signals, etc.) with external devices such as other AI devices (e.g., FIG. W1, 100x, 200, 400) or AI servers (200) using wired and wireless communication technology. To this end, the communication unit (110) can transmit information within the memory unit (130) to the external device or transfer a signal received from the external device to the memory unit (130).
[0909] The control unit (120) may determine at least one executable operation of the AI device (100) based on information determined or generated using a data analysis algorithm or a machine learning algorithm. In addition, the control unit (120) may control components of the AI device (100) to perform the determined operation. For example, the control unit (120) may request, search, receive, or utilize data from the learning processor unit (140c) or the memory unit (130), and may control components of the AI device (100) to perform a predicted operation or an operation determined to be desirable among at least one executable operation. In addition, the control unit (120) may collect history information including operation details of the AI device (100) or user feedback on the operation, and store the collected history information in the memory unit (130) or the learning processor unit (140c), or transmit the collected history information to an external device such as an AI server (FIG. W1, 400). The collected history information may be used to update a learning model.
[0910] The memory unit (130) can store data that supports various functions of the AI device (100). For example, the memory unit (130) can store data obtained from the input unit (140a), data obtained from the communication unit (110), output data of the learning processor unit (140c), and data obtained from the sensing unit (140). In addition, the memory unit (130) can store control information and / or software codes necessary for the operation / execution of the control unit (120).
[0911] The input unit (140a) can obtain various types of data from the outside of the AI device (100). For example, the input unit (120) can obtain learning data for model learning, input data to which the learning model will be applied, etc. The input unit (140a) may include a camera, a microphone, and / or a user input unit. The output unit (140b) may generate output related to sight, hearing, or touch. The output unit (140b) may include a display unit, a speaker, and / or a haptic module, etc. The sensing unit (140) can obtain at least one of internal information of the AI device (100), information about the surrounding environment of the AI device (100), and user information using various sensors. The sensing unit (140) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an RGB sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, and / or a radar, etc.
[0912] The learning processor unit (140c) can train a model composed of an artificial neural network using learning data. The learning processor unit (140c) can perform AI processing together with the learning processor unit of the AI server (Figure W1, 400). The learning processor unit (140c) can process information received from an external device via the communication unit (110) and / or information stored in the memory unit (130). In addition, the output value of the learning processor unit (140c) can be transmitted to an external device via the communication unit (110) and / or stored in the memory unit (130).
[0913] The claims described in the various embodiments of the present disclosure may be combined in various ways. For example, the technical features of the method claims of the various embodiments of the present disclosure may be combined and implemented as a device, and the technical features of the device claims of the various embodiments of the present disclosure may be combined and implemented as a method. Furthermore, the technical features of the method claims of the various embodiments of the present disclosure may be combined and implemented as a device, and the technical features of the method claims of the various embodiments of the present disclosure may be combined and implemented as a method.
Claims
1. In a method performed by a first node in a communication system, A step of transmitting at least one synchronization signal to a second node; A step of transmitting a control signal (control information) to the second node; A step of transmitting a quantum public key (QPK) based on a private key to the second node; A step of receiving a hybrid QBER check packet related to the result of a hybrid QBER check (hybrid quantum bit error rate check) for first qubits among a plurality of qubits constituting the QPK from the second node; A step of decrypting the above hybrid QBER check packet with a classical private key to generate basis matching information of the QPK; A step of transmitting a hybrid QBER check response packet based on the above-mentioned base matching information to the second node; A step of receiving a verification result of the validity of the QPK from the second node based on the above base matching information; A step of receiving an encrypted message from the second node based on the second qubits that are not used for the hybrid QBER check among the plurality of qubits based on the validity of the QPK, method.
2. In paragraph 1, The above-mentioned basis matching information is based on whether the basis information of the generated quantum public key corresponding to the quantum public key index of the hybrid QBER test information and the measurement basis information of the hybrid QBER test information match. method.
3. In paragraph 2, The above hybrid QBER inspection information is based on the decryption of the hybrid QBER inspection packet. method.
4. In paragraph 1, The validity of the above QPK is based on a comparison of the result of the above hybrid QBER check reported in the above hybrid QBER check response packet with a predefined threshold value. method.
5. In paragraph 4, If the hybrid QBER check response packet indicates a QBER greater than a predetermined threshold value, the step of discarding the QPK and transmitting a newly generated second QPK to the second node is further included. method.
6. In paragraph 1, Further comprising a step of obtaining information of the message based on the private key. method.
7. In paragraph 6, Decryption of the encrypted message is based on compensation through the private key for the information of the second qubits. method.
8. In the method of operation of the second node in the communication system, A step of receiving at least one synchronization signal from a first node; A step of receiving a control signal (control information) from the first node; A step of receiving a quantum public key (QPK) based on a private key from the first node; A step of transmitting a hybrid QBER check packet related to the result of a hybrid QBER check (hybrid quantum bit error rate check) for first qubits among a plurality of qubits constituting the QPK to the first node; A step of receiving a hybrid QBER check response packet based on basis matching information of the QPK from the first node; A step of verifying the validity of the QPK based on the hybrid QBER check response packet; A step of transmitting the result of verification of the validity of the QPK to the first node; A step of transmitting an encrypted message to the first node based on the second qubits that are not used for the hybrid QBER check among the plurality of qubits based on the validity of the QPK, The above-mentioned base matching information is generated by classical private key-based decryption of the hybrid QBER check packet. method.
9. In paragraph 8, The above-mentioned basis matching information is based on whether the basis information of the generated quantum public key corresponding to the quantum public key index of the hybrid QBER test information and the measurement basis information of the hybrid QBER test information match. method.
10. In paragraph 9, The above hybrid QBER inspection information is based on the decryption of the hybrid QBER inspection packet. method.
11. In paragraph 8, The validity of the above QPK is based on a comparison of the result of the above hybrid QBER check reported in the above hybrid QBER check response packet with a predefined threshold value. method.
12. In paragraph 11, If the hybrid QBER check response packet indicates a QBER greater than a predetermined threshold value, the step of discarding the QPK and receiving a newly generated second QPK from the second node is further included. method.
13. In paragraph 8, Decoding of the message is performed based on the above private key, method.
14. In paragraph 13, Decryption of the encrypted message is based on compensation through the private key for the information of the second qubits. method.
15. In the first node of the communication system, Transmitter and receiver; at least one processor; and At least one memory operably connectable to said at least one processor and storing instructions that, when executed by said at least one processor, perform operations; The above actions are, Comprising all steps of the method according to one of claims 1 to 7, Node 1.
16. In the second node of the communication system, Transmitter and receiver; at least one processor; and At least one memory operably connectable to said at least one processor and storing instructions that, when executed by said at least one processor, perform operations; The above actions are, Comprising all steps of a method according to one of claims 8 to 14, Second node.
17. In a control device that controls a first node in a communication system, at least one processor; and comprising at least one memory operably connected to at least one of the processors; The at least one memory stores instructions for performing operations based on being executed by the at least one processor, The above actions are, Comprising all steps of the method according to one of claims 1 to 7, controller.
18. In a control device that controls a second node in a communication system, at least one processor; and comprising at least one memory operably connected to at least one of the processors; The at least one memory stores instructions for performing operations based on being executed by the at least one processor, The above actions are, Comprising all steps of a method according to one of claims 8 to 14, controller.
19. In one or more non-transitory computer-readable media storing one or more instructions, The one or more instructions perform operations based on being executed by one or more processors, The above actions are, Comprising all steps of the method according to one of claims 1 to 7, Computer readable medium.
20. In one or more non-transitory computer-readable media storing one or more instructions, The one or more instructions perform operations based on being executed by one or more processors, The above actions are, Comprising all steps of a method according to one of claims 8 to 14, Computer readable medium.
Citation Information
Patent Citations
Structure for reinforcing support frame
KR1020230006155A
Device and method for detecting and correcting entanglement error with respect to arbitrary n-qubit entanglement state in quantum communication system
WO2023128603A1
Method and device for performing error correction on asymmetric pauli channel in quantum communication system
WO2023128604A1
KR20230162328A