Method and apparatus for supporting quantum coherence time-based quantum public key infrastructure in quantum communication system
A quantum coherence time-based QPKI with ephemeral keys addresses the vulnerability of asymmetric key systems to quantum algorithms, enhancing security by preventing real-time leakage and mitigating Harvest-Now-Decrypt-Later attacks.
Patent Information
- Application Number
- PCT/KR2024/002396
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-23
- Publication Date
- 2025-08-28
AI Technical Summary
The collapse of asymmetric key cryptography systems due to quantum algorithms poses a serious threat to secure communication systems, and transitioning to new security systems entails a significant technical burden, while existing solutions like Harvest-Now-Decrypt-Later attacks remain vulnerable.
A quantum coherence time-based quantum public key infrastructure (QPKI) is implemented, providing physical security through the no-cloning theorem and using ephemeral keys for hybrid encryption and encapsulation.
This approach adaptively prevents trapdoor leakage and safeguards against quantum algorithm attacks, ensuring robust and secure communication by periodically updating public keys.
Smart Images

Figure KR2024002396_28082025_PF_FP_ABST
Abstract
Description
Method and device for supporting quantum coherent time-based quantum public key infrastructure in a quantum communication system
[0001] The present disclosure relates to a device and method for supporting a quantum coherence time-based quantum public key infrastructure in a quantum communication system. The present disclosure proposes a method for achieving physical information security based on the no-cloning theorem and quantum coherence time.
[0002]
[0003] The collapse of asymmetric key cryptography systems due to quantum algorithms poses a serious threat to secure communication systems based on asymmetric key cryptography. To prevent this security threat, Post-Quantum Cryptography (PQC) technology is emerging. However, all asymmetric key systems based on computational complexity inevitably face the risk of being threatened by new quantum algorithms. Furthermore, transitioning to a new security system can entail a significant technical burden, as the new security technology must be applied across all devices.
[0004] Therefore, a method is needed to address the threat of quantum algorithms while maintaining an asymmetric key system. To achieve this, trapdoor leakage caused by quantum algorithms can be adaptively prevented by periodically updating the public key. This prevents real-time leakage even if a plaintext attack is conducted using quantum algorithms. However, even if real-time leakage does not occur, an attacker can still conduct a plaintext attack later using a Harvest-Now-Decrypt-Later (HNDL) attack. Consequently, limiting the validity period of a public key alone cannot achieve fundamental information security.
[0005]
[0006] To solve the above-described problems, the present disclosure provides a device and method for supporting a quantum coherence time based quantum public key infrastructure in a quantum communication system.
[0007] The present disclosure provides a device and method for supporting a quantum public key infrastructure (QPKI) that provides physical security based on the no-cloning theorem and quantum coherence time in a quantum communication system.
[0008] The present disclosure provides a device and method for performing encryption using a quantum public key and encapsulation using an ephemeral key (EK) in a hybrid manner in a quantum communication system.
[0009] The technical problems to be achieved in the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which the present disclosure belongs from the description below.
[0010]
[0011] According to various embodiments of the present disclosure, a method performed by a first node in a communication system is provided, the method comprising: transmitting at least one synchronization signal to a second node; transmitting control information to the second node; receiving a request for a quantum public key (QPK) from the second node; transmitting the QPK to the second node based on a private key associated with the first node; and receiving a message on which encryption and quantum state encapsulation based on the QPK have been performed from the second node.
[0012] According to various embodiments of the present disclosure, a method of operating a second node in a communication system is provided, the method comprising: receiving at least one synchronization signal from a first node; receiving control information from the first node; transmitting a request for a quantum public key (QPK) to the first node; receiving the QPK from the first node based on a private key associated with the first node; and transmitting a message on which encryption and quantum state encapsulation based on the QPK have been performed to the first node.
[0013] According to various embodiments of the present disclosure, in a communication system, a first node is provided, comprising: a transceiver; at least one processor; and at least one memory operably connectable to the at least one processor and storing instructions that, when executed by the at least one processor, perform operations, wherein the operations include all steps of a method of operating the first node according to various embodiments of the present disclosure.
[0014] According to various embodiments of the present disclosure, in a communication system, a second node is provided, comprising: a transceiver; at least one processor; and at least one memory operably connectable to the at least one processor and storing instructions that, when executed by the at least one processor, perform operations, wherein the operations include all steps of a method of operating the second node according to various embodiments of the present disclosure.
[0015] According to various embodiments of the present disclosure, a control device for controlling a first node in a communication system is provided, comprising: at least one processor; and at least one memory operably connected to the at least one processor, wherein the at least one memory stores instructions for performing operations based on being executed by the at least one processor, wherein the operations include all steps of an operating method of the first node according to various embodiments of the present disclosure.
[0016] According to various embodiments of the present disclosure, a control device for controlling a second node in a communication system is provided, comprising: at least one processor; and at least one memory operably connected to the at least one processor, wherein the at least one memory stores instructions for performing operations based on being executed by the at least one processor, wherein the operations include all steps of an operating method of the second node according to various embodiments of the present disclosure.
[0017] According to various embodiments of the present disclosure, one or more non-transitory computer-readable media storing one or more instructions, wherein the one or more instructions, based on being executed by one or more processors, perform operations, the operations comprising all steps of a method of operating a first node according to various embodiments of the present disclosure, are provided.
[0018] According to various embodiments of the present disclosure, there is provided one or more non-transitory computer-readable media storing one or more instructions, wherein the one or more instructions, when executed by one or more processors, perform operations, the operations comprising all steps of a method of operating a second node according to various embodiments of the present disclosure.
[0019]
[0020] To solve the above-described problems, the present disclosure may provide a device and method for supporting a quantum coherence time based quantum public key infrastructure in a quantum communication system.
[0021] The present disclosure may provide a device and method for supporting a quantum public key infrastructure (QPKI) that provides physical security based on the no-cloning theorem and quantum coherence time in a quantum communication system.
[0022] The present disclosure may provide a device and method for performing encryption using a quantum public key and encapsulation using an ephemeral key (EK) in a hybrid manner in a quantum communication system.
[0023]
[0024] The accompanying drawings are intended to aid in understanding the present disclosure and, together with detailed descriptions, may provide embodiments of the present disclosure. However, the technical features of the present disclosure are not limited to specific drawings, and the features disclosed in each drawing may be combined with each other to form new embodiments. Reference numerals in each drawing may indicate structural elements.
[0025] Figure 1 is a diagram illustrating an example of physical channels and general signal transmission used in a 3GPP system.
[0026] Figure 2 is a diagram illustrating the system structure of a New Generation Radio Access Network (NG-RAN).
[0027] Figure 3 is a diagram illustrating the functional division between NG-RAN and 5GC.
[0028] Figure 4 is a diagram illustrating an example of a 5G usage scenario.
[0029] Figure 5 is a diagram illustrating an example of a communication structure that can be provided in a 6G system.
[0030] Figure 6 is a schematic diagram illustrating an example of a perceptron structure.
[0031] Figure 7 is a schematic diagram illustrating an example of a multilayer perceptron structure.
[0032] Figure 8 is a schematic diagram illustrating an example of a deep neural network.
[0033] Figure 9 is a schematic diagram illustrating an example of a convolutional neural network.
[0034] Figure 10 is a schematic diagram illustrating an example of a filter operation in a convolutional neural network.
[0035] Figure 11 is a schematic diagram illustrating an example of a neural network structure in which a recurrent loop exists.
[0036] Figure 12 is a diagram schematically illustrating an example of the operating structure of a recurrent neural network.
[0037] Figure 13 is a diagram illustrating an example of the electromagnetic spectrum.
[0038] Figure 14 is a diagram illustrating an example of a THz communication application.
[0039] Fig. 15 is a diagram illustrating an example of an electronic component-based THz wireless communication transmitter and receiver.
[0040] FIG. 16 is a diagram illustrating an example of a method for generating a THz signal based on an optical element.
[0041] Fig. 17 is a diagram illustrating an example of an optical element-based THz wireless communication transceiver.
[0042] Fig. 18 is a diagram illustrating the structure of a photon source-based transmitter.
[0043] Figure 19 is a drawing showing the structure of an optical modulator.
[0044] FIG. 20 is a diagram illustrating an example of a man-in-the-middle attack in a system applicable to the present disclosure.
[0045] FIG. 21 is a diagram illustrating an example of a MAC-based authentication technique in a system applicable to the present disclosure.
[0046] FIG. 22 is a diagram illustrating an example of Wegman & Carter Authentication (WCA) in a system applicable to the present disclosure.
[0047] FIG. 23 is a diagram illustrating an example of collision probability in Wegman & Carter Authentication (WCA) in a system applicable to the present disclosure.
[0048] FIG. 24 is a diagram illustrating an example of a concept of cloning for a qubit in a system applicable to the present disclosure.
[0049] Figure 25 is a diagram illustrating an example of security keys in a 5G network system.
[0050] FIG. 26 is a diagram illustrating an example of an authentication procedure initiation and authentication method selection process in a system applicable to the present disclosure.
[0051] FIG. 27 is a diagram illustrating an example of an authentication procedure initiation and authentication method selection process in a system applicable to the present disclosure.
[0052] FIG. 28 is a diagram illustrating an example of a SUCI structure in a system applicable to the present disclosure.
[0053] FIG. 29 is a diagram illustrating an example of a system output for an elliptic curve integrated encryption scheme profile A applicable to the present disclosure.
[0054] FIG. 30 is a diagram illustrating an example of a system output for an elliptic curve integrated encryption scheme profile B applicable to the present disclosure.
[0055] FIG. 31a is a diagram illustrating an example of modulation by Qubit Rotation in a system applicable to the present disclosure.
[0056] FIG. 31b is a diagram illustrating an example of a Pauli operator in a system applicable to the present disclosure.
[0057] FIG. 32 is a diagram illustrating an example of modulation by Qubit Rotation in a system applicable to the present disclosure.
[0058] FIG. 33 is a diagram illustrating an example of modulation by Qubit Rotation in a system applicable to the present disclosure.
[0059] FIG. 34 is a diagram illustrating an example of a QPKE Packet structure in a system applicable to the present disclosure.
[0060] FIG. 35 is a diagram illustrating an example of a QPKE Packet structure in a system applicable to the present disclosure.
[0061] FIG. 36 is a diagram illustrating an example of a QPKE Packet structure in a system applicable to the present disclosure.
[0062] FIG. 37 is a diagram illustrating an example of a PKE-EK Packet structure in a system applicable to the present disclosure.
[0063] FIG. 38 is a diagram illustrating an example of decapsulation by qubit rotation in a system applicable to the present disclosure.
[0064] FIG. 39 is a diagram illustrating an example of the operation of a quantum channel and a classical channel signal that are encrypted with a single qubit based QPK in a coherence time based quantum public key infrastructure (QPKI) and encapsulated with an ephemeral key in a system applicable to the present disclosure.
[0065] FIG. 40 is a flowchart illustrating the entire process of Coherence Time based Quantum Public Key Infrastructure (QPKI) in a system applicable to the present disclosure.
[0066] FIG. 41 is a diagram illustrating an example of the operation process of the first node in a system applicable to the present disclosure.
[0067] FIG. 42 is a diagram illustrating an example of the operation process of a second node in a system applicable to the present disclosure.
[0068] FIG. 43 illustrates a communication system (1) applicable to various embodiments of the present disclosure.
[0069] FIG. 44 illustrates a wireless device that can be applied to various embodiments of the present disclosure.
[0070] FIG. 45 illustrates another example of a wireless device that can be applied to various embodiments of the present disclosure.
[0071] Figure 46 illustrates a signal processing circuit for a transmission signal.
[0072] FIG. 47 illustrates another example of a wireless device applicable to various embodiments of the present disclosure.
[0073] FIG. 48 illustrates a mobile device applicable to various embodiments of the present disclosure.
[0074] FIG. 49 illustrates a vehicle or autonomous vehicle applicable to various embodiments of the present disclosure.
[0075] FIG. 50 illustrates a vehicle applicable to various embodiments of the present disclosure.
[0076] FIG. 51 illustrates an XR device applicable to various embodiments of the present disclosure.
[0077] FIG. 52 illustrates a robot applicable to various embodiments of the present disclosure.
[0078] FIG. 53 illustrates an AI device applicable to various embodiments of the present disclosure.
[0079]
[0080] In various embodiments of the present disclosure, “A or B” may mean “only A,” “only B,” or “both A and B.” In other words, in various embodiments of the present disclosure, “A or B” may be interpreted as “A and / or B.” For example, in various embodiments of the present disclosure, “A, B or C” may mean “only A,” “only B,” “only C,” or “any combination of A, B and C.”
[0081] In various embodiments of the present disclosure, a slash ( / ) or a comma may mean "and / or." For example, "A / B" may mean "A and / or B." Accordingly, "A / B" may mean "only A," "only B," or "both A and B." For example, "A, B, C" may mean "A, B, or C."
[0082] In various embodiments of the present disclosure, “at least one of A and B” may mean “only A,” “only B,” or “both A and B.” Furthermore, in various embodiments of the present disclosure, the expressions “at least one of A or B” or “at least one of A and / or B” may be interpreted as equivalent to “at least one of A and B.”
[0083] Additionally, in various embodiments of the present disclosure, “at least one of A, B and C” can mean “only A,” “only B,” “only C,” or “any combination of A, B and C.” Additionally, “at least one of A, B or C” or “at least one of A, B and / or C” can mean “at least one of A, B and C.”
[0084] Additionally, parentheses used in various embodiments of the present disclosure may mean "for example." Specifically, when indicated as "control information (PDCCH)", "PDCCH" may be proposed as an example of "control information." In other words, "control information" in various embodiments of the present disclosure is not limited to "PDCCH", and "PDDCH" may be proposed as an example of "control information." Furthermore, even when indicated as "control information (i.e., PDCCH)", "PDCCH" may be proposed as an example of "control information."
[0085] Technical features individually described in a single drawing in various embodiments of the present disclosure may be implemented individually or simultaneously.
[0086]
[0087] The following technologies can be used in various wireless access systems, such as CDMA, FDMA, TDMA, OFDMA, and SC-FDMA. CDMA can be implemented using wireless technologies such as UTRA (Universal Terrestrial Radio Access) or CDMA2000. TDMA can be implemented using wireless technologies such as GSM (Global System for Mobile communications) / GPRS (General Packet Radio Service) / EDGE (Enhanced Data Rates for GSM Evolution). OFDMA can be implemented using wireless technologies such as IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802-20, and E-UTRA (Evolved UTRA). UTRA is a part of UMTS (Universal Mobile Telecommunications System). 3GPP (3rd Generation Partnership Project) LTE (Long Term Evolution) is a part of E-UMTS (Evolved UMTS) that uses E-UTRA, and LTE-A (Advanced) / LTE-A pro is an evolved version of 3GPP LTE. 3GPP NR (New Radio or New Radio Access Technology) is an evolved version of 3GPP LTE / LTE-A / LTE-A pro. 3GPP 6G may be an evolved version of 3GPP NR.
[0088]
[0089] For clarity, the description is based on 3GPP communication systems (e.g., LTE, NR, etc.), but the technical spirit of the present disclosure is not limited thereto. LTE refers to technology after 3GPP TS 36.xxx Release 8. Specifically, LTE technology after 3GPP TS 36.xxx Release 10 is referred to as LTE-A, and LTE technology after 3GPP TS 36.xxx Release 13 is referred to as LTE-A pro. 3GPP NR refers to technology after TS 38.xxx Release 15. 3GPP 6G may refer to technology after TS Release 17 and / or Release 18. “xxx” refers to a standard document detail number. LTE / NR / 6G may be collectively referred to as a 3GPP system. For background technology, terms, abbreviations, etc. used in the description of the present disclosure, reference may be made to matters described in standard documents published prior to the present disclosure. For example, reference may be made to the following documents.
[0090]
[0091] 3GPP LTE
[0092] - 36.211: Physical channels and modulation
[0093] - 36.212: Multiplexing and channel coding
[0094] - 36.213: Physical layer procedures
[0095] - 36.300: Overall description
[0096] - 36.331: Radio Resource Control (RRC)
[0097] 3GPP NR
[0098] - 38.211: Physical channels and modulation
[0099] - 38.212: Multiplexing and channel coding
[0100] - 38.213: Physical layer procedures for control
[0101] - 38.214: Physical layer procedures for data
[0102] - 38.300: NR and NG-RAN Overall Description
[0103] - 38.331: Radio Resource Control (RRC) protocol specification
[0104]
[0105] Physical Channel and Frame Structure
[0106] Physical channels and general signal transmission
[0107] Figure 1 is a diagram illustrating an example of physical channels and general signal transmission used in a 3GPP system.
[0108] In a wireless communication system, a terminal receives information from a base station via the downlink (DL) and transmits it to the base station via the uplink (UL). The information transmitted and received between the base station and the terminal includes data and various control information, and various physical channels exist depending on the type and purpose of the information being transmitted and received.
[0109]
[0110] When a terminal is powered on or enters a new cell, it performs an initial cell search operation, such as synchronizing with the base station (S11). To this end, the terminal receives a Primary Synchronization Signal (PSS) and a Secondary Synchronization Signal (SSS) from the base station to synchronize with the base station and obtain information such as a cell ID. Afterwards, the terminal can receive a Physical Broadcast Channel (PBCH) from the base station to obtain broadcast information within the cell. Meanwhile, the terminal can receive a Downlink Reference Signal (DL RS) during the initial cell search phase to check the downlink channel status.
[0111]
[0112] A terminal that has completed initial cell search can obtain more specific system information by receiving a physical downlink control channel (PDCCH) and a physical downlink shared channel (PDSCH) based on information contained in the PDCCH (S12).
[0113]
[0114] Meanwhile, when accessing a base station for the first time or when there are no radio resources for signal transmission, the terminal may perform a random access procedure (RACH) for the base station (S13 to S16). To this end, the terminal may transmit a specific sequence as a preamble via a physical random access channel (PRACH) (S13 and S15) and receive a response message (RAR (Random Access Response) message) to the preamble via a PDCCH and a corresponding PDSCH. In the case of a contention-based RACH, a contention resolution procedure may additionally be performed (S16).
[0115]
[0116] The terminal that has performed the procedure described above can then perform PDCCH / PDSCH reception (S17) and physical uplink shared channel (PUSCH) / physical uplink control channel (PUCCH) transmission (S18) as general uplink / downlink signal transmission procedures. In particular, the terminal can receive downlink control information (DCI) through the PDCCH. Here, the DCI includes control information such as resource allocation information for the terminal, and different formats can be applied depending on the purpose of use.
[0117]
[0118] Meanwhile, the control information that the terminal transmits to the base station via the uplink or that the terminal receives from the base station may include downlink / uplink ACK / NACK signals, CQI (Channel Quality Indicator), PMI (Precoding Matrix Index), RI (Rank Indicator), etc. The terminal may transmit the above-described control information such as CQI / PMI / RI via PUSCH and / or PUCCH.
[0119]
[0120] Structure of uplink and downlink channels
[0121] Downlink channel structure
[0122] The base station transmits a related signal to the terminal through a downlink channel described below, and the terminal receives the related signal from the base station through a downlink channel described below.
[0123]
[0124] (1) Physical Downlink Shared Channel (PDSCH)
[0125] PDSCH carries downlink data (e.g., DL-shared channel transport block, DL-SCH TB) and modulation methods such as Quadrature Phase Shift Keying (QPSK), 16 Quadrature Amplitude Modulation (QAM), 64 QAM, and 256 QAM are applied. The TB is encoded to generate a codeword. PDSCH can carry multiple codewords. Scrambling and modulation mapping are performed for each codeword, and the modulation symbols generated from each codeword are mapped to one or more layers (Layer mapping). Each layer is mapped to resources along with a Demodulation Reference Signal (DMRS), generated as an OFDM symbol signal, and transmitted through the corresponding antenna port.
[0126]
[0127] (2) Physical downlink control channel (PDCCH)
[0128] The PDCCH carries downlink control information (DCI) and employs modulation methods such as QPSK. A PDCCH consists of 1, 2, 4, 8, or 16 Control Channel Elements (CCEs), depending on the Aggregation Level (AL). Each CCE is comprised of six Resource Element Groups (REGs). Each REG is defined by one OFDM symbol and one (P)RB.
[0129] The UE acquires DCI transmitted via the PDCCH by performing decoding (also known as blind decoding) on a set of PDCCH candidates. The set of PDCCH candidates decoded by the UE is defined as a PDCCH search space set. The search space set may be a common search space or a UE-specific search space. The UE can acquire DCI by monitoring PDCCH candidates within one or more search space sets established by the MIB or higher layer signaling.
[0130]
[0131] Uplink channel structure
[0132] The terminal transmits a related signal to the base station through the uplink channel described below, and the base station receives the related signal from the terminal through the uplink channel described below.
[0133] (1) Physical Uplink Shared Channel (PUSCH)
[0134] PUSCH carries uplink data (e.g., UL-shared channel transport block, UL-SCH TB) and / or uplink control information (UCI), and is transmitted based on a CP-OFDM (Cyclic Prefix - Orthogonal Frequency Division Multiplexing) waveform, a DFT-s-OFDM (Discrete Fourier Transform - spread - Orthogonal Frequency Division Multiplexing) waveform, etc. When the PUSCH is transmitted based on a DFT-s-OFDM waveform, the UE transmits the PUSCH by applying transform precoding. For example, when transform precoding is disabled (e.g., transform precoding is disabled), the UE transmits the PUSCH based on the CP-OFDM waveform, and when transform precoding is enabled (e.g., transform precoding is enabled), the UE can transmit the PUSCH based on the CP-OFDM waveform or the DFT-s-OFDM waveform. PUSCH transmissions can be dynamically scheduled by UL grants in DCI, or semi-statically scheduled (configured grant) based on higher layer (e.g., RRC) signaling (and / or Layer 1 (L1) signaling (e.g., PDCCH)). PUSCH transmissions can be performed in a codebook-based or non-codebook-based manner.
[0135] (2) Physical Uplink Control Channel (PUCCH)
[0136] PUCCH carries uplink control information, HARQ-ACK and / or scheduling request (SR), and can be divided into multiple PUCCHs depending on the PUCCH transmission length.
[0137]
[0138] Below, we describe new radio access technology (new RAT, NR).
[0139] As more and more communication devices demand greater communication capacity, the need for improved mobile broadband communication compared to existing radio access technology (RAT) is emerging. Furthermore, massive Machine Type Communications (MTC), which connects numerous devices and objects to provide various services anytime, anywhere, is also a key issue to be considered in next-generation communication. Furthermore, communication system design that considers reliability and latency-sensitive services / terminals is being discussed. The introduction of next-generation radio access technologies that take into account enhanced mobile broadband communication, massive MTC, and URLLC (Ultra-Reliable and Low Latency Communication) is being discussed, and in various embodiments of the present disclosure, these technologies are conveniently referred to as new RAT or NR.
[0140]
[0141] Figure 2 is a diagram illustrating the system structure of a New Generation Radio Access Network (NG-RAN).
[0142] Referring to FIG. 2, the NG-RAN may include a gNB and / or an eNB that provides user plane and control plane protocol termination to the UE. FIG. 1 illustrates a case where only a gNB is included. The gNB and eNB are connected to each other via an Xn interface. The gNB and eNB are connected to the 5th generation core network (5G Core Network: 5GC) via the NG interface. More specifically, the gNB is connected to the access and mobility management function (AMF) via the NG-C interface, and the gNB is connected to the user plane function (UPF) via the NG-U interface.
[0143]
[0144] Figure 3 is a diagram illustrating the functional division between NG-RAN and 5GC.
[0145] Referring to FIG. 3, the gNB can provide functions such as inter-cell radio resource management (Inter Cell RRM), radio bearer management (RB control), connection mobility control (Connection Mobility Control), radio admission control (Radio Admission Control), measurement configuration and provision, and dynamic resource allocation. The AMF can provide functions such as NAS security and idle state mobility processing. The UPF can provide functions such as mobility anchoring and PDU processing. The SMF (Session Management Function) can provide functions such as terminal IP address allocation and PDU session control.
[0146]
[0147] Figure 4 is a diagram illustrating an example of a 5G usage scenario.
[0148] The 5G usage scenario illustrated in FIG. 4 is merely exemplary, and the technical features of various embodiments of the present disclosure can also be applied to other 5G usage scenarios not illustrated in FIG. 4.
[0149] Referring to Figure 4, the three key requirement areas for 5G include (1) enhanced mobile broadband (eMBB), (2) massive machine type communication (mMTC), and (3) ultra-reliable and low latency communications (URLLC). Some use cases may require optimization across multiple areas, while others may focus on just one key performance indicator (KPI). 5G supports these diverse use cases in a flexible and reliable manner.
[0150] eMBB focuses on improving data speeds, latency, user density, and overall capacity and coverage of mobile broadband connections. It targets throughputs of around 10 Gbps. eMBB significantly exceeds basic mobile internet access, enabling rich interactive experiences, media and entertainment applications in the cloud, and augmented reality. Data is a key driver of 5G, and for the first time, dedicated voice services may not be available in the 5G era. In 5G, voice is expected to be handled as an application, simply using the data connection provided by the communication system. The increased traffic volume is primarily due to the increasing content size and the growing number of applications that require high data rates. Streaming services (audio and video), interactive video, and mobile internet connectivity will become more prevalent as more devices connect to the internet. Many of these applications require always-on connectivity to push real-time information and notifications to users. Cloud storage and applications are rapidly growing on mobile communication platforms, applicable to both work and entertainment. Cloud storage is a particular use case driving the growth of uplink data rates. 5G is also used for remote work in the cloud, requiring significantly lower end-to-end latency to maintain a superior user experience when tactile interfaces are used. In entertainment, for example, cloud gaming and video streaming are other key factors driving the demand for mobile broadband. Entertainment is essential on smartphones and tablets, regardless of location, including in highly mobile environments like trains, cars, and airplanes. Another use case is augmented reality and information retrieval for entertainment, where augmented reality requires extremely low latency and instantaneous data volumes.
[0151] mMTC is designed to enable communication between a large number of low-cost, battery-powered devices, supporting applications such as smart metering, logistics, field, and body sensors. mMTC targets a battery life of approximately 10 years and / or a population of approximately 1 million devices per square kilometer. mMTC enables seamless connectivity of embedded sensors across all sectors and is one of the most anticipated 5G use cases. The number of IoT devices is projected to reach 20.4 billion by 2020. Industrial IoT is one area where 5G will play a key role, enabling smart cities, asset tracking, smart utilities, agriculture, and security infrastructure.
[0152] URLLC is ideal for vehicle communications, industrial control, factory automation, remote surgery, smart grids, and public safety applications by enabling devices and machines to communicate with high reliability, very low latency, and high availability. URLLC targets latency on the order of 1 ms. URLLC encompasses new services that will transform industries through ultra-reliable, low-latency links, such as remote control of critical infrastructure and autonomous vehicles. This level of reliability and latency is essential for smart grid control, industrial automation, robotics, and drone control and coordination.
[0153] Next, we will look more specifically at a number of usage examples included within the triangle in Fig. 4.
[0154] 5G can complement fiber-to-the-home (FTTH) and cable-based broadband (or DOCSIS) by delivering streams rated at hundreds of megabits per second to gigabits per second. These high speeds may be required to deliver TV at resolutions beyond 4K (6K, 8K, and beyond), as well as virtual reality (VR) and augmented reality (AR). VR and AR applications include near-immersive sports events. Certain applications may require specialized network configurations. For example, for VR gaming, a gaming company may need to integrate its core servers with the network operator's edge network servers to minimize latency.
[0155] Automotive is expected to be a significant new driver for 5G, with numerous use cases for in-vehicle mobile communications. For example, passenger entertainment demands both high capacity and high mobile broadband, as future users will consistently expect high-quality connectivity regardless of their location and speed. Another automotive application is augmented reality dashboards. An AR dashboard allows drivers to identify objects in the dark on top of what they see through the windshield. The AR dashboard overlays information to inform the driver about the distance and movement of objects. In the future, wireless modules will enable vehicle-to-vehicle communication, information exchange between vehicles and supporting infrastructure, and information exchange between vehicles and other connected devices (e.g., devices accompanying pedestrians). Safety systems can guide drivers to safer driving behaviors, reducing the risk of accidents. The next step will be remotely controlled or autonomous vehicles, which require highly reliable and fast communication between different autonomous vehicles and / or between vehicles and infrastructure. In the future, autonomous vehicles will perform all driving tasks, leaving drivers to focus solely on traffic anomalies that the vehicle itself cannot detect. The technological requirements for autonomous vehicles will require ultra-low latency and ultra-high-speed reliability, increasing traffic safety to levels unattainable by humans.
[0156] Smart cities and smart homes, often referred to as smart societies, will be embedded with dense wireless sensor networks. A distributed network of intelligent sensors will identify conditions for cost- and energy-efficient maintenance of cities or homes. Similar setups can be implemented for individual homes. Temperature sensors, window and heating controllers, burglar alarms, and appliances will all be wirelessly connected. Many of these sensors typically require low data rates, low power, and low cost. However, for example, real-time HD video may be required from certain types of devices for surveillance purposes.
[0157] The consumption and distribution of energy, including heat and gas, are becoming increasingly decentralized, requiring automated control of distributed sensor networks. Smart grids interconnect these sensors using digital information and communication technologies to collect and act on information. This information can include the behavior of suppliers and consumers, enabling smart grids to improve efficiency, reliability, economic efficiency, sustainable production, and the automated distribution of fuels like electricity. Smart grids can also be viewed as another low-latency sensor network.
[0158] The health sector has numerous applications that can benefit from mobile communications. Telecommunications systems can support telemedicine, which provides clinical care in remote locations. This can help reduce distance barriers and improve access to health services that are otherwise unavailable in remote rural areas. It can also be used to save lives in critical care and emergency situations. Mobile-based wireless sensor networks can provide remote monitoring and sensors for parameters such as heart rate and blood pressure.
[0159] Wireless and mobile communications are becoming increasingly important in industrial applications. Wiring is expensive to install and maintain. Therefore, the potential to replace cables with reconfigurable wireless links presents an attractive opportunity for many industries. However, achieving this requires wireless connections to operate with similar latency, reliability, and capacity to cables, while simplifying their management. Low latency and extremely low error rates are new requirements for 5G connectivity.
[0160] Logistics and freight tracking are important use cases for mobile communications, enabling the tracking of inventory and packages anywhere using location-based information systems. Logistics and freight tracking typically require low data rates but may require wide-range and reliable location information.
[0161] Hereinafter, examples of next-generation communications (e.g., 6G) that can be applied to various embodiments of the present disclosure will be described.
[0162]
[0163] 6G system in general
[0164] The 6G (wireless communication) system aims to achieve (i) very high data rates per device, (ii) a very large number of connected devices, (iii) global connectivity, (iv) very low latency, (v) low energy consumption for battery-free IoT devices, (vi) ultra-reliable connectivity, and (vii) connected intelligence with machine learning capabilities. The vision of the 6G system can be divided into four aspects: intelligent connectivity, deep connectivity, holographic connectivity, and ubiquitous connectivity, and the 6G system can satisfy the requirements as shown in Table 1 below. In other words, Table 1 is a table showing an example of the requirements of a 6G system.
[0165]
[0166] Per device peak data rate1TbpsE2E latency1msMaximum spectral efficiency100bps / HzMobility supportUp to 1000km / hrSatellite integrationFullyAIFullyAutonomous vehicleFullyXRFullyHaptic CommunicationFully
[0167]
[0168] 6G systems can have key factors such as enhanced mobile broadband (eMBB), ultra-reliable low latency communications (URLLC), massive machine-type communication (mMTC), AI integrated communication, tactile internet, high throughput, high network capacity, high energy efficiency, low backhaul and access network congestion, and enhanced data security.
[0169]
[0170] Figure 5 is a diagram illustrating an example of a communication structure that can be provided in a 6G system.
[0171] 6G systems are expected to have 50 times the simultaneous wireless connectivity of 5G systems. URLLC, a key feature of 5G, will become even more crucial in 6G communications by providing end-to-end latency of less than 1 ms. 6G systems will have significantly higher volumetric spectral efficiency, compared to the commonly used area spectral efficiency. 6G systems can offer extremely long battery life and advanced battery technologies for energy harvesting, eliminating the need for separate charging for mobile devices in 6G systems. New network characteristics in 6G may include:
[0172] - Satellite integrated network: 6G is expected to integrate with satellites to provide a global mobile network. The integration of terrestrial, satellite, and airborne networks into a single wireless communications system is crucial for 6G.
[0173] - Connected intelligence: Unlike previous generations of wireless communication systems, 6G is revolutionary and will update the wireless evolution from “connected things” to “connected intelligence.” AI can be applied at each stage of the communication process (or at each stage of signal processing, as described below).
[0174] - Seamless integration of wireless information and energy transfer: 6G wireless networks will transfer power to charge the batteries of devices such as smartphones and sensors. Therefore, wireless information and energy transfer (WIET) will be integrated.
[0175] - Ubiquitous super 3D connectivity: Access to networks and core network functions of drones and very low Earth orbit satellites will create super 3D connectivity in 6G ubiquitous.
[0176] Some general requirements for the new network characteristics of 6G, such as the above, may be as follows:
[0177] - Small cell networks: The concept of small cell networks was introduced to improve received signal quality in cellular systems by increasing throughput, energy efficiency, and spectral efficiency. Consequently, small cell networks are essential for 5G and beyond-5G (5GB) communication systems. Accordingly, 6G communication systems also adopt the characteristics of small cell networks.
[0178] Ultra-dense heterogeneous networks: Ultra-dense heterogeneous networks will be another key feature of 6G communication systems. Multi-tier networks comprised of heterogeneous networks improve overall QoS and reduce costs.
[0179] High-capacity backhaul: Backhaul connections are characterized by high-capacity backhaul networks to support high-volume traffic. High-speed fiber optics and free-space optics (FSO) systems may be potential solutions to this problem.
[0180] - Radar technology integrated with mobile technology: High-precision localization (or location-based services) through communications is a key feature of 6G wireless communication systems. Therefore, radar systems will be integrated with 6G networks.
[0181] - Softwarization and virtualization: Softwarization and virtualization are two critical features that form the foundation of the design process for 5GB networks to ensure flexibility, reconfigurability, and programmability. Furthermore, billions of devices can be shared on a shared physical infrastructure.
[0182]
[0183] Core implementation technology of 6G systems
[0184] Artificial Intelligence
[0185] The most crucial and newly introduced technology for 6G systems is AI. 4G systems did not involve AI. 5G systems will support partial or very limited AI. However, 6G systems will fully support AI for automation. Advances in machine learning will create more intelligent networks for real-time communications in 6G. Incorporating AI into communications can streamline and improve real-time data transmission. AI can use numerous analyses to determine how complex target tasks should be performed. In other words, AI can increase efficiency and reduce processing delays.
[0186] Time-consuming tasks such as handover, network selection, and resource scheduling can be performed instantly using AI. AI can also play a crucial role in machine-to-machine (M2M), machine-to-human, and human-to-machine communications. Furthermore, AI can facilitate rapid communication in brain-computer interfaces (BCIs). AI-based communication systems can be supported by metamaterials, intelligent structures, intelligent networks, intelligent devices, intelligent cognitive radios, self-sustaining wireless networks, and machine learning.
[0187] Recent attempts to integrate AI into wireless communication systems have focused on the application layer, network layer, and especially deep learning in wireless resource management and allocation. However, this research is increasingly evolving to the MAC layer and physical layer, with attempts to combine deep learning with wireless transmission, particularly at the physical layer. AI-based physical layer transmission refers to the application of AI-based signal processing and communication mechanisms, rather than traditional communication frameworks, in the fundamental signal processing and communication mechanisms. For example, this may include deep learning-based channel coding and decoding, deep learning-based signal estimation and detection, deep learning-based MIMO mechanisms, and AI-based resource scheduling and allocation.
[0188] Machine learning can be used for channel estimation and channel tracking, as well as for power allocation and interference cancellation in the physical layer of the downlink (DL). Furthermore, machine learning can be used for antenna selection, power control, and symbol detection in MIMO systems.
[0189] However, the application of DNN for transmission at the physical layer may have the following problems.
[0190] Deep learning-based AI algorithms require a large amount of training data to optimize training parameters. However, due to limitations in obtaining training data from specific channel environments, a large amount of training data is used offline. This means that static training on training data in specific channel environments can lead to conflicts with the dynamic characteristics and diversity of the wireless channel.
[0191] Furthermore, current deep learning primarily targets real-world signals. However, signals at the physical layer of wireless communications are complex signals. Further research is needed on neural networks that detect complex-domain signals to match the characteristics of wireless communication signals.
[0192] Below, we will look at machine learning in more detail.
[0193] Machine learning refers to a series of operations that train machines to perform tasks that humans can or cannot perform. Machine learning requires data and a learning model. Data learning methods in machine learning can be broadly categorized into three types: supervised learning, unsupervised learning, and reinforcement learning.
[0194] Neural network training aims to minimize output errors. It involves repeatedly inputting training data into a neural network, calculating the neural network output and target error for the training data, and backpropagating the neural network error from the output layer to the input layer to update the weights of each node in the neural network to reduce the error.
[0195] Supervised learning uses labeled training data, while unsupervised learning may not have labeled training data. For example, in the case of supervised learning for data classification, the training data may be data in which each training data category is labeled. Labeled training data is input to a neural network, and the error can be calculated by comparing the output (categories) of the neural network with the training data labels. The calculated error is backpropagated through the neural network in the backward direction (i.e., from the output layer to the input layer), and the connection weights of each node in each layer of the neural network can be updated through backpropagation. The amount of change in the connection weights of each updated node can be determined by the learning rate. The neural network's calculation of the input data and the backpropagation of the error can constitute a learning cycle (epoch). The learning rate can be applied differently depending on the number of iterations of the neural network's learning cycle. For example, in the early stages of training a neural network, a high learning rate can be used to quickly allow the network to achieve a certain level of performance, thereby increasing efficiency. In the later stages of training, a low learning rate can be used to increase accuracy.
[0196] Learning methods may vary depending on the characteristics of the data. For example, if the goal is to accurately predict data transmitted by a transmitter in a communication system, supervised learning is preferable to unsupervised learning or reinforcement learning.
[0197] The learning model corresponds to the human brain, and the most basic linear model can be thought of, but the machine learning paradigm that uses highly complex neural network structures, such as artificial neural networks, as learning models is called deep learning.
[0198] The neural network cores used in learning methods are mainly divided into deep neural networks (DNN), convolutional deep neural networks (CNN), and recurrent boltzmann machines (RNN).
[0199] An artificial neural network is an example of a network of multiple perceptrons.
[0200]
[0201] Figure 6 is a schematic diagram illustrating an example of a perceptron structure.
[0202] Referring to Fig. 6, when an input vector x=(x1,x2,...,xd) is input, the entire process of multiplying each component by a weight (W1,W2,...,Wd), adding up all the results, and then applying the activation function σ(·) is called a perceptron. A large-scale artificial neural network structure can extend the simplified perceptron structure illustrated in Fig. 6 to apply the input vector to perceptrons of different dimensions. For convenience of explanation, input values or output values are called nodes.
[0203] Meanwhile, the perceptron structure illustrated in Fig. 6 can be explained as consisting of a total of three layers based on input and output values. An artificial neural network in which there are H perceptrons of (d+1) dimensions between the 1st layer and the 2nd layer, and K perceptrons of (H+1) dimensions between the 2nd layer and the 3rd layer can be expressed as in Fig. 7.
[0204]
[0205] Figure 7 is a schematic diagram illustrating an example of a multilayer perceptron structure.
[0206] The layer where the input vector is located is called the input layer, the layer where the final output value is located is called the output layer, and all layers located between the input layer and the output layer are called hidden layers. The example in Fig. 7 shows three layers, but when counting the number of layers in an actual artificial neural network, the input layer is excluded, so it can be viewed as a total of two layers. An artificial neural network is composed of perceptrons, which are basic blocks, connected in two dimensions.
[0207] The aforementioned input, hidden, and output layers can be applied jointly not only to multilayer perceptrons but also to various artificial neural network structures, such as CNNs and RNNs, which will be described later. The greater the number of hidden layers, the deeper the artificial neural network. The machine learning paradigm that uses sufficiently deep artificial neural networks as learning models is called deep learning. Furthermore, the artificial neural network used for deep learning is called a deep neural network (DNN).
[0208]
[0209] Figure 8 is a schematic diagram illustrating an example of a deep neural network.
[0210] The deep neural network illustrated in Figure 8 is a multilayer perceptron consisting of eight hidden layers and eight output layers. The multilayer perceptron structure is referred to as a fully connected neural network. In a fully connected neural network, there is no connection between nodes located in the same layer, and there is a connection only between nodes located in adjacent layers. DNN has a fully connected neural network structure and is composed of a combination of multiple hidden layers and activation functions, and can be usefully applied to identify correlation characteristics between inputs and outputs. Here, the correlation characteristic can mean the joint probability of inputs and outputs.
[0211] Meanwhile, depending on how multiple perceptrons are connected to each other, various artificial neural network structures different from the aforementioned DNN can be formed.
[0212]
[0213] Figure 9 is a schematic diagram illustrating an example of a convolutional neural network.
[0214] In DNN, nodes located within a single layer are arranged in a one-dimensional vertical direction. However, Fig. 9 can assume a case where nodes are arranged two-dimensionally, with w nodes in width and h nodes in height (the convolutional neural network structure of Fig. 9). In this case, since a weight is added to each connection in the connection process from one input node to the hidden layer, a total of hХw weights must be considered. Since there are hХw nodes in the input layer, a total of h2w2 weights are required between two adjacent layers.
[0215] The convolutional neural network of Fig. 9 has a problem in that the number of weights increases exponentially according to the number of connections. Therefore, instead of considering the connections of all modes between adjacent layers, it assumes that there are small filters, and performs weighted sum and activation function operations on the overlapping portions of the filters, as in Fig. 10.
[0216]
[0217] Figure 10 is a schematic diagram illustrating an example of a filter operation in a convolutional neural network.
[0218] Each filter has a weight corresponding to the number of its size, and learning of the weights can be performed so that a specific feature on the image can be extracted as a factor and output. In Fig. 10, a filter of size 3Х3 is applied to the upper left 3Х3 region of the input layer, and the output value resulting from performing weighted sum and activation function operations on the corresponding node is stored in z22.
[0219] The above filter performs weighted sum and activation function operations while moving at a certain horizontal and vertical interval while scanning the input layer, and places the output value at the current filter position. This operation method is similar to the convolution operation for images in the field of computer vision, so a deep neural network with this structure is called a convolutional neural network (CNN), and the hidden layer generated as a result of the convolution operation is called a convolutional layer. In addition, a neural network with multiple convolutional layers is called a deep convolutional neural network (DCNN).
[0220] In the convolutional layer, the number of weights can be reduced by calculating a weighted sum that includes only the nodes located in the area covered by the filter, starting from the node where the current filter is located. This allows a single filter to focus on features within a local area. Accordingly, CNNs can be effectively applied to image data processing where physical distance in a two-dimensional area is an important criterion for judgment. Meanwhile, CNNs can apply multiple filters immediately before the convolutional layer, and can generate multiple output results through the convolution operation of each filter.
[0221] Meanwhile, depending on the data properties, there may be data for which sequence characteristics are important. Considering the length variability and chronological relationship of such sequence data, a structure that applies a method of inputting one element of the data sequence at each timestep and inputting the output vector (hidden vector) of the hidden layer output at a specific timestep together with the immediately following element in the sequence is called a recurrent neural network structure.
[0222]
[0223] Figure 11 is a schematic diagram illustrating an example of a neural network structure in which a recurrent loop exists.
[0224] Referring to Figure 11, a recurrent neural network (RNN) is a structure that inputs elements (x1(t), x2(t), ,..., xd(t)) of a data sequence at a time point t into a fully connected neural network, and then inputs the hidden vectors (z1(t-1), z2(t-1),..., zH(t-1)) of the immediately preceding time point t-1 together and applies a weighted sum and activation function. The reason for transmitting the hidden vector to the next time point in this way is because the information in the input vectors of the preceding time points is considered to be accumulated in the hidden vector of the current time point.
[0225]
[0226] Figure 12 is a diagram schematically illustrating an example of the operating structure of a recurrent neural network.
[0227] Referring to Figure 12, the recurrent neural network operates in a predetermined order of time for the input data sequence.
[0228] When the input vector (x1(t), x2(t), ,..., xd(t)) at time point 1 is input to the recurrent neural network, the hidden vector (z1(1), z2(1),..., zH(1)) is input together with the input vector (x1(2), x2(2),..., xd(2)) at time point 2, and the vector (z1(2), z2(2),..., zH(2)) of the hidden layer is determined through a weighted sum and an activation function. This process is repeatedly performed until time points 2, 3, ,,, T.
[0229] Meanwhile, when multiple hidden layers are placed within a recurrent neural network, it is called a deep recurrent neural network (DRNN). Recurrent neural networks are designed to be useful for processing sequence data (e.g., natural language processing).
[0230] It is a neural network core used in a learning manner, and includes various deep learning techniques such as DNN, CNN, RNN, Restricted Boltzmann Machine (RBM), Deep Belief Network (DBN), and Deep Q-Network, and can be applied to fields such as computer vision, speech recognition, natural language processing, and speech / signal processing.
[0231] Recent attempts to integrate AI into wireless communication systems have focused on the application layer, network layer, and especially deep learning in wireless resource management and allocation. However, this research is increasingly evolving to the MAC layer and physical layer, with attempts to combine deep learning with wireless transmission, particularly at the physical layer. AI-based physical layer transmission refers to the application of AI-based signal processing and communication mechanisms, rather than traditional communication frameworks, in the fundamental signal processing and communication mechanisms. For example, this may include deep learning-based channel coding and decoding, deep learning-based signal estimation and detection, deep learning-based MIMO mechanisms, and AI-based resource scheduling and allocation.
[0232] THz (Terahertz) communication
[0233] Data rates can be increased by increasing bandwidth. This can be achieved by utilizing sub-THz communications with wide bandwidths and applying advanced massive MIMO technology. THz waves, also known as sub-millimeter waves, typically refer to the frequency range between 0.1 THz and 10 THz, with corresponding wavelengths ranging from 0.03 mm to 3 mm. The 100 GHz to 300 GHz band (sub-THz band) is considered a key part of the THz band for cellular communications. Adding the sub-THz band to the mmWave band will increase the capacity of 6G cellular communications. Among the defined THz bands, 300 GHz to 3 THz lies in the far infrared (IR) frequency band. While part of the optical band, the 300 GHz to 3 THz band lies at the boundary of the optical band, immediately following the RF band. Therefore, this 300 GHz to 3 THz band exhibits similarities to RF.
[0234]
[0235] Figure 13 is a diagram illustrating an example of the electromagnetic spectrum.
[0236] Key characteristics of THz communications include (i) the widely available bandwidth to support very high data rates and (ii) the high path loss that occurs at high frequencies (requiring highly directional antennas). The narrow beamwidths generated by highly directional antennas reduce interference. The small wavelength of THz signals allows for a significantly larger number of antenna elements to be integrated into devices and base stations operating in this band. This enables the use of advanced adaptive array technologies to overcome range limitations.
[0237] Optical wireless technology
[0238] OWC technology is designed for 6G communications, in addition to RF-based communications for all possible device-to-access networks. These networks connect to network-to-backhaul / fronthaul networks. OWC technology has already been used in 4G communication systems, but it will be used more widely to meet the demands of 6G communication systems. OWC technologies such as light fidelity, visible light communication, optical camera communication, and wideband-based FSO communication are already well-known. Communications based on optical wireless technology can provide very high data rates, low latency, and secure communications. LiDAR can also be used for ultra-high-resolution 4D mapping in 6G communications based on wideband.
[0239] FSO backhaul network
[0240] The transmitter and receiver characteristics of an FSO system are similar to those of a fiber-optic network. Therefore, data transmission in an FSO system is similar to that of a fiber-optic system. Therefore, FSO can be a promising technology for providing backhaul connectivity in 6G systems, in conjunction with fiber-optic networks. Using FSO, ultra-long-distance communications are possible, even over distances exceeding 10,000 km. FSO supports high-capacity backhaul connectivity for remote and non-remote areas, such as the ocean, space, underwater, and isolated islands. FSO also supports cellular base station (BS) connections.
[0241] Massive MIMO technology
[0242] One of the key technologies for improving spectral efficiency is the application of MIMO technology. As MIMO technology improves, spectral efficiency also improves. Therefore, massive MIMO technology will be crucial in 6G systems. Because MIMO technology utilizes multiple paths, multiplexing technology must be considered to ensure that data signals can be transmitted along more than one path, as well as beam generation and operation technologies suitable for the THz band.
[0243] Blockchain
[0244] Blockchain will become a crucial technology for managing massive amounts of data in future communication systems. Blockchain is a form of distributed ledger technology. A distributed ledger is a database distributed across numerous nodes or computing devices. Each node replicates and stores an identical copy of the ledger. Blockchains are managed by a peer-to-peer network and can exist without being managed by a central authority or server. Data on a blockchain is collected and organized into blocks. Blocks are linked together and protected using cryptography. Blockchain perfectly complements large-scale IoT with its inherently enhanced interoperability, security, privacy, reliability, and scalability. Therefore, blockchain technology offers several features, such as interoperability between devices, traceability of large amounts of data, autonomous interaction with other IoT systems, and the massive connectivity stability of 6G communication systems.
[0245] 3D networking
[0246] 6G systems integrate terrestrial and airborne networks to support vertically expanded user communications. 3D BS will be provided via low-orbit satellites and UAVs. Adding a new dimension in altitude and associated degrees of freedom, 3D connections differ significantly from existing 2D networks.
[0247] Quantum communication
[0248] Unsupervised reinforcement learning holds promise in the context of 6G networks. Supervised learning approaches cannot label the massive amounts of data generated by 6G networks. Unsupervised learning does not require labeling. Therefore, this technology can be used to autonomously build representations of complex networks. Combining reinforcement learning and unsupervised learning allows for truly autonomous network operation.
[0249] drone
[0250] Unmanned Aerial Vehicles (UAVs), or drones, will be a key element in 6G wireless communications. In most cases, high-speed wireless connections will be provided using UAV technology. BS entities are installed on UAVs to provide cellular connectivity. UAVs offer specific capabilities not found in fixed BS infrastructure, such as easy deployment, robust line-of-sight links, and controlled mobility. During emergencies such as natural disasters, deploying terrestrial communication infrastructure is not economically feasible, and sometimes, volatile environments make it impossible to provide services. UAVs can easily handle these situations. UAVs will become a new paradigm in wireless communications. This technology facilitates three fundamental requirements for wireless networks: enhanced mobile broadband (eMBB), URLLC, and mMTC. UAVs can also support various purposes, such as enhancing network connectivity, fire detection, disaster emergency services, security and surveillance, pollution monitoring, parking monitoring, and accident monitoring. Therefore, UAV technology is recognized as one of the most important technologies for 6G communications.
[0251] Cell-free Communication
[0252] Tight integration of multiple frequencies and heterogeneous communication technologies is crucial in 6G systems. As a result, users will be able to seamlessly move from one network to another without requiring any manual configuration on their devices. The best network will be automatically selected from available communication technologies. This will break the limitations of the cell concept in wireless communications. Currently, user movement from one cell to another in dense networks results in excessive handovers, resulting in handover failures, handover delays, data loss, and a ping-pong effect. 6G cell-free communications will overcome all of these challenges and provide better QoS. Cell-free communications will be achieved through multi-connectivity and multi-tier hybrid technologies, as well as heterogeneous radios on devices.
[0253] Integration of wireless information and energy transmission
[0254] WIET uses the same fields and waves as wireless communication systems. Specifically, sensors and smartphones will be charged using wireless power transfer during communication. WIET is a promising technology for extending the life of battery-powered wireless systems. Therefore, battery-less devices will be supported by 6G communications.
[0255] Integration of sensing and communication
[0256] Autonomous wireless networks are capable of continuously sensing dynamically changing environmental conditions and exchanging information between different nodes. In 6G, sensing will be tightly integrated with communications to support autonomous systems.
[0257] Integration of Access Backhaul Networks
[0258] In 6G, the density of access networks will be enormous. Each access network will be connected to backhaul connections, such as fiber optics and FSO networks. To accommodate the massive number of access networks, there will be tight integration between access and backhaul networks.
[0259] Holographic beam forming
[0260] Beamforming is a signal processing procedure that adjusts an antenna array to transmit a wireless signal in a specific direction. It is a subset of smart antennas or advanced antenna systems. Beamforming technology offers several advantages, including high signal-to-noise ratio, interference avoidance and rejection, and high network efficiency. Holographic beamforming (HBF) is a novel beamforming method that differs significantly from MIMO systems because it uses software-defined antennas. HBF will be a highly effective approach for efficient and flexible signal transmission and reception in multi-antenna communication devices in 6G.
[0261] Big data analysis
[0262] Big data analytics is a complex process for analyzing diverse, large-scale data sets, or "big data." This process uncovers hidden data, unknown correlations, and customer trends, ensuring complete data management. Big data is collected from various sources, such as video, social networks, images, and sensors. This technology is widely used to process massive amounts of data in 6G systems.
[0263] Large Intelligent Surface (LIS)
[0264] THz-band signals have strong linearity, which can create many shadow areas due to obstacles. LIS technology, which enables expanded communication coverage, enhanced communication stability, and additional value-added services by installing LIS near these shadow areas, is becoming increasingly important. LIS is an artificial surface made of electromagnetic materials that can alter the propagation of incoming and outgoing radio waves. While LIS can be viewed as an extension of massive MIMO, it differs from massive MIMO in its array structure and operating mechanism. Furthermore, LIS operates as a reconfigurable reflector with passive elements, passively reflecting signals without using active RF chains, which offers the advantage of low power consumption. Furthermore, because each passive reflector in LIS must independently adjust the phase shift of the incoming signal, this can be advantageous for wireless communication channels. By appropriately adjusting the phase shift via the LIS controller, the reflected signal can be collected at the target receiver to boost the received signal power.
[0265] Terahertz (THz) wireless communications in general
[0266] THz wireless communication uses THz waves with a frequency of approximately 0.1 to 10 THz (1 THz = 1012 Hz), and can refer to terahertz (THz) band wireless communication using a very high carrier frequency of 100 GHz or higher. THz waves are located between the RF (Radio Frequency) / millimeter (mm) and infrared bands, and (i) compared to visible light / infrared light, they penetrate non-metallic / non-polarizable materials well, and compared to RF / millimeter waves, they have a shorter wavelength, so they have high linearity and can focus beams. In addition, since the photon energy of THz waves is only a few meV, they have the characteristic of being harmless to the human body. The frequency bands expected to be used for THz wireless communication may be the D-band (110 GHz to 170 GHz) or H-band (220 GHz to 325 GHz), which have low propagation loss due to molecular absorption in the air. Discussions on standardization of THz wireless communication are being centered around the IEEE 802.15 THz working group in addition to 3GPP, and standard documents issued by the IEEE 802.15 Task Group (TG3d, TG3e) may specify or supplement the contents described in various embodiments of the present disclosure. THz wireless communication can be applied to wireless cognition, sensing, imaging, wireless communication, THz navigation, etc.
[0267]
[0268] Figure 14 is a diagram illustrating an example of a THz communication application.
[0269] As illustrated in Figure 14, THz wireless communication scenarios can be categorized into macro networks, micro networks, and nanoscale networks. In macro networks, THz wireless communication can be applied to vehicle-to-vehicle and backhaul / fronthaul connections. In micro networks, THz wireless communication can be applied to fixed point-to-point or multi-point connections, such as indoor small cells, wireless connections in data centers, and near-field communications, such as kiosk downloads.
[0270] Table 2 below shows examples of technologies that can be used in THz waves.
[0271] Transceivers DeviceAvailable immature: UTC-PD, RTD and SBDModulation and CodingLow order modulation techniques (OOK, QPSK), LDPC, Reed Soloman, Hamming, Polar, TurboAntennaOmni and Directional, phased array with low number of antenna elementsBandwidth69GHz (or 23 GHz) at 300GHzChannel modelsPartiallyData rate100GbpsOutdoor deploymentNoFree space lossHighCoverageLowRadio Measurements300GHz indoorDevice sizeFew micrometers
[0272]
[0273] THz wireless communications can be categorized based on the methods used to generate and receive THz waves. THz generation methods can be categorized as either optical or electronic-based.
[0274]
[0275] Fig. 15 is a diagram illustrating an example of an electronic component-based THz wireless communication transmitter and receiver.
[0276] Methods for generating THz using electronic components include a method using semiconductor components such as a resonant tunneling diode (RTD), a method using a local oscillator and a multiplier, a MMIC (Monolithic Microwave Integrated Circuits) method using an integrated circuit based on a compound semiconductor HEMT (High Electron Mobility Transistor), and a method using a Si-CMOS-based integrated circuit. In the case of Fig. 15, a multiplier (doubler, tripler, multiplier) is applied to increase the frequency, and it passes through a subharmonic mixer and is radiated by an antenna. Since the THz band forms a high frequency, a multiplier is essential. Here, the multiplier is a circuit that has an output frequency that is N times that of the input, and matches it to the desired harmonic frequency and filters out all remaining frequencies. In addition, beamforming can be implemented by applying an array antenna or the like to the antenna of Fig. 15. In Fig. 15, IF represents intermediate frequency, tripler and multiplexer represent multipliers, PA represents power amplifier, LNA represents low noise amplifier, and PLL represents phase-locked loop.
[0277]
[0278] FIG. 16 is a diagram illustrating an example of a method for generating a THz signal based on an optical element.
[0279] Fig. 17 is a diagram illustrating an example of an optical element-based THz wireless communication transceiver.
[0280] Optical component-based THz wireless communication technology refers to a method of generating and modulating THz signals using optical components. Optical component-based THz signal generation technology generates an ultra-high-speed optical signal using a laser and an optical modulator, and converts it into a THz signal using an ultra-high-speed photodetector. Compared to technologies that use only electronic components, this technology can easily increase the frequency, generate high-power signals, and obtain flat response characteristics over a wide frequency band. As illustrated in Figure 16, optical component-based THz signal generation requires a laser diode, a wideband optical modulator, and an ultra-high-speed photodetector. In the case of Figure 16, the light signals of two lasers with different wavelengths are combined to generate a THz signal corresponding to the wavelength difference between the lasers. In Fig. 16, an optical coupler refers to a semiconductor device that transmits an electrical signal using optical waves to provide electrical isolation and coupling between circuits or systems, and a UTC-PD (Uni-Travelling Carrier Photo-Detector) is a type of photodetector that uses electrons as active carriers and reduces the travel time of electrons with bandgap grading. The UTC-PD is capable of detecting light at 150 GHz or higher. In Fig. 17, an EDFA (Erbium-Doped Fiber Amplifier) represents an erbium-doped fiber amplifier, a PD (Photo Detector) represents a semiconductor device that can convert an optical signal into an electrical signal, an OSA represents an optical module (Optical Sub Assembly) that modularizes various optical communication functions (photoelectric conversion, electro-optical conversion, etc.) into a single component, and a DSO represents a digital storage oscilloscope.
[0281]
[0282] The structure of a photoelectric converter (or photoelectric converter) is described with reference to FIGS. 18 and 19.
[0283] Fig. 18 is a diagram illustrating the structure of a photon source-based transmitter.
[0284] Figure 19 is a drawing showing the structure of an optical modulator.
[0285] In general, the phase of a signal can be changed by passing the optical source of a laser through an optical wave guide. At this time, data is loaded by changing the electrical characteristics through a microwave contact, etc. Therefore, the optical modulator output is formed as a modulated waveform. An opto-electrical modulator (O / E converter) can generate THz pulses by optical rectification operation by a nonlinear crystal, photoelectric conversion by a photoconductive antenna, emission from a bunch of relativistic electrons, etc. Terahertz pulses generated in the above manner can have a length in units of femtoseconds to picoseconds. An optical / electronic converter (O / E converter) performs down conversion by utilizing the non-linearity of the device.
[0286] Considering the THz spectrum usage, it is likely that THz systems will use multiple contiguous gigahertz bands for fixed or mobile service purposes. Based on the outdoor scenario criteria, the available bandwidth can be classified based on the oxygen attenuation of 10^2 dB / km in the spectrum up to 1 THz. Accordingly, a framework in which the available bandwidth is composed of multiple band chunks can be considered. As an example of the above framework, if the THz pulse length for one carrier is set to 50 ps, the bandwidth (BW) becomes approximately 20 GHz.
[0287] Effective down-conversion from the infrared band (IR band) to the terahertz band (THz band) depends on how to utilize the nonlinearity of the optical / electrical converter (O / E converter). In other words, to down-convert to the desired terahertz band (THz band), it is necessary to design an optical / electrical converter (O / E converter) with the most ideal non-linearity for transferring to the corresponding terahertz band (THz band). If an optical / electrical converter (O / E converter) that is not suitable for the target frequency band is used, errors are likely to occur in the amplitude and phase of the corresponding pulse.
[0288] In a single-carrier system, a terahertz transmission and reception system can be implemented using a single optical-to-electrical converter. Depending on the channel environment, in a multi-carrier system, the number of optical-to-electrical converters may be equal to the number of carriers. This phenomenon will be particularly noticeable in a multi-carrier system that utilizes multiple broadbands according to the aforementioned spectrum usage plan. In this regard, a frame structure for the multi-carrier system may be considered. A signal down-converted using an optical-to-electrical converter may be transmitted in a specific resource region (e.g., a specific frame). The frequency region of the specific resource region may include multiple chunks. Each chunk may be composed of at least one component carrier (CC).
[0289]
[0290] Specific descriptions of various embodiments of the present disclosure
[0291] Hereinafter, various embodiments of the present disclosure will be described in more detail.
[0292]
[0293] The present disclosure relates to a method and apparatus for supporting a quantum coherent time-based quantum public key infrastructure with a hybrid approach in a quantum communication system.
[0294]
[0295] Background to various embodiments of the present disclosure
[0296] User authentication technology
[0297] FIG. 20 is a diagram illustrating an example of a man-in-the-middle attack in a system applicable to the present disclosure.
[0298] In quantum communication systems, the security of information transmitted via a quantum channel is guaranteed by the non-cloning theorem, a quantum mechanical property. This allows for the security of transmitted messages to be determined through a QBER (Quantum Bit Error Rate) estimation process, utilizing a portion of the information transmitted via the quantum channel. This allows for the detection of eavesdropping by a third party. Therefore, the security of the transmitted message can be guaranteed. However, as shown in Figure 20, if Eve, a third party, exists between Alice (the sender) and Bob (the receiver), attempting a man-in-the-middle attack by pretending to be the receiver to Alice and the sender to Bob, the QBER estimation results from the information transmission between Alice and Eve, and Eve and Bob, cannot be used to detect Eve's presence. This allows Eve to access all the transmitted data while relaying it, and could even attempt to falsify or modify it. Therefore, to prevent this, a user authentication process is required, verifying that both the sender and receiver, the parties exchanging information, are authorized users.
[0299] Existing authentication techniques can be divided into hash function-based methods that incorporate cryptographic strengths and methods based on security from an information-theoretic perspective. First, cryptographic hash function-based methods are used as authentication techniques based on the computational complexity of the hash function's collision probability. Among current cryptographic techniques, the SHA technique is known as a representative hash function-based technique. However, because this technique relies on computational complexity, it is highly likely that its security will be threatened in the future with the advent of quantum computers. To strengthen security, current quantum cryptography communication systems use a family of keyed hash functions that combine symmetric keys and hash functions based on information-theoretic security as an authentication technique. Furthermore, quantum communication standards organizations such as ETSI have adopted this method as a standard authentication method. This method uses a hash function called Strongly Universal Hashing as a Message Authentication Code (MAC) algorithm to generate a Message Authentication Code (MAC) to be used in the authentication process, and additionally uses a symmetric key used as a one-time pad (OTP) in the generation process. Since it is very unlikely that information can be recovered through the reverse process from the MAC without knowing the key information, it is currently known to have the highest level of security. A representative method is the Wegman & Carter Authentication (WCA) technique proposed by M. Wegman and J. Carter. Currently, authentication techniques of the WCA series are applied as standard authentication methods for quantum information transmission techniques such as QKD, and the detailed structure of WCA is as follows.
[0300]
[0301] Classical authentication method: Message authentication code (MAC) by Wegman & Carter
[0302] FIG. 21 is a diagram illustrating an example of a MAC-based authentication technique in a system applicable to the present disclosure.
[0303] MAC is used to verify the integrity of a message. As shown in Figure 21, it is difficult for a third party who does not know the one-time symmetric key information previously shared between the sender and receiver to determine which MAC algorithm was used when generating the MAC. Before the authentication process, the sender and receiver share the same symmetric key information and MAC algorithm. When the sender inputs the plaintext message to be used for authentication into the MAC algorithm, the MAC algorithm to be used is selected based on the pre-shared key value. Next, when the plaintext is input into the selected MAC algorithm, a MAC is generated as the output value. To generate the MAC for the receiver, the sender transmits the plaintext message and MAC it generated via a classical channel. The receiver passes the received plaintext message through its MAC algorithm. Since the receiver possesses the same pre-shared key as the sender, it can generate the MAC using the same MAC algorithm. Finally, the MAC transmitted by the sender is compared with the MAC generated by the receiver to determine if they match. If the two values match, authentication is successful. If the two values do not match, authentication fails. In the MAC method, the pre-shared symmetric key information is ultimately not transmitted over a traditional channel, but is held only by the agreed-upon sender and receiver. Therefore, even if a third party were to obtain the message information without securing the symmetric key, they would not be able to determine which MAC algorithm is being applied. Therefore, this method guarantees security. Therefore, the security of this technique is higher as the number of MAC algorithm configuration methods increases.
[0304]
[0305] FIG. 22 is a diagram illustrating an example of Wegman & Carter Authentication (WCA) in a system applicable to the present disclosure.
[0306] The quantum key distribution (QKD) protocol, which is currently being applied as a security technology for 4G LTE / 5G, uses the WCA technique proposed by Wegman and Carter as a standard authentication technology, and uses the method of Fig. 22 to generate a tag with a MAC to be used for authentication using a symmetric key generated in the form of a one time pad and a Strongly Universal Hash class.
[0307] This technique can be applied to both user authentication to check whether the sender and receiver have changed during message transmission and message authentication to check whether the content and order of message information have changed. Here, similar to MAC, tag information that acts as a MAC is generated using a pre-shared key and MAC algorithm. The MAC algorithm used here is the hash function set H of the Strongly Universal Hash class. And the pre-shared key information in the sender and receiver is a hash function h in H. k It plays a role in selecting whether to use the pre-shared key, and the length of the pre-shared key is assigned as log2|H| bits, where |H| means the number of hash functions that make up the hash function set. Next, the tag information is T=h k (m) is denoted as a hash function h selected from a pre-shared key as an input value for the message m of the authentication process. k It is obtained from the result obtained after passing. Finally, the tag information transmitted from the transmitter and the message received from the receiver are compared with the tag information of the receiver obtained from the receiver's pre-shared key and hash function to check if they match and then determine whether authentication is necessary.
[0308] As mentioned earlier, the Wegman & Carter authentication scheme uses a hash function as a MAC algorithm. A hash function is a function that takes information of any length and outputs a fixed-length hash value. It is also called a message digest because it reduces a sentence of the original length to a fixed size. The reason the hash function is used as a MAC in the authentication process is because it has the following three characteristics.
[0309] (1) 1st Preimage resistance: For any given output value y, it is computationally impossible to find an input value x that satisfies y = h(x).
[0310] (2) 2nd Preimage resistance: When there is h(x) for a given input value x and h(x)=h(x`), it is computationally infeasible to find another input value x` that satisfies x≠x`.
[0311] (3) Collision resistance: It is computationally infeasible to find two input values x and x` that satisfy the hash value h(x) = h(x`).
[0312]
[0313] FIG. 23 is a diagram illustrating an example of collision probability in Wegman & Carter Authentication (WCA) in a system applicable to the present disclosure.
[0314] WCA is a Man-in-the-middle attack. When Eve replaces message m with m' and guesses and sends a tag, Eve does not know which hash function the sender and receiver used, so she selects a random hash function to guess the tag, and the success probability is 1 / |T|. (Here, |T| represents the number of tags.) In other words, the number of tags is determined by the number of types of hash functions |H| used, so the more types of hash functions are used, the lower the possibility that Eve will guess the tag. In other words, as in the collision probability formula in Fig. 23, the larger the number of hash functions, the lower the collision probability.
[0315] Ref. 1) T. Krovetz and W. Dai (2007). "VMAC: Message Authentication Code using Universal Hashing". CFRG Working Group. IETF. Retrieved 2010-08-12
[0316] Ref. 2) J. Carter; Wegman, M. (1977). “Universal classes of hash functions”. Proceedings of the Ninth Annual ACM Symposium on Theory of Computing. ACM: 106?112.
[0317] Ref. 3) J. Carter; Wegman, M. (1981). “New hash functions and their use in authentication and set equality”. Journal of Computer and System Sciences. 22 (3): 265-279.
[0318]
[0319] Quantum No-cloning Theorem
[0320] FIG. 24 is a diagram illustrating an example of a concept of cloning for a qubit in a system applicable to the present disclosure.
[0321] The uncloning of quantum states, utilized in quantum communication, is a key theoretical principle that ensures the security of quantum communication. In physics, it states that it is impossible to create independent and identical copies of any unknown quantum state. Originating from James Park's No-go Theorem in 1970, the No-cloning Theorem was announced by Wootters and Zurek in 1982. Since then, development and experimentation with quantum cloning technologies have continued. However, rather than creating completely independent and identical copies, these studies focus on creating clones in an entangled state with some fidelity, thus not violating the No-cloning Theorem.
[0322] Copying a Qubit means changing the Input State About Original State through Quantum Dynamics Wow Clone State This means outputting . If diagrammed, it is as shown in Figure 24.
[0323] If the Unitary Transform above is configured as a CNOT Gate, the Ancilla State When doing this, it can be expressed by the following mathematical formula 1.
[0324]
[0325] Therefore, the purpose is It is not possible to derive the state of . To make it more general, if there exists an arbitrary Unitary Transform that copies a qubit, then the Input State or Let's assume that. Then, the following relationship appears as mathematical equation 2.
[0326]
[0327] Then, the Input State is an arbitrary Quantum State When this happens, a relationship similar to the following mathematical expression 3 appears.
[0328]
[0329] That is, there cannot be any arbitrary Unitary Transform that completely copies a qubit.
[0330] Therefore, even if an attacker steals a qubit in quantum communication, it is impossible to copy that qubit and use it for an attack.
[0331]
[0332] Quantum Coherence Time
[0333] Qubits utilized in quantum communication, similar to classical communication, can also be affected by imperfections in the real-world environment, affecting the quality of transmitted information. This interaction with the environment can cause irreversible changes to the quantum state, a process known as decoherence. Environmental decoherence is a major cause of quantum state corruption, and can occur not only in quantum memory but also during quantum transmission or quantum processing. In particular, unlike classical communication, qubits are based on a single-photon state, corresponding to a very low energy level. Therefore, they are highly sensitive to environmental factors (temperature, vibration, atmospheric conditions, devices, etc.). Therefore, a quantum state can lose its original properties after a certain period of time by losing its quantum superposition state. The time it takes for a quantum state to maintain its original quantum superposition state while retaining its original properties is called coherence time.
[0334] Therefore, in quantum communication, qubit-based communication must occur within the coherence time. Furthermore, the transmission, computation, and measurement operations required for communication must be completed within this time frame to ensure that the sender can accurately convey the intended information to the receiver.
[0335]
[0336] The symbols / abbreviations / terms used in this disclosure are as follows.
[0337] - QA: Quantum Authentication
[0338]
[0339] Technical problems to be solved in this disclosure
[0340] Authentication with Key Distribution in Classical Communication
[0341] Figure 25 is a diagram illustrating an example of security keys in a 5G network system.
[0342] When considering the 5G Network in the 3GPP standard among existing communication systems, security keys to be used for communication can be obtained using a method such as that shown in Fig. 25.
[0343] In Fig. 25, the UDM / ARPF (Unified Data Management / Authentication credential Repository Processing Function) on the Network Side and the USIM (Universal Subscriber Identity Module) on the UE Side share the Root Key K through a predefined method. The Root Key is a user-specific information key corresponding to 128 bits or 256 bits depending on the operator's selection, and through the Root Key, the user authentication process, 5G AKA or EAP-AKA', is performed through the Ciphering Key or Integrity Key, and the Anchor Key corresponding to KSEAF is generated at the same time as the user authentication. Through the above process, the UE is authenticated as a user to the Network, and shares the Anchor Key for generating keys to be applied to secure communication such as encryption in subsequent communications.
[0344]
[0345] The 5G AKA or EAP-AKA process that operates for user authentication above can be summarized as follows.
[0346] (3GPP TS 33.501) 6.1.2 Initiation of authentication and selection of authentication method
[0347] FIG. 26 is a diagram illustrating an example of an authentication procedure initiation and authentication method selection process in a system applicable to the present disclosure.
[0348] Specifically, Figure 26 shows (3GPP TS 33.501 v18.1) Figure 6.1.2-1: Initiation of authentication procedure and selection of authentication method.
[0349] To perform the user authentication process, the UE transmits a Registration Request Message containing subscriber identity information, SUCI (Subscription Concealed Identifier) or temporary identity information, 5G-GUTI (5G-Globally Unique Temporary Identity), to SEAF (Security Anchor Function) / AMF (Access and Mobility Management Function) as an N1 Message. 5G-GUTI is used when the UE has been granted 5G-GUTI from the AMF after successful authentication in the previous registration process, and the 5G-GUTI is converted to a SUPI (Subscription Permanent Identifier) mapped by the AMF. If the UE does not have a 5G-GUTI or receives an Identity Request message from the AMF, it must request authentication via SUCI.
[0350] Upon receiving the registration request, the SEAF obtains the mobile carrier information that the terminal is subscribed to based on the SUCI or SUPI, and sends an authentication request message along with the information of the currently connected network (SN) to the AUSF (Authentication Server Function) of the corresponding mobile network (HN). The AUSF then sends it to the UDM (Unified Data Management). In the UDM, the Subscription Identifier De-concealing Function (SIDF) is used to decrypt the SUCI into SUPI to verify the user and select the authentication method 5G-AKA or EAP-AKA.
[0351]
[0352] (3GPP TS 33.501) 6.1.3 Authentication Procedures
[0353] FIG. 27 is a diagram illustrating an example of an authentication procedure initiation and authentication method selection process in a system applicable to the present disclosure.
[0354] Specifically, Figure 27 shows (3GPP TS 33.501 v18.1) Figure 6.1.3.2-1: Authentication procedure for 5G AKA.
[0355]
[0356] The authentication procedure for 5G AKA works as follows, cf. also Figure 6.1.3.2-1:
[0357] 1. For each Nudm_Authenticate_Get Request, the UDM / ARPF shall create a 5G HE AV. The UDM / ARPF does this by generating an AV with the Authentication Management Field (AMF) separation bit set to "1" as defined in TS 33.102. The UDM / ARPF shall then derive KAUSF (as per Annex A.2) and calculate XRES* (as per Annex A.4). Finally, the UDM / ARPF shall create a 5G HE AV from RAND, AUTN, XRES*, and KAUSF.
[0358] 2. The UDM shall then return the 5G HE AV to the AUSF together with an indication that the 5G HE AV is to be used for 5G AKA in a Nudm_UEAuthentication_Get Response. In case SUCI was included in the Nudm_UEAuthentication_Get Request, UDM will include the SUPI in the Nudm_UEAuthentication_Get Response after deconcealment of SUCI by SIDF.
[0359] If a subscriber has an AKMA subscription, the UDM shall include the AKMA indication and Routing indicator in the Nudm_UEAuthentication_Get Response.
[0360] 3. The AUSF shall store the XRES* temporarily together with the received SUCI or SUPI.
[0361] 4. The AUSF shall then generate the 5G AV from the 5G HE AV received from the UDM / ARPF by computing the HXRES* from XRES* (according to Annex A.5) and KSEAF from KAUSF (according to Annex A.6), and replacing the XRES* with the HXRES* and KAUSF with KSEAF in the 5G HE AV.
[0362] 5. The AUSF shall then remove the KSEAF and return the 5G SE AV (RAND, AUTN, HXRES*) to the SEAF in a Nausf_UEAuthentication_Authenticate Response.
[0363] 6. The SEAF shall send RAND, AUTN to the UE in a NAS message Authentication Request. This message shall also include the ngKSI that will be used by the UE and AMF to identify the KAMF and the partial native security context that is created if the authentication is successful. This message shall also include the ABBA parameter. The SEAF shall set the ABBA parameter as defined in Annex A.7.1. The ME shall forward the RAND and AUTN received in NAS message Authentication Request to the USIM.
[0364] NOTE 2: The ABBA parameter is included to enable the bidding down protection of security features.
[0365] 7. At receipt of the RAND and AUTN, the USIM shall verify the freshness of the received values by checking whether AUTN can be accepted as described in TS 33.102. If so, the USIM computes a response RES. The USIM shall return RES, CK, IK to the ME. If the USIM computes a Kc (i.e. GPRS Kc) from CK and IK using conversion function c3 as described in TS 33.102 , and sends it to the ME, then the ME shall ignore such GPRS Kc and not store the GPRS Kc on USIM or in ME. The ME then shall compute RES* from RES according to Annex A.4. The ME shall calculate KAUSF from CK||IK according to clause A.2. The ME shall calculate KSEAF from KAUSF according to clause A.6. An ME accessing 5G shall check during authentication that the "separation bit" in the AMF field of AUTN is set to 1. The "separation bit" is bit 0 of the AMF field of AUTN.
[0366] NOTE 3: This separation bit in the AMF field of AUTN cannot be used anymore for operator specific purposes as described by TS 33.102, Annex F.
[0367] 8. The UE shall return RES* to the SEAF in a NAS message Authentication Response.
[0368] 9. The SEAF shall then compute HRES* from RES* according to Annex A.5, and the SEAF shall compare HRES* and HXRES*. If they coincide, the SEAF shall consider the authentication successful from the serving network point of view. If not, the SEAF proceed as described in sub-clause 6.1.3.2.2. If the UE is not reached, and the RES* is never received by the SEAF, the SEAF shall consider authentication as failed, and indicate a failure to the AUSF.
[0369] 10. The SEAF shall send RES*, as received from the UE, in a Nausf_UEAuthentication_Authenticate Request message to the AUSF.
[0370] 11. When the AUSF receives as authentication confirmation the Nausf_UEAuthentication_Authenticate Request message including a RES* it may verify whether the 5G AV has expired. If the 5G AV has expired, the AUSF may consider the authentication as unsuccessful from the home network point of view. Upon successful authentication, the AUSF stores the KAUSF based on the home network operator's policy according to clause 6.1.1.1. AUSF shall compare the received RES* with the stored XRES*. If the RES* and XRES* are equal, the AUSF shall consider the authentication as successful from the home network point of view. AUSF shall inform UDM about the authentication result (see sub-clause 6.1.4 of the present document for linking with the authentication confirmation).
[0371] NOTE 4: It is left to implementation to temporarily store the KAUSF received in step 2 in AUSF until the RES* verification is done successfully (i.e., at step 11).
[0372] 12. The AUSF shall indicate to the SEAF in the Nausf_UEAuthentication_Authenticate Response whether the authentication was successful or not from the home network point of view. If the authentication was successful, the KSEAF shall be sent to the SEAF in the Nausf_UEAuthentication_Authenticate Response. In case the AUSF received a SUCI from the SEAF in the authentication request (see sub-clause 6.1.2 of the present document), and if the authentication was successful, then the AUSF shall also include the SUPI in the Nausf_UEAuthentication_Authenticate Response message.
[0373] The authentication procedure for 5G AKA is as follows or Figure 6.1.3.2-1.
[0374] 1. For each Nudm_Authenticate_Get request, the UDM / ARPF shall generate a 5G HE AV. The UDM / ARPF does this by generating an AV with the Authentication Management Field (AMF) separator bit set to "1" as defined in TS 33.102. The UDM / ARPF then derives the KAUSF (according to Annex A.2) and computes the XRES* (according to Annex A.4). Finally, the UDM / ARPF shall generate a 5G HE AV from the RAND, AUTN, XRES*, and KAUSF.
[0375] 2. Then, the UDM shall return the 5G HE AV to the AUSF in the Nudm_UEAuthentication_Get response with an indication that the 5G HE AV is used for 5G AKA. If SUCI was included in the Nudm_UEAuthentication_Get request, the UDM shall include SUCI in the Nudm_UEAuthentication_Get response after the SUCI is unmasked by the SIDF.
[0376] If the subscriber has an AKMA subscription, UDM must include the AKMA indication and routing indication in the Nudm_UEAuthentication_Get response.
[0377] 3. AUSF must temporarily store XRES* along with the received SUCI or SUPI.
[0378] 4. Then, AUSF shall generate 5G AV from 5G HE AV received from UDM / ARPF by calculating HXRES* from XRES* (according to Annex A.5) and KSEAF from KAUSF (according to Annex A.6). In 5G HE AV, XRES* is replaced with HXRES* and KAUSF is replaced with KSEAF.
[0379] 5. Then, AUSF shall remove KSEAF and return 5G SE AV (RAND, AUTN, HXRES*) to SEAF via Nausf_UEAuthentication_Authenticate response.
[0380] 6. SEAF shall send RAND and AUTN to the UE via NAS message authentication request. This message also includes the ngKSI, which the UE and AMF will use to identify the KAMF, and the partial default security context created if authentication is successful. This message also includes ABBA parameters. SEAF shall set the ABBA parameters as defined in Appendix A.7.1. The ME shall forward the RAND and AUTN received in the NAS message authentication request to the USIM.
[0381] Note 2: The ABBA parameter is included to enable bid-down protection for security features.
[0382] 7. Upon receiving RAND and AUTN, the USIM shall verify the up-to-dateness of the received values by checking whether it can accept the AUTN as described in TS 33.102. If so, the USIM shall compute the response RES. The USIM shall return RES, CK, and IK to the ME. If the USIM computes Kc (i.e., GPRS Kc) from CK and IK using the conversion function c3 as described in TS 33.102 and sends it to the ME, the ME shall ignore such GPRS Kc and shall not store the GPRS Kc on the USIM or in the ME. The ME shall then compute RES* from RES according to Annex A.4. The ME shall compute KAUSF from CK||IK according to Clause A.2. The ME shall compute KSEAF from KAUSF according to Clause A.6. MEs connecting to 5G must ensure that the "separation bit" in the AMF field of the AUTN is set to 1 during authentication. The "separation bit" is bit 0 of the AMF field of the AUTN.
[0383] NOTE 3: This separation bit in the AMF field of the AUTN is no longer available for operator-specific purposes as described in TS 33.102, Annex F.
[0384] 8. The UE must return RES* to SEAF in the NAS message authentication response.
[0385] 9. SEAF shall then calculate HRES* from RES* according to Appendix A.5, and compare HRES* with HXRES*. If they match, SEAF shall consider authentication successful from the service network perspective. Otherwise, SEAF shall proceed as described in subsection 6.1.3.2.2. If the UE is not reached and RES* is not received by SEAF, SEAF shall consider authentication to have failed and indicate a failure to AUSF.
[0386] 10. SEAF shall forward the RES* received from the UE to AUSF in the Nausf_UEAuthentication_Authenticate request message.
[0387] 11. When the AUSF receives a Nausf_UEAuthentication_Authenticate Request message containing RES* as an authentication confirmation, it can check whether the 5G AV has expired. If the 5G AV has expired, the AUSF can consider it as an authentication failure from the home network perspective. If the authentication is successful, the AUSF stores the KAUSF according to the home network operator's policy as per Section 6.1.1.1. The AUSF compares the received RES* with the stored XRES*. If the RES* and XRES* are identical, the AUSF shall consider the authentication as a success from the home network perspective. The AUSF shall notify the UDM about the authentication result (see subsection 6.1.4 of this document for connection with the authentication confirmation).
[0388] NOTE 4: It is implementation dependent to temporarily store the KAUSF received in Step 2 of the AUSF until the RES* verification is successfully completed (i.e., in Step 11).
[0389] 12. The AUSF shall indicate to SEAF whether authentication was successful from the home network perspective via the Nausf_UEAuthentication_Authenticate response. If authentication was successful, KSEAF shall forward the Nausf_UEAuthentication_Authenticate response to SEAF. If the AUSF received SUCI from SEAF in the authentication request (see subsection 6.1.2 of this document) and authentication was successful, the AUSF shall also include SUPI in the Nausf_UEAuthentication_Authenticate response message.
[0390] When the Authentication Method is selected as 5G AKA, the user authentication process is performed as shown in the above diagram. Based on the decrypted user information, the AUSF (Authentication Server Function) Key and 5G HE AV (Home Environment Authentication Vector) are generated using the user's top-level key value stored in the ARPF (Authentication Credential Repository Processing Function). The AUSF generates a 5G AV from the 5G HE AV received from the UDM (Unified Data Management) and transmits the 5G SE AV (Serving Environment Authentication Vector) excluding the SEAF Key to the SEAF. The SEAF transmits an Authenticate Request message including the value excluding the HXRES* value of the 5G SE AV to the terminal. The terminal generates an AUTN using the received RAND value and the top-level key stored in the terminal's USIM, and authenticates the network by verifying whether this value is the same as the AUTN received from the SEAF. Next, the RES* value to be used for terminal authentication and the AUSF Key and SEAF Key to be used in the terminal are sequentially generated, and then the RES* is transmitted to SEAF via the Authenticate Response message. SEAF obtains HRES* using the RES* transmitted by the terminal, and authenticates the terminal by comparing it with the HXRES* value of the 5G SE AV transmitted from the AUSF. In other words, the terminal is authenticated from the perspective of the network (SN) that provides the service to the terminal. After completing terminal authentication, SEAF transmits the RES* received from the terminal back to the AUSF, and the AUSF re-authenticates the terminal from the perspective of the home network (HN) by comparing it with the XRES* value of the 5G HE AV transmitted from the UDM.After successful authentication, AUSF transmits the subscriber's identity information, SUPI and SEAF Key, to the SEAF of the network (SN) to which the terminal is connected, and reports the authentication result to the UDM.
[0391] The 5G-AKA procedure is characterized by complementing the weaknesses of the 4G EPS-AKA procedure. First, it prevents theft of subscriber identity information in the initial wireless section by using SUCI. In addition, authentication is further strengthened by simultaneously receiving authentication from both the network (SN) to which the terminal is connected and receiving services, as well as the home network (HN) to which the terminal is subscribed. In addition, the subscriber identity information, SUPI, is transmitted to the network (SN) to which the terminal is connected only after authentication by the home network is completed, and the AMF Key can be generated only with this SUPI. This prevents a series of abnormal procedures from occurring, in which the network to which the terminal is connected completes the authentication procedure independently and proceeds with the subsequent key sharing and security context setup procedure without home network authentication.
[0392]
[0393] FIG. 28 is a diagram illustrating an example of a SUCI structure in a system applicable to the present disclosure.
[0394] Specifically, Figure 28 shows (3GPP TS 23.003 v18.2) Figure 2.2B-1: Structure of SUCI.
[0395] To prevent theft of subscriber identity information in the initial wireless section in the operation of Figure 27, the terminal must, in advance, hold the HN's public key in a reliable manner and, by encrypting the subscriber identity information to be sent, construct SUCI. The SUCI information is constructed as shown in Figure 28.
[0396] The SUCI is composed of the following parts:
[0397] 1) SUPI Type, consisting in a value in the range 0 to 7. It identifies the type of the SUPI concealed in the SUCI. The following values are defined:
[0398] - 0: IMSI
[0399] - 1: Network Specific Identifier (NSI)
[0400] - 2: Global Line Identifier (GLI)
[0401] - 3: Global Cable Identifier (GCI)
[0402] - 4 to 7: spare values for future use.
[0403] 2) Home Network Identifier, identifying the home network of the subscriber.
[0404] When the SUPI Type is an IMSI, the Home Network Identifier is composed of two parts:
[0405] - Mobile Country Code (MCC), consisting of three decimal digits. The MCC identifies uniquely the country of domicile of the mobile subscription;
[0406] - Mobile Network Code (MNC), consisting of two or three decimal digits. The MNC identifies the home PLMN or SNPN of the mobile subscription.
[0407] When the SUPI type is a Network Specific Identifier (NSI), a GLI or a GCI, the Home Network Identifier consists of a string of characters with a variable length representing a domain name as specified in clause 2.2 of IETF RFC 7542. For a GLI or a GCI, the domain name shall correspond to the realm part specified in the NAI format for SUPI in clauses 28.15.2 and 28.16.2.
[0408] 3) Routing Indicator, consisting of 1 to 4 decimal digits assigned by the home network operator and provisioned in the USIM, that allow together with the Home Network Identifier to route network signalling with SUCI to AUSF and UDM instances capable to serve the subscriber.
[0409] Each decimal digit present in the Routing Indicator shall be regarded as meaningful (e.g. value "012" is not the same as value "12"). If no Routing Indicator is configured on the USIM or the ME, this data field shall be set to the value 0 (i.e. only consist of one decimal digit of "0").
[0410] 4) Protection Scheme Identifier, consisting in a value in the range of 0 to 15 (see Annex C.1 of 3GPP TS 33.501). It represents the null scheme or a non-null scheme specified in Annex C of 3GPP TS 33.501 or a protection scheme specified by the HPLMN; the null scheme shall be used if the SUPI type is a GLI or GCI.
[0411] 5) Home Network Public Key Identifier, consisting in a value in the range 0 to 255. It represents a public key provisioned by the HPLMN or SNPN and it is used to identify the key used for SUPI protection. This data field shall be set to the value 0 if and only if null protection scheme is used;
[0412] 6) Scheme Output, consisting of a string of characters with a variable length or hexadecimal digits, dependent on the used protection scheme, as defined below. It represents the output of a public key protection scheme specified in Annex C of 3GPP TS 33.501 or the output of a protection scheme specified by the HPLMN.
[0413] SUCI consists of the following parts:
[0414] 1) SUPI type, consisting of values in the range 0 to 7. Identifies the SUPI type hidden in SUCI. The following values are defined.
[0415] - 0: IMSI
[0416] - 1: Network Specific Identifier (NSI)
[0417] - 2: Global Line Identifier (GLI)
[0418] - 3: Global Cable Identifier (GCI)
[0419] - 4 ~ 7: Reserved values for future use.
[0420] 2) Home network identifier, identifies the subscriber's home network.
[0421] If the SUPI type is IMSI, the home network identifier consists of two parts:
[0422] - The Mobile Country Code (MCC) consists of three decimal places. The MCC uniquely identifies the country of residence of a mobile subscriber.
[0423] - The Mobile Network Code (MNC) consists of two or three decimal digits. The MNC identifies the home PLMN or SNPN of the mobile subscription.
[0424] If the SUPI type is a Network Specific Identifier (NSI), a GLI, or a GCI, the home network identifier consists of a variable-length string representing the domain name specified in Section 2.2 of IETF RFC 7542. For a GLI or a GCI, the domain name must match the area part specified in the NAI format for SUPI in Sections 28.15.2 and 28.16.2.
[0425] 3) A routing indicator consisting of a 1- to 4-digit decimal number assigned by the home network operator and provided to the USIM. Using the SUCI along with the home network identifier, network signals can be routed to AUSF and UDM instances capable of providing service to subscribers.
[0426] Each decimal digit in the routing indicator is considered significant (e.g., the value "012" is not the same as the value "12"). If no routing indicator is configured on the USIM or ME, this data field must be set to the value 0 (i.e., it consists of only one decimal digit, "0").
[0427] 4) A protection scheme identifier (see Annex C.1 of 3GPP TS 33.501) consisting of values in the range 0 to 15. It indicates the null scheme, non-null scheme, or protection scheme specified in Annex C of 3GPP TS 33.501, or the protection scheme specified by HPLMN. The null scheme must be used when the SUPI type is GLI or GCI.
[0428] 5) Home network public key identifier, consisting of a value in the range 0 to 255. This represents the public key provided by the HPLMN or SNPN and is used to identify the key used for SUPI protection. This data field should be set to 0 only when the null protection scheme is used.
[0429] 6) Scheme output consisting of a string of variable length or hexadecimal digits, depending on the protection scheme used as defined below. This represents the output of the public key protection scheme specified in Annex C of 3GPP TS 33.501 or the output of the protection scheme specified by HPLMN.
[0430]
[0431] The content corresponding to the Scheme Output part above may be configured differently depending on the protection scheme, and may be configured as in Fig. 29 or Fig. 30 when the Elliptic Curve Integrated Encryption Scheme is used.
[0432] FIG. 29 is a diagram illustrating an example of a system output for an elliptic curve integrated encryption scheme profile A applicable to the present disclosure.
[0433] Specifically, Figure 29 shows (3GPP TS 23.003 v18.2) Figure 2.2B-3: Scheme Output for Elliptic Curve Integrated Encryption Scheme Profile A.
[0434] FIG. 30 is a diagram illustrating an example of a system output for an elliptic curve integrated encryption scheme profile B applicable to the present disclosure.
[0435] Specifically, Figure 30 shows (3GPP TS 23.003 v18.2) Figure 2.2B-4: Scheme Output for Elliptic Curve Integrated Encryption Scheme Profile B.
[0436] In the above SUCI structure, the entity that can decrypt the ciphertext value is the SIDF of UDM, which holds the private key of HN. However, due to the development of quantum computers and quantum algorithms, the security of systems using the above public key encryption may be threatened. It has been theoretically proven that encryption methods based on RSA (RIVEST? SHAMIR? ADLEMAN) or ECC (Elliptic Curve Cryptography), which are commonly used in asymmetric key-based security systems, can be deciphered within the valid time by parallel operation of the Shor Algorithm. For RSA 2048 bit, factoring is possible within 8 hours by 20 million noisy qubits [“How to factor 2048-bit RSA integers in 8 hours using 20 million noisy qubits” Quantum 5, 433 (2021)], and a study analyzing factoring within 177 days with only 13,436 qubits based on multi-parallel quantum memory [“Factoring 2048-bit RSA Integers in 177 Days with 13,436 Qubits and a Multimode Memory” PRL, (2021)] has been published. The collapse of an asymmetric key encryption system by such a quantum algorithm poses a serious threat to secure communication systems based on asymmetric key encryption.
[0437] To prevent these security threats, Post-Quantum Cryptography (PQC) technology is emerging. However, all asymmetric key systems based on computational complexity inevitably face the risk of being threatened by new quantum algorithms. Furthermore, transitioning to a new security system can entail a significant technical burden, as the new security technology must be applied across the entire device.
[0438] Therefore, a method is needed to address the threat of quantum algorithms while maintaining an asymmetric key system. To achieve this, trapdoor leakage caused by quantum algorithms can be adaptively prevented by periodically updating the public key. This prevents real-time leakage even if a plaintext attack is conducted using quantum algorithms. However, even if real-time leakage does not occur, an attacker can still conduct a plaintext attack later using a Harvest-Now-Decrypt-Later (HNDL) attack. Consequently, limiting the validity period of a public key alone cannot achieve fundamental information security.
[0439] In this disclosure, we propose a method for achieving physical information security based on the no-cloning theorem and quantum coherence time.
[0440]
[0441] Composition of various embodiments of the present disclosure
[0442] Quantum Coherence Time based Quantum Public Key Infrastructure
[0443] In this disclosure, we propose a Quantum Public Key Infrastructure (QPKI) system that provides physical security based on the no-cloning theorem and quantum coherence time.
[0444]
[0445] The technology proposed in this disclosure provides physical security by sharing quantum public keys in real time, rather than in advance, while combining them with classical PKI systems to prevent quantum information from being intercepted within the quantum coherence time. If quantum information is not intercepted within the quantum coherence time, it is lost. Therefore, even if an attacker uses a Harvest-Now-Decrypt-Later (HNDL) attack, they cannot launch a Plaintext attack later.
[0446] In the technology proposed in the present disclosure, 1) it is assumed that the Classical PKI system has shared the Classical Public Key in a reliable manner. Here, sharing the initial Classical Public Key in a reliable manner generally means obtaining the Classical Public Key by Out-of-verification. For example, in a 3GPP communication system, the Classical Public Key of the HN is obtained at the initial USIM registration stage of the terminal. (TS 33.501 5.2.5 subscriber privacy: The Home Network Public Key shall be stored in the USIM.) 2) it is assumed that the Classical PKI system can renew a new Public Key in a reliable manner. 3. It is assumed that the minimum required time until the trapdoor of a specific Classical Public Key K of a specific Classical PKI system A is leaked by a quantum algorithm, etc. is X. 4. It is assumed that the quantum coherence time of the quantum state is maintained for a maximum of Y hours. 4. It has the relationship X > Y.
[0447]
[0448] 1. (HN-UE) Sharing and Renewing Classical Public Keys in a Reliable Way
[0449] HN and UE share the Classical Public Key in a reliable way, and renew it within X hours.
[0450] Sharing a Classical Public Key in a reliable manner means obtaining the Classical Public Key through out-of-verification. For example, in a 3GPP communication system, the HN's Classical Public Key is obtained during the initial USIM registration phase of the terminal.
[0451] A reliable way to update a Classical Public Key is through the Public Key Update System. The Public Key Update System can be comprised of five steps, as follows:
[0452] (1) (Step 1) (HN) Setting the public key validity period T and the public key update cycle R
[0453] HN sets the Public Key validity time Threshold T to be less than the time X that it takes to threaten the stability of the Public Key. The validity time Threshold T can be determined in real time by HN and stored in the UDM.
[0454] HN sets the Update Period R of the Public Key. Update Period R can be determined in real time by HN and stored in the UDM.
[0455] (2) (Step 2) (HN) Periodic Key Pair Generation
[0456] HN is the Key Pair of the public key system being used (e.g., Elliptic Curve Integrated Encryption Scheme (ECIES) in 3GPP TS 33.501). is generated periodically. Here, means the Secret Key (or Private Key) of the nth Key Pair, means the public key of the nth key pair.
[0457] Periodically generated key pairs are stored in the HN's UDM in the order of generation. (TS 33.501 5.8.2 Subscriber privacy-related requirements to UDM and SIDF: The Home Network Private Key used for subscriber privacy shall be protected from physical attacks in the UDM. The UDM shall hold the Home Network Public Key Identifier(s) for the private / public key pair(s) used for subscriber privacy.)
[0458] The time stamp for the generation time of the key pair generated in HN is stored in UDM.
[0459] The time stamp for the expired time of the key pair generated in HN is stored in UDM.
[0460] Key Pairs generated by HN may be limited to Key Pairs that have not been used before.
[0461] The generation of the Key Pair above may differ from the Key Update cycle R. For example, Key Pair generation may be performed and stored continuously within the UDM regardless of the Key Update cycle. Key Pairs for Public Key Update may sequentially use Key Pairs stored sequentially within the UDM.
[0462] (3) (Step 3) (HN) Updated Public Key Encryption
[0463] HN is the Secret Key of the Key Pair that was previously disclosed and used. Public Key to be made public from the newly created Key Pair Encrypts and creates a Renewal Key Block (RKB). The RKB can contain the following information.
[0464] (3-1) Renewal Key Block (RKB)
[0465] (3-1-1) Home Network Identifier
[0466] (3-1-1-1) It tells you which HN's public key to renew using the Home Network identifier.
[0467] (3-1-2) Protection Scheme ID (Protection Scheme Identifier)
[0468] (3-1-2-1) The encryption methods are defined in advance as identifiers for the encryption methods that encrypt / decrypt the updated public key.
[0469] (3-1-3) Home Network Public Key ID (Home Network Public Key Identifier)
[0470] (3-1-3-1) The identifier for the Home Network Public Key indicates which key among the Home Network Public Keys is being renewed.
[0471] (3-1-4) Basis P-Key (Basis Public Key)
[0472] (3-1-4-1) This is the Basis P-Key used when decrypting the Updated P-Key. It corresponds to the Home Network Public Key ID and is the Public Key of the HN used in the previous cycle.
[0473] (3-1-4-2) For example, if the Index indicating the current Public Key cycle is n, the Public Key of HN corresponding to the previous cycle is am.
[0474] (3-1-5) Encrypted P-Key (Encrypted Public Key)
[0475] (3-1-5-1) Basis Secret is an encryption technique corresponding to the Protection Scheme ID. Updated Public Key of HN encrypted by am.
[0476] (3-1-5-1-1) Here, Is by This means that it has been encrypted.
[0477] (3-1-5-2) Encrypted P-Key is decrypted with Basis P-key underneath, You can get it.
[0478] (3-1-5-2-1) Here, Is by This means that it has been decrypted.
[0479] (3-1-6) Validity Information
[0480] (3-1-6-1) Validity Information indicates the time for which the information in the Renewal Key Block is valid.
[0481] (4) (Step 4) (HN) Updated Public Key Broadcasting
[0482] The Renewal Key Block (RKB) generated and managed by UDM is broadcast to all users via public channels. The RKB generated by UDM can be announced to all users via the gNB via SEAF.
[0483] Here, the public channel may be a physical channel that carries a physical layer message. For example, it may be a physical broadcast channel (PBCH) that carries a master information block (MIB) or a physical downlink shared channel (PDSCH) that carries a system information block (SIB).
[0484] Alternatively, the public channel may be an upper layer channel that carries upper layer messages.
[0485] (5) (Step 5) (UE) Renewal Public Key Decryption
[0486] All UEs receive the broadcasted RKB and decrypt the RKB's Encrypted P-Key using the existing HN's Public Key.
[0487] (5-1) All UEs check whether their Home Network ID is correct in the received RKB and compare the Public Key of the HN they previously had with the Basis Public Key of the RKB to check whether they match.
[0488] (5-1-1) If the existing HN Public Key and the RKB Basis Public Key match, the Encrypted P-Key is decrypted using the Protection Scheme and Basis Public Key indicated by the RKB.
[0489] (5-1-1-1) The existing HN Public Key is replaced with the decrypted Updated P-Key.
[0490] (5-1-2) If the existing HN Public Key and the RKB Basis Public Key do not match, an updated public key is received through a separate Out-of-Verification.
[0491] Therefore, HN and UE can perform data encryption using Classical Public Key for X time, and security is not threatened during this time. However, it does not prevent HNDL Attack.
[0492]
[0493] 2. (UE) Request Quantum Public Key
[0494] When a UE needs to transmit secure information to the HN, it requests the HN to transmit a quantum public key. The request for the quantum public key can be made through a classical channel or a public channel (not a secure channel). The public channel can be a physical channel that carries physical layer messages. For example, it can be a physical uplink shared channel (PUSCH) or a physical uplink control channel (PUCCH). Alternatively, it can be an upper layer channel that carries upper layer messages.
[0495] Since the request for transmission of the Quantum Public Key can be received through the Serving Network (SN), the request can include information about the HN in order to request the Quantum Public Key of the HN.
[0496] A request to transmit a Quantum Public Key may be made including the length of the required Quantum Public Key.
[0497]
[0498] 3. (HN) Generation of Quantum Public Key
[0499] HN generates a Quantum Public Key to be shared with the UE. The Quantum Public Key is generated from a Private Key, which can be logical information. The Quantum Public Key represents a quantum state generated in one of two types, as follows:
[0500] (1) Single Qubit based Public Key
[0501] (1-1) HN creates a single qubit with an initial quantum state.
[0502] (1-1-1) For example, Initial Quantum State or can be set to .
[0503] (1-2) HN holds the Logical Information generated through the Random Number Generator as a Private Key. This information is Secret Information that is not disclosed to the outside world.
[0504] (1-2-1) For example, we can select any natural number n, where n is a number less than a predefined specific Threshold N.
[0505] (1-2-2) The Random Number Generator above can generate a Pure Random Number through a Quantum Random Number Generator, etc.
[0506]
[0507] FIG. 31a is a diagram illustrating an example of modulation by Qubit Rotation in a system applicable to the present disclosure.
[0508] (1-3) HN modulates the Initial Quantum State based on an arbitrary natural number n to create a Quantum Public Key Creates.
[0509] (1-3-1) For example, if the Initial Quantum State is When , modulate the Qubit Rotation corresponding to the natural number n: .
[0510] (1-3-1-1) Here, It means Unitary operation for Qubit Rotation.
[0511] (1-3-1-2) Qubit Rotation is Initial Quantum State and Orthogonal Quantum State It means Phase Rotation between.
[0512] (1-3-1-3) Here, Qubit Rotation is Initial Quantum State class It means that the z-axis phase rotation occurs between them. At this time, the axes that can be used are all x, y, and z. However, Initial Quantum State class If you are on this z-axis, you can also use only x-axis or y-axis rotation.
[0513] (1-4) Public Key modified by Private Key n Save to UDM.
[0514] (1-5) Multiple Private Keys in the same way and Public Key Create and save.
[0515] (1-6) Here, i is the index of the key.
[0516] (2) Entanglement based Public Key
[0517] (2-1) HN creates an Entanglement State with an Initial Bell State.
[0518] (2-1) For example, the Initial Bell State can be set to one of four Bell States.
[0519] (2-1-1)
[0520] (2-1-2)
[0521] (2-1-3)
[0522] (2-1-4)
[0523] (2-2) In the above, A means the first particle of the Qubit Pair (or Bell Pair) that constitutes the Bell State, and B means the second particle.
[0524] (2-2) HN holds the Logical Information generated through the Random Number Generator as a Private Key. This information is Secret Information that is not disclosed to the outside world.
[0525] (2-2-1) For example, we can select any natural number n, where n is a number less than a predefined threshold N.
[0526] (2-2-2) The Random Number Generator above can generate a Pure Random Number through a Quantum Random Number Generator, etc.
[0527]
[0528] FIG. 31b is a diagram illustrating an example of a Pauli operator in a system applicable to the present disclosure.
[0529] (2-3) HN generates a Quantum Public Key by modulating the Initial Bell State based on an arbitrary natural number n.
[0530] (2-3-1) For example, Initial Bell State When , a Unitary operation corresponding to the natural number n is applied to one Particle.
[0531] (2-3-1-1) For example, if the particle you want to use as a public key is the first particle, unitary operation is performed only on the first particle. Apply.
[0532] (2-3-1-2) Here, the Unitary operation can be a Pauli operation. A Pauli operation is an operation represented by Pauli X, Y, Z, and I, and means modulation of a quantum state.
[0533] (2-3-1-3) Pauli operators X, Y, and Z correspond to the measured values of spin along the x, y, and z axes, and are expressed as in Fig. 31b. Fig. 31b shows Pauli operators. Each operator has the following properties. The X operator performs a classical not operation (bit flip), Z performs an operation that converts the phase, and Y (=XZ) performs a combination operation of the two.
[0534]
[0535] (2-3-2) Or for example, one Initial Bell State And another Initial Bell State When , a Permutation operation corresponding to a natural number n is applied to two or more Initial Bell State operations.
[0536] (2-4) Key modified by Private Key n Save to UDM.
[0537] (2-4-1) Here, I stands for Pauli I. Initial Bell State Is and It can be written by dividing it into means the first particle of the Initial Bell State, where, refers to the second particle of the Initial Bell State.
[0538] (2-4-2) Here, is the first particle of the modified Bell State and is a Quantum Public Key, is the second unmodified Particle, which is the Quantum Secret Key.
[0539] (2-5) Multiple Quantum Secret Keys and Quantum Public Key Pairs in the same way Create and save.
[0540] (2-5-1) Here, i is the index of the key.
[0541] In the above, generation of the Quantum Public Key can be performed at the time of receiving a Request of Quantum Public Key from the UE.
[0542] In the above, the generation of the Quantum Public Key may be generated in advance by the HN and stored in the Quantum Memory, regardless of the time of receiving the Request for Quantum Public Key from the UE.
[0543]
[0544] 4. (HN-UE) Transmission of Quantum Public Key
[0545] HN provides the Quantum Public Key to the UE is transmitted. Here, represents the Quantum Public Key Set transmitted, and L is the length of the Quantum Public Key transmitted. At this time, the i-th Quantum Public Key It can be the first particle of a single qubit based public key or an entanglement based public key. Here, the quantum public key transmission is transmitted through a quantum channel.
[0546] Quantum Public Key transmission can be transmitted with the Quantum Public Key length set based on the length information of the Quantum Public Key included in the UE's Request of Quantum Public Key.
[0547] Quantum Public Key transmission can be performed by setting the Quantum Public Key length in units of a predefined length in the system. Here, the predefined length unit can be transmitted as header information along with the signal transmitting the Quantum Public Key.
[0548]
[0549] 5. (UE) Quantum Public Key-based Data Encryption
[0550] The UE encrypts the data it wants to transmit to the HN using the Quantum Public Key received from the HN.
[0551] FIG. 32 is a diagram illustrating an example of modulation by Qubit Rotation in a system applicable to the present disclosure.
[0552] (1) Single Qubit based Public Key & Entanglement based Public Key
[0553] (1-1) The UE receives the Quantum Public Key from the HN based on the Data d it wants to send. Data encryption is performed by modifying .
[0554] (1-1-1) For example, Quantum Public Key When , modulate the Qubit Rotation corresponding to Data d: .
[0555] (1-1-1-1) Here, It means Unitary operation for Qubit Rotation.
[0556] (1-1-1-2) Here, Qubit Rotation is Quantum Public Key For the z-axis, if d is 0, no rotation occurs, and if it is 1, π rotation occurs.
[0557] (1-1-1-3) Here, d is assumed to be bit information, 0 or 1.
[0558] (1-1-1-4) In the above, Qubit Rotation is Quantum Public Key It can be a Pauli Operation. Here, if d is 0, the Pauli Operation does not occur, and if it is 1, the Pauli Operation occurs.
[0559] (1-1-1-5) In the above, the Pauli Operation can be agreed upon in advance between the transmitter and receiver as one of X, Y, and Z.
[0560] In the same way, all Quantum Public Keys About each Data can be modified. Here, i is the index of the Data Index and the Quantum Public Key.
[0561] Here, Data Encryption can be set differently in a pre-arranged manner.
[0562] Here, data encryption can be set differently depending on the type of Quantum Public Key in a pre-agreed manner.
[0563]
[0564] 6. (UE) Encapsulation of Encrypted Data Based on Ephemeral Key
[0565] The UE generates and stores a random Ephemeral Key, and encapsulates the Encrypted Data with the Ephemeral Key to create Encapsulated & Encrypted Data.
[0566] FIG. 33 is a diagram illustrating an example of modulation by Qubit Rotation in a system applicable to the present disclosure.
[0567] (1) Here, the Ephemeral Key is the Logical Information generated through the Random Number Generator and is encrypted data. is used to modulate.
[0568] (1-1) For example, an Ephemeral Key can be any natural number b, where b is a number less than a predefined threshold B.
[0569] (1-2) The Random Number Generator above can generate a Pure Random Number through a Quantum Random Number Generator, etc.
[0570] (2) Encapsulation of the encrypted data above can be performed in the same manner as the data encryption method.
[0571] (2-1) For example, Encrypted Data When , modulate the Qubit Rotation corresponding to the Ephemeral Key b: .
[0572] (2-2) Here, It means Unitary operation for Qubit Rotation.
[0573] (2-3) Here, Qubit Rotation means performing Qubit Rotation along the same axis as the Qubit Rotation axis on which Data Encryption was performed.
[0574] (2-4) In the above, Qubit Rotation is Encrypted Data It can be a Pauli Operation. Here, it means that the selection and number of uses of the Pauli Operator are determined by a look-up table determined in advance according to b, and the Pauli Operation occurs. The Pauli Operation can be agreed upon in advance between the transmitting and receiving ends as one of X, Y, and Z.
[0575] (2-5) All Encrypted Data in the same way For each Ephemeral Key Encapsulation can be achieved with .
[0576] (2-5-1) Here, i is the index of the Data Index and Ephemeral Key.
[0577]
[0578] 7. (UE) Ephemeral Key Encryption based on Classical Public Key
[0579] The UE encrypts the Ephemeral Key used for Encapsulation of Encrypted Data based on the Classical Public Key previously shared and updated with the HN.
[0580] UE1. (HN-UE) A reliable way to share and update Classical Public Keys shared and updated by HN. 6. (UE) Encrypting Ephemeral Key b used for Encapsulation of Encrypted Data in Encryption of Encrypted Data based on Ephemeral Key. At this time, Encryption method uses Classical Public Key Encryption method agreed upon in advance, Encrypted Ephemeral Key is obtained. Here, Is as This means that it has been encrypted, 6. (UE) Encapsulation of Encrypted Data based on Ephemeral Key Multiple Encrypted Data Each Ephemeral Key for This is an Ephemeral Key Vector that contains the entire: . Here, T represents the total length of the Ephemeral Key used in the Encapsulation of Encrypted Data based on the Ephemeral Key.
[0581]
[0582] 8. (UE-HN) Quantum Public Key Encrypted
[0583] The UE transmits a Quantum Public Key Encrypted (QPKE) Packet containing Encapsulated & Encrypted Data to the HN via a quantum channel or via a classical channel and a quantum channel.
[0584] FIG. 34 is a diagram illustrating an example of a QPKE Packet structure in a system applicable to the present disclosure.
[0585] (1) Quantum channel-based QPKE packet transmission
[0586] (1-1) Transmit a QPKE Packet containing control information and security information through a quantum channel.
[0587] (1-2) When transmitting a QPKE Packet through a quantum channel, the QPKE Packet structure is as shown in Fig. 34.
[0588] (1-2-1) All QPKE Packets are generated in Quantum State, and fields (Synchronization Header, Protection Scheme ID, Home Network Public Key ID) excluding Encrypted Data can be composed of Optical Signals. At this time, the Optical Signal can be an Optical Signal at the Single Photon level or a Field composed of Multiple Photons.
[0589] (1-2-1-1) Fields composed of optical signals do not require security, and signals can be composed in a way agreed upon in advance between the transmitter and receiver.
[0590] (1-2-1-2) For example, ON / Off Keying (OOK) or Phase / Amplitude / Polarization Modulation methods can be used.
[0591] (1-2-1-3) Fields composed of optical signals can have a field size defined in advance between the transmitter and receiver.
[0592] (1-2-2) Synchronization Header is synchronization information for linking information with the Classical Public Key Encrypted Ephemeral Key (PKE-EK) Packet transmitted through the classical channel and the QPKE Packet transmitted through the quantum channel.
[0593] (1-2-2-1) The Synchronization Header of the PKE-EK Packet transmitted through the classical channel and the Synchronization Header of the QPKE Packet transmitted through the quantum channel consist of the same information.
[0594] (1-2-2-2) Synchronization Header can be a Synchronization Code promised in a predefined manner.
[0595] (1-2-2-2-1) For example, the Synchronization Code can be an Index indicating the order of the QPKE Packet, and the Synchronization Code can be defined as a Sequence structure that can be detected at the receiving end.
[0596] (1-2-2-2-2) Even though the Synchronization Code above is an index indicating the order of the QPKE Packet, it is defined as a Sequence structure with a length that can perform information separation between multiple users.
[0597] (1-2-2-3) Synchronization Header can be a randomly generated Synchronization Code.
[0598] (1-2-2-3-1) For example, it can be a sequence of random numbers generated through QRNG, etc.
[0599] (1-2-2-3-2) The length of the sequence consisting of random numbers corresponding to the synchronization code is agreed upon in advance between the transmitting and receiving ends.
[0600] (1-2-3) Protection Scheme ID is a field that indicates the encapsulation and encryption method of the encapsulated and encrypted data of the QPKE Packet.
[0601] (1-2-3-1) Protection Scheme ID can be indicated by specifying different Encapsulation and Encryption methods.
[0602] (1-2-3-2) Protection Scheme ID can be made to function as a single identifier when the Encapsulation method and Encryption method are specified in the same way.
[0603] (1-2-3-3) Protection Scheme ID can include the Type of Quantum Public Key.
[0604] (1-2-3-4) Protection Scheme ID may not be used if it is agreed upon between the sender and receiver in a single manner.
[0605] (1-2-3-5) Protection Scheme ID can be set to the default value 0 if it is agreed upon between the transmitter and receiver in a single manner.
[0606] (1-2-4) Home Network Public Key ID is a field that indicates the Quantum Public Key ID for the Encapsulated & Encrypted Data of the QPKE Packet.
[0607] (1-2-4-1) Home Network Public Key ID represents the Quantum Public Key Index.
[0608] (1-2-4-1-1) If the Quantum Public Key used for Encapsulated & Encrypted Data is composed of multiple Quantum States, it can indicate the first Index among the entire Quantum Public Key.
[0609] (1-2-4-1-2) If the Quantum Public Key used for Encapsulated & Encrypted Data is composed of multiple Quantum States, it can represent the Index range of the entire Quantum Public Key.
[0610] (1-2-5) Encapsulated & Encrypted Data is a data field that is encapsulated with an Ephemeral Key and encrypted with a Quantum Public Key expressed as a Home Network Public Key ID.
[0611] (1-2-5-1) This is a Quantum State that encrypts data using the Encryption method indicated in the Protection Scheme ID using the Quantum Public Key, and encapsulates encrypted data using the Encapsulation method indicated in the Protection Scheme ID of the PEK-EK Packet using the Ephemeral Key.
[0612] (1-2-5-2) When multiple data are encrypted and encapsulated using multiple Quantum Public Keys and Classical Ephemeral Keys, the Encapsulated & Encrypted Data can be a Quantum State Stream.
[0613] (1-2-5-3) Encapsulation & Encrypted Data Field composed of Quantum State Stream can have a field size defined in advance between the sender and receiver.
[0614]
[0615] FIG. 35 is a diagram illustrating an example of a QPKE Packet structure in a system applicable to the present disclosure.
[0616] (2) QPKE Packet Transmission Based on Classical Channel and Quantum Channel
[0617] (2-1) A QPKE Control Packet that transmits control information related to a QPKE Packet is transmitted through a classical channel, and a QPKE Packet that contains only security information is transmitted through a quantum channel.
[0618] (2-2) When transmitting a QPKE Control Packet through a classical channel, the structure of the QPKE Control Packet is as shown in Figure 35.
[0619] (2-2-1) QPKE Control Packet consists entirely of classical information and can be composed of RF Signal or Optical Signal.
[0620] (2-2-1-1) The fields of the QPKE Control Packet are not information requiring security, and are control information transmitted in a method agreed upon in advance between the transmitter and receiver.
[0621] (2-2-1-2) For example, ON / Off Keying (OOK) or Phase / Amplitude / Polarization Modulation methods can be used.
[0622] (2-2-1-3) The fields of the QPKE Control Packet can have a field size that is agreed upon in advance between the transmitter and receiver.
[0623] (2-2-2) Synchronization Header is synchronization information for linking information with QPKE Control Packet and PKE-EK Packet transmitted through the classical channel and QPKE Packet transmitted through the quantum channel.
[0624] (2-2-2-1) The Synchronization Header of the QPKE Control Packet transmitted through the classical channel and the Synchronization Header of the PKE-EK Packet and the Synchronization Header of the QPKE Packet transmitted through the quantum channel are composed of the same information.
[0625] (2-2-2-2) Synchronization Header can be a Synchronization Code promised in a predefined manner.
[0626] (2-2-2-2-1) For example, the Synchronization Code can be an Index indicating the order of the QPKE Packet, and the Synchronization Code can be defined as a Sequence structure that can be detected at the receiving end.
[0627] (2-2-2-2-2) Even though the Synchronization Code above is an index indicating the order of the QPKE Packet, it is defined as a Sequence structure with a length that can perform information separation among multiple users.
[0628] (2-2-2-3) Synchronization Header can be a randomly generated Synchronization Code.
[0629] (2-2-2-3-1) For example, it can be a sequence of random numbers generated through QRNG, etc.
[0630] (2-2-2-3-2) The length of the sequence consisting of random numbers corresponding to the synchronization code is agreed upon in advance between the transmitting and receiving ends.
[0631] (2-2-3) Protection Scheme ID is a field that indicates the encapsulation method and encryption method of the encapsulated and encrypted data of the QPKE Packet controlled by the QPKE Control Packet.
[0632] (2-2-3-1) Protection Scheme ID can be indicated by specifying different Encapsulation and Encryption methods.
[0633] (2-2-3-2) Protection Scheme ID can be made to function as a single identifier when the Encapsulation method and Encryption method are specified in the same way.
[0634] (2-2-3-3) Protection Scheme ID can include the Type of Quantum Public Key.
[0635] (2-2-3-4) Protection Scheme ID may not be used if it is agreed upon between the sender and receiver in a single manner.
[0636] (2-2-3-5) Protection Scheme ID can be set to the default value 0 if it is agreed upon between the transmitter and receiver in a single manner.
[0637] (2-2-4) Home Network Public Key ID is a field that indicates the Quantum Public Key ID for the Encapsulated & Encrypted Data of the QPKE Packet controlled by the QPKE Control Packet.
[0638] (2-2-4-1) Home Network Public Key ID represents the Quantum Public Key Index.
[0639] (2-2-4-1-1) If the Quantum Public Key used for Encapsulated & Encrypted Data is composed of multiple Quantum States, it can indicate the first Index among the entire Quantum Public Key.
[0640] (2-2-4-1-2) If the Quantum Public Key used for Encapsulated & Encrypted Data is composed of multiple Quantum States, it can represent the Index range of the entire Quantum Public Key.
[0641]
[0642] FIG. 36 is a diagram illustrating an example of a QPKE Packet structure in a system applicable to the present disclosure.
[0643] (2-3) When transmitting a QPKE Packet through a quantum channel, the QPKE Packet structure is as shown in Fig. 36.
[0644] (2-3-1) All QPKE Packets are generated as Quantum States, and the Synchronization Header can be composed of an Optical Signal. At this time, the Optical Signal can be an Optical Signal at the Single Photon level or a Field composed of Multiple Photons.
[0645] (2-3-1-1) The Synchronization Header composed of an optical signal is not information requiring security, and the signal can be composed in a method agreed upon in advance between the transmitting and receiving ends.
[0646] (2-3-1-2) For example, ON / Off Keying (OOK) or Phase / Amplitude / Polarization Modulation methods can be used.
[0647] (2-3-2) Synchronization Header is synchronization information for linking information with QPKE Control Packet and PKE-EK Packet transmitted through the classical channel and QPKE Packet transmitted through the quantum channel.
[0648] (2-3-2-1) The Synchronization Header of the QPKE Control Packet transmitted through the classical channel and the Synchronization Header of the PKE-EK Packet and the Synchronization Header of the QPKE Packet transmitted through the quantum channel are composed of the same information.
[0649] (2-3-2-2) Synchronization Header can be a Synchronization Code promised in a predefined manner.
[0650] (2-3-2-2-1) For example, the Synchronization Code can be an Index indicating the order of the QPKE Packet, and the Synchronization Code can be defined as a Sequence structure that can be detected at the receiving end.
[0651] (2-3-2-2-2) Even though the Synchronization Code above is an index indicating the order of the QPKE Packet, it is defined as a Sequence structure with a length that can perform information separation between multiple users.
[0652] (2-3-2-3) Synchronization Header can be a randomly generated Synchronization Code.
[0653] (2-3-2-3-1) For example, it can be a sequence of random numbers generated through QRNG, etc.
[0654] (2-3-2-3-2) The length of the sequence consisting of random numbers corresponding to the synchronization code is agreed upon in advance between the transmitting and receiving ends.
[0655] (2-3-3) Encapsulated & Encrypted Data is a data field that is encapsulated with an Ephemeral Key and encrypted with a Quantum Public Key expressed as a Home Network Public Key ID.
[0656] (2-3-3-1) This is a Quantum State in which data is encrypted using the Encryption method indicated in the Protection Scheme ID using the Quantum Public Key, and the Quantum State in which encrypted data is encapsulated using the Encapsulation method indicated in the Protection Scheme ID of the PEK-EK Packet using the Ephemeral Key.
[0657] (2-3-3-2) When multiple data are encrypted and encapsulated using multiple Quantum Public Keys and Classical Ephemeral Keys, the Encapsulated & Encrypted Data can be a Quantum State Stream.
[0658] (2-3-3-3) Encapsulation & Encrypted Data Field consisting of Quantum State Stream can have a field size defined in advance between the sender and receiver.
[0659]
[0660] 9. Transmission of (UE-HN) Classical Public Key Encrypted-Ephemeral Key (PKE-EK) Packet
[0661] The UE transmits a Classical Public Key Encrypted-Ephemeral Key (PKE-EK) Packet containing the Encrypted-Ephemeral Key to the HN through the classical channel.
[0662] FIG. 37 is a diagram illustrating an example of a PKE-EK Packet structure in a system applicable to the present disclosure.
[0663] (1) When transmitting a PKE-EK Packet through a classic channel, the structure of the PKE-EK Packet is as shown in Fig. 37.
[0664] (1-1) PKE-EK Packet consists entirely of classical information and can be composed of RF Signal or Optical Signal.
[0665] (1-1-1) For example, ON / Off Keying (OOK) or Phase / Amplitude / Polarization Modulation methods can be used.
[0666] (1-1-2) The fields of the PKE-EK Packet can have a field size that is agreed upon in advance between the transmitter and receiver.
[0667] (1-2) Synchronization Header is synchronization information for linking information with the QPKE Control Packet and PKE-EK Packet transmitted through the classical channel and the QPKE Packet transmitted through the quantum channel.
[0668] (1-2-1) The Synchronization Header of the QPKE Control Packet transmitted through the classical channel and the Synchronization Header of the PKE-EK Packet and the Synchronization Header of the QPKE Packet transmitted through the quantum channel are composed of the same information.
[0669] (1-2-2) Synchronization Header can be a Synchronization Code promised in a predefined manner.
[0670] (1-2-2-1) For example, the Synchronization Code can be an index indicating the order of the QPKE Packet, and the Synchronization Code can be defined as a sequence structure that can be detected at the receiving end.
[0671] (1-2-2-2) Even though the Synchronization Code above is an index indicating the order of the QPKE Packet, it is defined as a Sequence structure with a length that can perform information separation between multiple users.
[0672] (1-2-3) Synchronization Header can be a randomly generated Synchronization Code.
[0673] (1-2-3-1) For example, it can be a sequence of random numbers generated through QRNG, etc.
[0674] (1-2-3-2) The length of the sequence consisting of random numbers corresponding to the synchronization code is agreed upon in advance between the transmitting and receiving ends.
[0675] (1-3) Protection Scheme ID is a field that indicates the encryption method of the Encrypted Ephemeral Key of the PKE-EK Packet.
[0676] (1-3-1) The encryption methods are defined in advance as identifiers for encryption methods that encrypt / decrypt the Encrypted Ephemeral Key of the PKE-EK Packet.
[0677] (1-3-2) For example, the Protection Scheme Identifier of the SUCI structure of 3GPP TS 33.501 can be followed. (3GPP TS 23.003 2.2B and 33.501 Annex C.1)
[0678] (1-3-3) The encryption method can be predefined and shared in HN.
[0679] (1-3-4) Protection Scheme ID may not be used if it is agreed upon between the sender and receiver in a single manner.
[0680] (1-3-5) The Protection Scheme ID can be set to the default value 0 if it is agreed upon between the transmitter and receiver in a single manner.
[0681] (1-4) Home Network Public Key ID is a field that indicates the Classical Public Key ID used in the Encrypted Ephemeral Key of the PKE-EK Packet.
[0682] (1-4-1) This identifies the Classical Public Key of the Home Network and indicates which key among the Classical Public Keys was used.
[0683] (1-4-2) For example, the Home Network Public Key Identifier of the SUCI structure of 3GPP TS 33.501 can be followed. (3GPP TS 23.003 2.2B)
[0684] (1-5) Encrypted Ephemeral Key is a data field for the Ephemeral Key encrypted by the Classical Public Key of HN using an encryption technique corresponding to the Protection Scheme ID.
[0685] (1-5-1) Encrypted Ephemeral Key is HN’s Classical Public Key Ephemeral Key encrypted by Contains information.
[0686]
[0687] 10. Decryption of (HN) Classical Public Key Encrypted-Ephemeral Key (PKE-EK) Packet
[0688] HN decrypts the Classical Public Key Encrypted-Ephemeral Key (PKE-EK) Packet received from the UE to obtain the Ephemeral Key.
[0689] HN detects the Synchronization Header of the PKE-EK Packet to obtain the Synchronization Code. Furthermore, based on the Home Network Public Key ID, HN decrypts the Encrypted Ephemeral Key using the Private Key corresponding to the Trapdoor of the Public Key held by HN. At this time, the decryption method is performed based on the Protection Scheme ID of the PKE-EK Packet.
[0690] For example, Encrypted Ephemeral Key Is Private Key, which is Trapdoor Decryption by Ephemeral Key Vector Obtain .
[0691]
[0692] 11. (HN) Decapsulation of Quantum Public Key Encrypted (QPKE) Packet
[0693] FIG. 38 is a diagram illustrating an example of decapsulation by qubit rotation in a system applicable to the present disclosure.
[0694] HN decapsulates the encapsulated and encrypted data of the Quantum Public Key Encrypted (QPKE) Packet received through the quantum channel using an ephemeral key.
[0695] HN detects and compares the Synchronization Header of PEK-EK Packet and QPKE Packet, and ties packets with the same Synchronization Code.
[0696] HN is 10. (HN) Ephemeral Key Vector obtained by decrypting the Encrypted Ephemeral Key of the PKE-EK Packet in the Decryption of the Classical Public Key Encrypted-Ephemeral Key (PKE-EK) Packet. Based on this, Encapsulated & Encrypted Data of QPKE Packet received through quantum channel Decapsulate. Here, the decapsulation method is selected as the method of decapsulating the encapsulation method specified in the Protection Scheme ID of the QPKE Packet or QPKE Control Packet.
[0697] For example, HN is the Ephemeral Key information used for Encapsulation. 10. (HN) Classical Public Key Encrypted-Ephemeral Key (PKE-EK) is known through decryption of packet, so Encapsulated & Encrypted Data About Decapsulation Perform.
[0698] For example, if the protection scheme for encapsulation is Qubit Rotation, can be expressed as . Therefore, the received information to If you do, can be written as, Decapsulation can be performed as follows. That is, as a decapsulated quantum state, Encrypted Data is a data state encrypted with a Quantum Public Key. can be obtained.
[0699]
[0700] All Encapsulate & Encrypt Data in the same way For each Ephemeral Key Decapsulation can be achieved with , where i is the index of the data index and the ephemeral key.
[0701]
[0702] 12. (HN) Decryption of Quantum Public Key Encrypted (QPKE) Packet
[0703] HN decrypts the Encrypted Data, which is the decapsulated quantum state of the Encapsulated & Encrypted Data of the Quantum Public Key Encrypted (QPKE) Packet received through the quantum channel.
[0704] (1) Single Qubit based Public Key System
[0705] (1-1) When HN receives a quantum channel-based QPKE packet, it decrypts the public key information of the encrypted data into private key information based on the Protection Scheme ID and the Home Network Public Key ID. When the Home Network Public Key ID is i, HN decrypts the i-th Quantum Public Key Generation information (or Private Key) Because I know Compensation for Perform.
[0706] For example, if the Protection Scheme is Qubit Rotation, can be expressed as . Therefore, the received information to If you do, can be written as, In addition, in the case of the Qubit Rotation method, since the Qubit Rotation is commutative about the same axis, it can be expressed by the following mathematical expression 4.
[0707]
[0708] That is, as a decrypted quantum state, the initial state About the i-th Data information can be obtained. Therefore, if the Decrypted quantum state is measured, the Decrypted Data can be obtained. In the same way, if Decryption and quantum state measurement are performed on the Encrypted Data, which is the Decapsulated quantum state of the entire Encapsulated & Encrypted Data, the entire Data can be obtained.
[0709] (1-2) HN receives a QPKE Control Packet based on a classical channel, and when a QPKE Packet is received based on a quantum channel, it detects and compares the Synchronization Header of the QPKE Control Packet and the QPKE Packet, and ties packets with the same Synchronization Code.
[0710] Based on the Protection Scheme ID of the QPKE Control Packet and the Home Network Public Key ID, the Quantum Public Key information of the Encrypted Data, which is the decapsulated quantum state of the Encapsulated & Encrypted Data of the Tie QPKE Packet, is decrypted into Private Key information. When the Home Network Public Key ID is i, HN is the i-th Quantum Public Key Since we know the generation information (or Private Key) n_i, Compensation for Perform. When measuring the Decrypted quantum state compensated with , Decrypted Data can be obtained. In the same way, if Decryption and quantum state measurement are performed on the Encrypted Data, which is the Decapsulated quantum state of the entire Encapsulated & Encrypted Data, the entire Data can be obtained.
[0711] (2) Entanglement based Public Key System
[0712] (2-1) When HN receives a quantum channel-based QPKE Packet, it decrypts the quantum public key information of the Encrypted Data, which is the decapsulated quantum state of the Encapsulated & Encrypted Data, into private key information based on the Protection Scheme ID and the Home Network Public Key ID. When the Home Network Public Key ID is i, HN decrypts the i-th Quantum Public Key Generation information (or Private Key) Because I know Compensation for Perform.
[0713] For example, if the Protection Scheme is a Pauli Operation method, can be expressed as performing the same Pauli Operation. Therefore, the received information to If you do, can be written as, In addition, in the case of the Pauli Operation method, since the same Pauli Operation is commutative, it can be expressed by the following mathematical expression 5.
[0714]
[0715] That is, as the first particle of the Decrypted Bell state, the first particle of the initial Bell State About the i-th Data information can be obtained. Therefore, the first Particle in the Decrypted Bell state The second particle corresponding to the Quantum Secret Key that HN possessed By measuring using Bell State Measurement (BSM), the Decrypted Data d_i can be obtained. In the same way, by performing Decryption and BSM on the Encrypted Data, which is the decapsulated quantum state of the entire Encapsulated & Encrypted Data, the entire Data can be obtained.
[0716] (2-2) HN receives a QPKE Control Packet based on a classical channel, and when a QPKE Packet is received based on a quantum channel, it detects and compares the Synchronization Header of the QPKE Control Packet and the QPKE Packet, and ties packets with the same Synchronization Code.
[0717] Based on the Protection Scheme ID of the QPKE Control Packet and the Home Network Public Key ID, the Quantum Public Key information of the Encrypted Data, which is the decapsulated quantum state of the Encapsulated & Encrypted Data of the Tie QPKE Packet, is decrypted into Private Key information. When the Home Network Public Key ID is i, HN is the i-th Public Key Generation information (or Private Key) Because I know Compensation for Perform. If the Quantum Secret Key corresponding to the first and second Particles of the Decrypted Bell state are BSMed, the Decrypted Data can be obtained. In the same way, if Decryption and BSM are performed on the Encrypted Data, which is the decapsulated quantum state of the entire Encapsulated & Encrypted Data, the entire Data can be obtained.
[0718]
[0719] FIG. 39 is a diagram illustrating an example of the operation of a quantum channel and a classical channel signal that are encrypted with a single qubit based QPK in a coherence time based quantum public key infrastructure (QPKI) and encapsulated with an ephemeral key in a system applicable to the present disclosure.
[0720] (1) Alice generates a Classical Public Key (CP) using a Classical Private Key (CS) and shares it with Bob in advance through a trusted network (Provisioning).
[0721] (2) When Bob has a message (m) he wants to send, he requests Alice's Quantum Public Key.
[0722] (3) When Alice is asked for a Quantum Public Key from Bob, she generates a Quantum Public Key (p) using her Private Key (s) and sends it to Bob in real time.
[0723] (4) Bob encrypts the message (m) with the quantum public key (p) received from Alice.
[0724] (5) Bob performs encapsulation based on a randomly generated Ephemeral Key (b) on the encoded message and sends it to Alice.
[0725] (6) Bob encrypts the randomly generated Ephemeral Key (b) with the Classical Public Key (CP) and sends it to Alice.
[0726] (7) Alice obtains the Ephemeral Key by decrypting the Ephemeral Key encrypted with the Classical Public Key (CP) among the received signals using the Classical Private Key (CS).
[0727] (8) Alice decapsulates the encapsulated and encrypted message among the received signals using the acquired Ephemeral Key (b), and compensates for the information of the Quantum Public Key (p) using the Private Key (s), leaving only the Message (m) information.
[0728] (8-1) Alice obtains the Ephemeral Key by decryption within Y hours based on the Classical Private Key (CS) information, and the Message, which is a quantum state, must be decapsulated and decrypted to avoid collapse.
[0729] (9) Alice measures the signal that leaves only the Message (m) information and obtains the target Message (m) information.
[0730]
[0731] FIG. 40 is a flowchart illustrating the entire process of Coherence Time based Quantum Public Key Infrastructure (QPKI) in a system applicable to the present disclosure.
[0732] Alice generates a Classical Public Key using a Classical Private Key.
[0733] Alice and Bob share a classic public key via a certificated infrastructure.
[0734] Alice receives a Request Quantum Public Key from Bob.
[0735] Alice performs QPK Generation.
[0736] Alice performs Transmit Quantum Public Key to Bob.
[0737] Bob performs message encryption on a plaintext message.
[0738] Afterwards, quantum state encapsulation is performed.
[0739] Bob performs encapsulation using an ephemeral key.
[0740] Bob performs E-Key Encryption.
[0741] Alice receives a QPKE packet from Bob.
[0742] Alice receives a PKE-EK packet from Bob.
[0743] Alice performs E-Key Decryption.
[0744] Alice performs decapsulation.
[0745] Alice performs message decryption.
[0746] Alice performs message detection.
[0747]
[0748] The QPKE Control Packet, QPKE Packet, and PKE-EK Packet mentioned above have been described in terms of the relationship between the UE and the HN, but it is self-evident that the same method can be applied to nodes of the same level. For example, the UE can be Node A, and the HN can be Node B, and they can use the same method to configure Quantum Public Key Encrypted Packets to exchange Encapsulated & Encrypted Data. In this case, the Home Network Public Key ID can be renamed and operated as the Public Key ID of the other Node.
[0749] All of the general signal information transmitted via classical channels can also be transmitted via quantum channels. However, unlike information transmitted via quantum channels, information that can be transmitted via classical channels may not have physical security requirements.
[0750] In the proposed Quantum Public Key Infrastructure System based on Quantum Coherence Time, the Classical Public Key System is not limited to encryption methods based on Public Key Encryption, such as RSA (RIVEST-SHAMIR-ADLEMAN) or ECC (Elliptic Curve Cryptography). It is self-evident that the Classical Public Key System in the proposed Quantum Public Key Infrastructure System can correspond to any encryption method that utilizes asymmetric keys. For example, it is self-evident that the same method can be applied to the Post-Quantum Cryptography (PQC) encryption method developed to counter quantum algorithms.
[0751]
[0752] Effects of various embodiments of the present disclosure
[0753] The expected effects of various embodiments of the present disclosure are as follows.
[0754] (1) You can share QPK and configure a QPKI system using QPKE.
[0755] (2) Physical security is provided through QPK to counter threats to existing PKI systems caused by quantum algorithms.
[0756] (2-1) Even without an ideal assumption on quantum memory, Alice decapsulates within the coherence time, and Eve physically defends against the HNDL attack by making decapsulation impossible within the coherence time.
[0757] (3) Physical security is provided through QPKI for the transmission of subscriber identity information in existing communication systems.
[0758] (4) Define Data Field and Signaling to operate in 3GPP Standard.
[0759]
[0760] Characteristic configurations of various embodiments of the present disclosure are as follows.
[0761] (1) PKE-EK Packet configuration and its procedure
[0762] (2) Linking procedure between PKE-EK and QPKE Packet
[0763] (3) Method and procedure for encapsulation and decapsulation of quantum states using EK
[0764] (4) Method and procedure for performing encryption using Quantum Public Key and encapsulation using EK in a hybrid manner
[0765]
[0766] [Description of the first node claim]
[0767] The embodiments described below are specifically described with reference to FIG. 41 in terms of the operation of the first node. The methods described below are distinguished for convenience of explanation, and it is understood that some components of one method may be substituted for some components of another method, or may be applied in combination with each other, as long as they are not mutually exclusive.
[0768] FIG. 41 is a diagram illustrating an example of the operation process of the first node in a system applicable to the present disclosure.
[0769] According to various embodiments of the present disclosure, a method performed by a first node in a communication system is provided.
[0770] According to various embodiments of the present disclosure, each of the first node and the second node may correspond to either a terminal or a base station in a wireless communication system. According to various embodiments of the present disclosure, the first node may correspond to either Alice, HN, or BS.
[0771] The embodiment of FIG. 41 may further include, before step S4101, one or more of the following steps: a step in which the first node transmits one or more synchronization signals to the second node; a step in which the first node transmits system information to the second node; a step in which the first node transmits configuration information to the second node; and a step in which the first node transmits control information to the second node.
[0772] The embodiment of FIG. 41 may further include, before step S4101, one or more of the following steps: a step in which the first node receives a random access preamble from the second node; a step in which the first node transmits a random access response (RAR) to the second node; a step in which the first node receives a random access message 3 from the second node; and a step in which the first node transmits a contention resolution message to the second node. Message 3 is a first PUSCH transmission scheduled by the RAR together with an RAR UL grant.
[0773] At step S4101, the first node receives a request for a quantum public key (QPK) from the second node.
[0774] At step S4102, the first node transmits the QPK based on the private key associated with the first node to the second node.
[0775] At step S4103, the first node receives a message on which encryption and quantum state encapsulation based on QPK have been performed from the second node.
[0776]
[0777] According to various embodiments of the present disclosure, the message may include a first message based on a quantum public key encrypted packet (QPKE packet) and a second message based on a public key encrypted-ephemeral key packet (PKE-EK packet).
[0778] According to various embodiments of the present disclosure, the message may be encrypted based on the QPK.
[0779] According to various embodiments of the present disclosure, the quantum state encapsulation may be performed on the message based on an ephemeral key.
[0780] According to various embodiments of the present disclosure, the embodiment of FIG. 41 may further include the steps of transmitting a CP key (classical public key) associated with the first node to the second node; and receiving the temporary key encrypted based on the CP key from the second node.
[0781] According to various embodiments of the present disclosure, the embodiment of FIG. 41 may further include a step of obtaining the temporary key through decryption of the encrypted temporary key based on the CP key; and a step of obtaining information of the message through decapsulation of the message based on the temporary key.
[0782] According to various embodiments of the present disclosure, the CP key may be transmitted in advance through a specific network.
[0783] According to various embodiments of the present disclosure, information of the message can be obtained by performing compensation of the QPK using the private key for the message on which the decapsulation was performed.
[0784] According to various embodiments of the present disclosure, the message in the quantum state may not be collapsed if the decapsulation by the temporary key is performed within a set time.
[0785]
[0786] According to various embodiments of the present disclosure, a first node is provided in a communication system. The first node includes a transceiver and at least one processor, wherein the at least one processor may be configured to perform the operating method of the first node according to FIG. 41.
[0787]
[0788] According to various embodiments of the present disclosure, a device for controlling a first node in a communication system is provided. The device includes at least one processor and at least one memory operably connected to the at least one processor. The at least one memory may be configured to store instructions for performing an operating method of the first node according to FIG. 41 based on instructions executed by the at least one processor.
[0789]
[0790] According to various embodiments of the present disclosure, one or more non-transitory computer-readable media (CRM) storing one or more instructions are provided. The one or more instructions, when executed by one or more processors, perform operations, and the operations may include the operating method of the first node according to FIG. 41.
[0791]
[0792] [Description of the second node claim]
[0793] The embodiments described below are specifically described with reference to FIG. 42 in terms of the operation of the second node. The methods described below are distinguished for convenience of explanation, and it is understood that some components of one method may be substituted for some components of another method, or may be applied in combination with each other, as long as they are not mutually exclusive.
[0794] FIG. 42 is a diagram illustrating an example of the operation process of a second node in a system applicable to the present disclosure.
[0795] According to various embodiments of the present disclosure, a method performed by a second node in a communication system is provided.
[0796] According to various embodiments of the present disclosure, each of the first node and the second node may correspond to either a terminal or a base station in a wireless communication system. According to various embodiments of the present disclosure, the second node may correspond to either Bob or a UE.
[0797] The embodiment of FIG. 42 may further include, before step S4201, one or more of the following steps: a step in which the second node receives one or more synchronization signals from the first node; a step in which the second node receives system information from the first node; a step in which the second node receives configuration information from the first node; and a step in which the second node receives control information from the first node.
[0798] The embodiment of FIG. 42 may further include, before step S4201, one or more of the following steps: a step in which the second node transmits a random access preamble to the first node; a step in which the second node receives a random access response (RAR) from the first node; a step in which the second node transmits a random access message 3 to the first node; and a step in which the second node receives a contention resolution message from the first node. Message 3 is a first PUSCH transmission scheduled by RAR together with an RAR UL grant.
[0799] At step S4201, the second node sends a request for a quantum public key (QPK) to the first node.
[0800] At step S4202, the second node receives the QPK from the first node based on a private key associated with the first node.
[0801] At step S4203, the second node transmits a message on which encryption and quantum state encapsulation based on QPK have been performed to the first node.
[0802]
[0803] According to various embodiments of the present disclosure, the message may include a first message based on a quantum public key encrypted packet (QPKE packet) and a second message based on a public key encrypted-ephemeral key packet (PKE-EK packet).
[0804] According to various embodiments of the present disclosure, the message may be encrypted based on the QPK.
[0805] According to various embodiments of the present disclosure, the quantum state encapsulation may be performed on the message based on an ephemeral key.
[0806] According to various embodiments of the present disclosure, the embodiment of FIG. 42 may further include the steps of: receiving a classical public key (CP key) associated with the first node from the first node; and transmitting the temporary key encrypted based on the CP key to the first node.
[0807] According to various embodiments of the present disclosure, information of the message can be decoded through decapsulation of the message based on the temporary key.
[0808] According to various embodiments of the present disclosure, the temporary key can be decrypted based on the CP key.
[0809] According to various embodiments of the present disclosure, the CP key may be received in advance through a specific network.
[0810] According to various embodiments of the present disclosure, information of the message can be obtained by performing compensation of the QPK using the private key for the message on which the decapsulation was performed.
[0811] According to various embodiments of the present disclosure, the message in the quantum state may not be collapsed if the decapsulation by the temporary key is performed within a set time.
[0812]
[0813] According to various embodiments of the present disclosure, a second node is provided in a communication system. The second node includes a transceiver and at least one processor, wherein the at least one processor may be configured to perform the operating method of the second node according to FIG. 42.
[0814]
[0815] According to various embodiments of the present disclosure, a device for controlling a first node in a communication system is provided. The device includes at least one processor and at least one memory operably connected to the at least one processor. The at least one memory may be configured to store instructions for performing an operating method of a second node according to FIG. 42 based on instructions executed by the at least one processor.
[0816]
[0817] According to various embodiments of the present disclosure, one or more non-transitory computer-readable media (CRM) storing one or more instructions are provided. The one or more instructions, when executed by one or more processors, perform operations, and the operations may include the operating method of a second node according to FIG. 42.
[0818]
[0819] Communication system applicable to the present disclosure
[0820] FIG. 43 illustrates a communication system (1) applicable to various embodiments of the present disclosure.
[0821] Referring to FIG. 43, a communication system (1) applicable to various embodiments of the present disclosure includes a wireless device, a base station, and a network. Here, the wireless device refers to a device that performs communication using a wireless access technology (e.g., 5G NR (New RAT), LTE (Long Term Evolution), 6G wireless communication), and may be referred to as a communication / wireless / 5G device / 6G device. Although not limited thereto, the wireless device may include a robot (100a), a vehicle (100b-1, 100b-2), an XR (eXtended Reality) device (100c), a hand-held device (100d), a home appliance (100e), an IoT (Internet of Things) device (100f), and an AI device / server (400). For example, the vehicle may include a vehicle equipped with a wireless communication function, an autonomous vehicle, a vehicle capable of performing vehicle-to-vehicle communication, etc. Here, the vehicle may include an Unmanned Aerial Vehicle (UAV) (e.g., a drone). XR devices include AR (Augmented Reality) / VR (Virtual Reality) / MR (Mixed Reality) devices, and may be implemented in the form of a Head-Mounted Device (HMD), a Head-Up Display (HUD) installed in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, digital signage, a vehicle, a robot, etc. Mobile devices may include a smartphone, a smart pad, a wearable device (e.g., a smart watch, smart glasses), a computer (e.g., a laptop, etc.), etc. Home appliances may include a TV, a refrigerator, a washing machine, etc. IoT devices may include a sensor, a smart meter, etc. For example, a base station and a network may also be implemented as a wireless device, and a specific wireless device (200a) may act as a base station / network node to other wireless devices.
[0822] Wireless devices (100a to 100f) can be connected to a network (300) via a base station (200). Artificial Intelligence (AI) technology can be applied to the wireless devices (100a to 100f), and the wireless devices (100a to 100f) can be connected to an AI server (400) via the network (300). The network (300) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, or a 6G network. The wireless devices (100a to 100f) can communicate with each other via the base station (200) / network (300), but can also communicate directly (e.g., sidelink communication) without going through the base station / network. For example, vehicles (100b-1, 100b-2) can communicate directly (e.g., V2V (Vehicle to Vehicle) / V2X (Vehicle to Everything) communication). In addition, IoT devices (e.g., sensors) can communicate directly with other IoT devices (e.g., sensors) or other wireless devices (100a to 100f).
[0823] Wireless communication / connection (150a, 150b, 150c) can be established between wireless devices (100a~100f) / base stations (200), and base stations (200) / base stations (200). Here, wireless communication / connection can be achieved through various wireless access technologies (e.g., 5G NR) such as uplink / downlink communication (150a), sidelink communication (150b) (or D2D communication), and communication between base stations (150c) (e.g., relay, IAB (Integrated Access Backhaul). Through wireless communication / connection (150a, 150b, 150c), wireless devices and base stations / wireless devices, and base stations and base stations can transmit / receive wireless signals to each other. For example, wireless communication / connection (150a, 150b, 150c) can transmit / receive signals through various physical channels. To this end, at least some of various configuration information setting processes for transmitting / receiving wireless signals, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), and resource allocation processes can be performed based on various proposals of various embodiments of the present disclosure.
[0824] Meanwhile, NR supports multiple numerologies (or subcarrier spacing (SCS)) to support various 5G services. For example, an SCS of 15 kHz supports a wide area in traditional cellular bands; an SCS of 30 kHz / 60 kHz supports dense urban areas, lower latency, and wider carrier bandwidth; and an SCS of 60 kHz or higher supports a bandwidth greater than 24.25 GHz to overcome phase noise.
[0825] The NR frequency band can be defined by two types of frequency ranges (FR1, FR2). The numerical values of the frequency ranges can be changed, and for example, the frequency ranges of the two types (FR1, FR2) can be as shown in Table 3 below. For convenience of explanation, among the frequency ranges used in the NR system, FR1 can mean the "sub 6 GHz range", and FR2 can mean the "above 6 GHz range" and can be called millimeter wave (mmW).
[0826]
[0827] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR1450MHz-6000MHz15, 30, 60kHzFR224250MHz-52600MHz60, 120, 240kHz
[0828]
[0829] As described above, the numerical value of the frequency range of the NR system can be changed. For example, FR1 may include a band from 410 MHz to 7125 MHz, as shown in Table 4 below. That is, FR1 may include a frequency band above 6 GHz (or 5850, 5900, 5925 MHz, etc.). For example, the frequency band above 6 GHz (or 5850, 5900, 5925 MHz, etc.) included within FR1 may include an unlicensed band. The unlicensed band may be used for various purposes, such as for vehicular communications (e.g., autonomous driving).
[0830] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR141MHz-7125MHz15, 30, 60kHzFR224250MHz-52600MHz60, 120, 240kHz
[0831] According to various embodiments of the present disclosure, the communication system (1) can support terahertz (THz) wireless communication. THz wireless communication is a wireless communication using THz waves having a frequency of approximately 0.1 to 10 THz (1 THz = 1012 Hz), and may refer to terahertz (THz) band wireless communication using a very high carrier frequency of 100 GHz or higher. The frequency band expected to be used for THz wireless communication may be a D-band (110 GHz to 170 GHz) or H-band (220 GHz to 325 GHz) band where propagation loss due to absorption of molecules in the air is small.
[0832]
[0833] Wireless devices applicable to the present disclosure
[0834] Below, examples of wireless devices to which various embodiments of the present disclosure are applied are described.
[0835] FIG. 44 illustrates a wireless device that can be applied to various embodiments of the present disclosure.
[0836] Referring to FIG. 44, the first wireless device (100) and the second wireless device (200) can transmit and receive wireless signals through various wireless access technologies (e.g., LTE, NR). Here, {the first wireless device (100), the second wireless device (200)} can correspond to {the wireless device (100x), the base station (200)} and / or {the wireless device (100x), the wireless device (100x)} of FIG. 43.
[0837] A first wireless device (100) includes one or more processors (102) and one or more memories (104), and may further include one or more transceivers (106) and / or one or more antennas (108). The processor (102) controls the memories (104) and / or the transceivers (106), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this document. For example, the processor (102) may process information in the memory (104) to generate first information / signal, and then transmit a wireless signal including the first information / signal via the transceiver (106). In addition, the processor (102) may receive a wireless signal including second information / signal via the transceiver (106), and then store information obtained from signal processing of the second information / signal in the memory (104). The memory (104) may be connected to the processor (102) and may store various information related to the operation of the processor (102). For example, the memory (104) may perform some or all of the processes controlled by the processor (102), or may store software code including commands for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. Here, the processor (102) and the memory (104) may be part of a communication modem / circuit / chip designed to implement a wireless communication technology (e.g., LTE, NR). The transceiver (106) may be connected to the processor (102) and may transmit and / or receive wireless signals via one or more antennas (108). The transceiver (106) may include a transmitter and / or a receiver. The transceiver (106) may be used interchangeably with an RF (Radio Frequency) unit. In various embodiments of the present disclosure, a wireless device may mean a communication modem / circuit / chip.
[0838] The second wireless device (200) includes one or more processors (202), one or more memories (204), and may further include one or more transceivers (206) and / or one or more antennas (208). The processor (202) controls the memories (204) and / or the transceivers (206), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this document. For example, the processor (202) may process information in the memory (204) to generate third information / signals, and then transmit a wireless signal including the third information / signals via the transceivers (206). Furthermore, the processor (202) may receive a wireless signal including fourth information / signals via the transceivers (206), and then store information obtained from signal processing of the fourth information / signals in the memory (204). The memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, the memory (204) may perform some or all of the processes controlled by the processor (202), or may store software code including commands for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. Here, the processor (202) and the memory (204) may be part of a communication modem / circuit / chip designed to implement wireless communication technology (e.g., LTE, NR). The transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals via one or more antennas (208). The transceiver (206) may include a transmitter and / or a receiver. The transceiver (206) may be used interchangeably with an RF unit. In various embodiments of the present disclosure, a wireless device may also mean a communication modem / circuit / chip.
[0839] Hereinafter, the hardware elements of the wireless device (100, 200) will be described in more detail. Although not limited thereto, one or more protocol layers may be implemented by one or more processors (102, 202). For example, one or more processors (102, 202) may implement one or more layers (e.g., functional layers such as PHY, MAC, RLC, PDCP, RRC, SDAP). One or more processors (102, 202) may generate one or more Protocol Data Units (PDUs) and / or one or more Service Data Units (SDUs) according to the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. One or more processors (102, 202) may generate messages, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. One or more processors (102, 202) can generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data or information according to the functions, procedures, proposals and / or methods disclosed herein, and provide the signals to one or more transceivers (106, 206). One or more processors (102, 202) can receive signals (e.g., baseband signals) from one or more transceivers (106, 206) and obtain PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed herein.
[0840] One or more processors (102, 202) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer. One or more processors (102, 202) may be implemented by hardware, firmware, software, or a combination thereof. For example, one or more Application Specific Integrated Circuits (ASICs), one or more Digital Signal Processors (DSPs), one or more Digital Signal Processing Devices (DSPDs), one or more Programmable Logic Devices (PLDs), or one or more Field Programmable Gate Arrays (FPGAs) may be included in one or more processors (102, 202). The descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this document may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. The descriptions, functions, procedures, suggestions, methods and / or operation flowcharts disclosed in this document may be implemented using firmware or software configured to perform one or more processors (102, 202) or stored in one or more memories (104, 204) and executed by one or more processors (102, 202). The descriptions, functions, procedures, suggestions, methods and / or operation flowcharts disclosed in this document may be implemented using firmware or software in the form of codes, instructions and / or sets of instructions.
[0841] One or more memories (104, 204) may be coupled to one or more processors (102, 202) and may store various forms of data, signals, messages, information, programs, codes, instructions, and / or commands. The one or more memories (104, 204) may be configured as ROM, RAM, EPROM, flash memory, hard drives, registers, cache memory, computer-readable storage media, and / or combinations thereof. The one or more memories (104, 204) may be located internally and / or externally to the one or more processors (102, 202). Additionally, the one or more memories (104, 204) may be coupled to the one or more processors (102, 202) via various technologies, such as wired or wireless connections.
[0842] One or more transceivers (106, 206) can transmit user data, control information, wireless signals / channels, etc., as mentioned in the methods and / or flowcharts of this document, to one or more other devices. One or more transceivers (106, 206) can receive user data, control information, wireless signals / channels, etc., as mentioned in the descriptions, functions, procedures, proposals, methods and / or flowcharts of this document, from one or more other devices. For example, one or more transceivers (106, 206) can be connected to one or more processors (102, 202) and can transmit and receive wireless signals. For example, one or more processors (102, 202) can control one or more transceivers (106, 206) to transmit user data, control information, or wireless signals to one or more other devices. Additionally, one or more processors (102, 202) may control one or more transceivers (106, 206) to receive user data, control information, or wireless signals from one or more other devices. Additionally, one or more transceivers (106, 206) may be coupled to one or more antennas (108, 208), and one or more transceivers (106, 206) may be configured to transmit and receive user data, control information, wireless signals / channels, or the like, as referred to in the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein, via one or more antennas (108, 208). In this document, one or more antennas may be multiple physical antennas or multiple logical antennas (e.g., antenna ports). One or more transceivers (106, 206) can convert received user data, control information, wireless signals / channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc. using one or more processors (102, 202).One or more transceivers (106, 206) may convert user data, control information, wireless signals / channels, etc. processed by one or more processors (102, 202) from baseband signals to RF band signals. For this purpose, one or more transceivers (106, 206) may include an (analog) oscillator and / or filter.
[0843] FIG. 45 illustrates another example of a wireless device that can be applied to various embodiments of the present disclosure.
[0844] According to FIG. 45, the wireless device may include at least one processor (102, 202), at least one memory (104, 204), at least one transceiver (106, 206), and one or more antennas (108, 208).
[0845] The difference between the example of the wireless device described in FIG. 44 and the example of the wireless device in FIG. 45 is that in FIG. 44, the processor (102, 202) and the memory (104, 204) are separated, but in the example of FIG. 45, the memory (104, 204) is included in the processor (102, 202).
[0846] Here, the specific description of the processor (102, 202), memory (104, 204), transceiver (106, 206), and one or more antennas (108, 208) is as described above, so in order to avoid unnecessary repetition of description, the description of the repeated description is omitted.
[0847] Below, examples of signal processing circuits to which various embodiments of the present disclosure are applied are described.
[0848] Figure 46 illustrates a signal processing circuit for a transmission signal.
[0849] Referring to FIG. 46, the signal processing circuit (1000) may include a scrambler (1010), a modulator (1020), a layer mapper (1030), a precoder (1040), a resource mapper (1050), and a signal generator (1060). Although not limited thereto, the operations / functions of FIG. 46 may be performed in the processor (102, 202) and / or the transceiver (106, 206) of FIG. 44. The hardware elements of FIG. 46 may be implemented in the processor (102, 202) and / or the transceiver (106, 206) of FIG. 44. For example, blocks 1010 to 1060 may be implemented in the processor (102, 202) of FIG. 44. Additionally, blocks 1010 to 1050 may be implemented in the processor (102, 202) of FIG. 44, and block 1060 may be implemented in the transceiver (106, 206) of FIG. 44.
[0850] The codeword can be converted into a wireless signal through the signal processing circuit (1000) of FIG. 46. Here, the codeword is an encoded bit sequence of an information block. The information block can include a transport block (e.g., an UL-SCH transport block, a DL-SCH transport block). The wireless signal can be transmitted through various physical channels (e.g., a PUSCH or a PDSCH).
[0851] Specifically, the codeword can be converted into a bit sequence scrambled by a scrambler (1010). The scramble sequence used for scrambling is generated based on an initialization value, and the initialization value may include ID information of the wireless device, etc. The scrambled bit sequence can be modulated into a modulation symbol sequence by a modulator (1020). The modulation method may include pi / 2-BPSK (pi / 2-Binary Phase Shift Keying), m-PSK (m-Phase Shift Keying), m-QAM (m-Quadrature Amplitude Modulation), etc. The complex modulation symbol sequence can be mapped to one or more transmission layers by a layer mapper (1030). The modulation symbols of each transmission layer can be mapped to the corresponding antenna port(s) by a precoder (1040) (precoding). The output z of the precoder (1040) can be obtained by multiplying the output y of the layer mapper (1030) by a precoding matrix W of N*M. Here, N is the number of antenna ports, and M is the number of transmission layers. Here, the precoder (1040) can perform precoding after performing transform precoding (e.g., DFT transform) on complex modulation symbols. In addition, the precoder (1040) can perform precoding without performing transform precoding.
[0852] The resource mapper (1050) can map modulation symbols of each antenna port to time-frequency resources. The time-frequency resources can include multiple symbols (e.g., CP-OFDMA symbols, DFT-s-OFDMA symbols) in the time domain and multiple subcarriers in the frequency domain. The signal generator (1060) generates a wireless signal from the mapped modulation symbols, and the generated wireless signal can be transmitted to another device through each antenna. To this end, the signal generator (1060) can include an Inverse Fast Fourier Transform (IFFT) module, a Cyclic Prefix (CP) inserter, a Digital-to-Analog Converter (DAC), a frequency uplink converter, etc.
[0853] The signal processing process for receiving signals in a wireless device can be configured in reverse order of the signal processing process (1010 to 1060) of FIG. 46. For example, a wireless device (e.g., 100, 200 of FIG. 44) can receive wireless signals from the outside through an antenna port / transceiver. The received wireless signals can be converted into baseband signals through a signal restorer. For this purpose, the signal restorer can include a frequency downlink converter, an analog-to-digital converter (ADC), a CP remover, and a fast Fourier transform (FFT) module. Thereafter, the baseband signal can be restored to a codeword through a resource demapper process, a postcoding process, a demodulation process, and a descrambling process. The codewords can be restored to the original information blocks through decoding. Accordingly, a signal processing circuit (not shown) for a received signal may include a signal restorer, a resource de-mapper, a postcoder, a demodulator, a de-scrambler, and a decoder.
[0854] Below, examples of wireless device utilization to which various embodiments of the present disclosure are applied are described.
[0855] Figure 47 illustrates another example of a wireless device applicable to various embodiments of the present disclosure. The wireless device may be implemented in various forms depending on the use case / service (see Figure 43).
[0856] Referring to FIG. 47, the wireless device (100, 200) corresponds to the wireless device (100, 200) of FIG. 44 and may be composed of various elements, components, units, and / or modules. For example, the wireless device (100, 200) may include a communication unit (110), a control unit (120), a memory unit (130), and an additional element (140). The communication unit may include a communication circuit (112) and a transceiver(s) (114). For example, the communication circuit (112) may include one or more processors (102, 202) and / or one or more memories (104, 204) of FIG. 44. For example, the transceiver(s) (114) may include one or more transceivers (106, 206) and / or one or more antennas (108, 208) of FIG. 44. The control unit (120) is electrically connected to the communication unit (110), the memory unit (130), and the additional elements (140) and controls the overall operation of the wireless device. For example, the control unit (120) may control the electrical / mechanical operation of the wireless device based on the program / code / command / information stored in the memory unit (130). In addition, the control unit (120) may transmit information stored in the memory unit (130) to an external device (e.g., another communication device) via a wireless / wired interface through the communication unit (110), or store information received from an external device (e.g., another communication device) via a wireless / wired interface in the memory unit (130).
[0857] The additional element (140) may be configured in various ways depending on the type of the wireless device. For example, the additional element (140) may include at least one of a power unit / battery, an input / output unit (I / O unit), a driving unit, and a computing unit. Although not limited thereto, the wireless device may be implemented in the form of a robot (Fig. 43, 100a), a vehicle (Fig. 43, 100b-1, 100b-2), an XR device (Fig. 43, 100c), a portable device (Fig. 43, 100d), a home appliance (Fig. 43, 100e), an IoT device (Fig. 43, 100f), a digital broadcasting terminal, a hologram device, a public safety device, an MTC device, a medical device, a fintech device (or a financial device), a security device, a climate / environmental device, an AI server / device (Fig. 43, 400), a base station (Fig. 43, 200), a network node, etc. Wireless devices may be mobile or stationary depending on the use / service.
[0858] In FIG. 47, various elements, components, units / parts, and / or modules within the wireless device (100, 200) may be entirely interconnected via a wired interface, or at least some may be wirelessly connected via a communication unit (110). For example, within the wireless device (100, 200), the control unit (120) and the communication unit (110) may be wired, and the control unit (120) and a first unit (e.g., 130, 140) may be wirelessly connected via the communication unit (110). In addition, each element, component, unit / part, and / or module within the wireless device (100, 200) may further include one or more elements. For example, the control unit (120) may be composed of a set of one or more processors. For example, the control unit (120) may be composed of a set of a communication control processor, an application processor, an electronic control unit (ECU), a graphics processing processor, a memory control processor, etc. As another example, the memory unit (130) may be composed of RAM (Random Access Memory), DRAM (Dynamic RAM), ROM (Read Only Memory), flash memory, volatile memory, non-volatile memory, and / or a combination thereof.
[0859] Below, the implementation example of Fig. 47 is described in more detail with reference to the drawings.
[0860] Figure 48 illustrates a mobile device applicable to various embodiments of the present disclosure. The mobile device may include a smartphone, a smart pad, a wearable device (e.g., a smartwatch, smartglasses), or a portable computer (e.g., a laptop, etc.). The mobile device may be referred to as a Mobile Station (MS), a User Terminal (UT), a Mobile Subscriber Station (MSS), a Subscriber Station (SS), an Advanced Mobile Station (AMS), or a Wireless Terminal (WT).
[0861] Referring to FIG. 48, the portable device (100) may include an antenna unit (108), a communication unit (110), a control unit (120), a memory unit (130), a power supply unit (140a), an interface unit (140b), and an input / output unit (140c). The antenna unit (108) may be configured as a part of the communication unit (110). Blocks 110 to 130 / 140a to 140c correspond to blocks 110 to 130 / 140 of FIG. 47, respectively.
[0862] The communication unit (110) can transmit and receive signals (e.g., data, control signals, etc.) with other wireless devices and base stations. The control unit (120) can control components of the mobile device (100) to perform various operations. The control unit (120) can include an AP (Application Processor). The memory unit (130) can store data / parameters / programs / codes / commands required for operating the mobile device (100). In addition, the memory unit (130) can store input / output data / information, etc. The power supply unit (140a) supplies power to the mobile device (100) and can include a wired / wireless charging circuit, a battery, etc. The interface unit (140b) can support connection between the mobile device (100) and other external devices. The interface unit (140b) can include various ports (e.g., audio input / output ports, video input / output ports) for connection with external devices. The input / output unit (140c) can input or output video information / signals, audio information / signals, data, and / or information input from a user. The input / output unit (140c) may include a camera, a microphone, a user input unit, a display unit (140d), a speaker, and / or a haptic module.
[0863] For example, in the case of data communication, the input / output unit (140c) obtains information / signals (e.g., touch, text, voice, image, video) input by the user, and the obtained information / signals can be stored in the memory unit (130). The communication unit (110) converts the information / signals stored in the memory into wireless signals, and can directly transmit the converted wireless signals to other wireless devices or to a base station. In addition, the communication unit (110) can receive wireless signals from other wireless devices or base stations, and then restore the received wireless signals to the original information / signals. The restored information / signals can be stored in the memory unit (130) and then output in various forms (e.g., text, voice, image, video, haptic) through the input / output unit (140c).
[0864] FIG. 49 illustrates a vehicle or autonomous vehicle applicable to various embodiments of the present disclosure.
[0865] Vehicles or autonomous vehicles can be implemented as mobile robots, cars, trains, manned or unmanned aerial vehicles (AVs), ships, etc.
[0866] Referring to FIG. 49, a vehicle or autonomous vehicle (100) may include an antenna unit (108), a communication unit (110), a control unit (120), a driving unit (140a), a power supply unit (140b), a sensor unit (140c), and an autonomous driving unit (140d). The antenna unit (108) may be configured as a part of the communication unit (110). Blocks 110 / 130 / 140a to 140d correspond to blocks 110 / 130 / 140 of FIG. 47, respectively.
[0867] The communication unit (110) can transmit and receive signals (e.g., data, control signals, etc.) with external devices such as other vehicles, base stations (e.g., base stations, road side units, etc.), and servers. The control unit (120) can control elements of the vehicle or autonomous vehicle (100) to perform various operations. The control unit (120) can include an ECU (Electronic Control Unit). The drive unit (140a) can drive the vehicle or autonomous vehicle (100) on the ground. The drive unit (140a) can include an engine, a motor, a power train, wheels, brakes, a steering device, etc. The power supply unit (140b) supplies power to the vehicle or autonomous vehicle (100) and can include a wired / wireless charging circuit, a battery, etc. The sensor unit (140c) can obtain vehicle status, surrounding environment information, user information, etc. The sensor unit (140c) may include an IMU (inertial measurement unit) sensor, a collision sensor, a wheel sensor, a speed sensor, an incline sensor, a weight detection sensor, a heading sensor, a position module, a vehicle forward / backward sensor, a battery sensor, a fuel sensor, a tire sensor, a steering sensor, a temperature sensor, a humidity sensor, an ultrasonic sensor, an illuminance sensor, a pedal position sensor, etc. The autonomous driving unit (140d) may implement a technology for maintaining a driving lane, a technology for automatically controlling speed such as adaptive cruise control, a technology for automatically driving along a set path, a technology for automatically setting a path and driving when a destination is set, etc.
[0868] For example, the communication unit (110) can receive map data, traffic information data, etc. from an external server. The autonomous driving unit (140d) can generate an autonomous driving route and driving plan based on the acquired data. The control unit (120) can control the drive unit (140a) so that the vehicle or autonomous vehicle (100) moves along the autonomous driving route according to the driving plan (e.g., speed / direction control). During autonomous driving, the communication unit (110) can irregularly / periodically acquire the latest traffic information data from an external server and can acquire surrounding traffic information data from surrounding vehicles. In addition, during autonomous driving, the sensor unit (140c) can acquire vehicle status and surrounding environment information. The autonomous driving unit (140d) can update the autonomous driving route and driving plan based on newly acquired data / information. The communication unit (110) can transmit information regarding the vehicle location, autonomous driving route, driving plan, etc. to the external server. External servers can predict traffic information data in advance using AI technology or other technologies based on information collected from vehicles or autonomous vehicles, and provide the predicted traffic information data to the vehicles or autonomous vehicles.
[0869] Figure 50 illustrates a vehicle applicable to various embodiments of the present disclosure. The vehicle may also be implemented as a means of transportation, a train, an aircraft, a ship, or the like.
[0870] Referring to FIG. 50, the vehicle (100) may include a communication unit (110), a control unit (120), a memory unit (130), an input / output unit (140a), and a position measurement unit (140b). Here, blocks 110 to 130 / 140a to 140b correspond to blocks 110 to 130 / 140 of FIG. 47, respectively.
[0871] The communication unit (110) can transmit and receive signals (e.g., data, control signals, etc.) with other vehicles or external devices such as base stations. The control unit (120) can control components of the vehicle (100) to perform various operations. The memory unit (130) can store data / parameters / programs / codes / commands that support various functions of the vehicle (100). The input / output unit (140a) can output AR / VR objects based on information in the memory unit (130). The input / output unit (140a) can include a HUD. The position measurement unit (140b) can obtain position information of the vehicle (100). The position information can include absolute position information of the vehicle (100), position information within a driving line, acceleration information, position information with respect to surrounding vehicles, etc. The position measurement unit (140b) can include GPS and various sensors.
[0872] For example, the communication unit (110) of the vehicle (100) can receive map information, traffic information, etc. from an external server and store them in the memory unit (130). The location measurement unit (140b) can obtain vehicle location information through GPS and various sensors and store the information in the memory unit (130). The control unit (120) can create a virtual object based on the map information, traffic information, and vehicle location information, and the input / output unit (140a) can display the created virtual object on the vehicle window (1410, 1420). In addition, the control unit (120) can determine whether the vehicle (100) is being driven normally within the driving line based on the vehicle location information. If the vehicle (100) abnormally deviates from the driving line, the control unit (120) can display a warning on the vehicle window through the input / output unit (140a). Additionally, the control unit (120) can broadcast a warning message regarding driving abnormalities to surrounding vehicles via the communication unit (110). Depending on the situation, the control unit (120) can transmit vehicle location information and information regarding driving / vehicle abnormalities to relevant authorities via the communication unit (110).
[0873] Figure 51 illustrates an XR device applicable to various embodiments of the present disclosure. The XR device may be implemented as an HMD, a head-up display (HUD) installed in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, digital signage, a vehicle, a robot, and the like.
[0874] Referring to FIG. 51, the XR device (100a) may include a communication unit (110), a control unit (120), a memory unit (130), an input / output unit (140a), a sensor unit (140b), and a power supply unit (140c). Here, blocks 110 to 130 / 140a to 140c correspond to blocks 110 to 130 / 140 of FIG. 47, respectively.
[0875] The communication unit (110) can transmit and receive signals (e.g., media data, control signals, etc.) with external devices such as other wireless devices, portable devices, or media servers. The media data can include videos, images, sounds, etc. The control unit (120) can control components of the XR device (100a) to perform various operations. For example, the control unit (120) can be configured to control and / or perform procedures such as video / image acquisition, (video / image) encoding, metadata generation and processing, etc. The memory unit (130) can store data / parameters / programs / codes / commands required for driving the XR device (100a) / generating XR objects. The input / output unit (140a) can obtain control information, data, etc. from the outside, and output the generated XR objects. The input / output unit (140a) can include a camera, a microphone, a user input unit, a display unit, a speaker, and / or a haptic module, etc. The sensor unit (140b) can obtain the XR device status, surrounding environment information, user information, etc. The sensor unit (140b) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an RGB sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, and / or a radar. The power supply unit (140c) supplies power to the XR device (100a) and may include a wired / wireless charging circuit, a battery, etc.
[0876] For example, the memory unit (130) of the XR device (100a) may include information (e.g., data, etc.) required for creating an XR object (e.g., AR / VR / MR object). The input / output unit (140a) may obtain a command to operate the XR device (100a) from the user, and the control unit (120) may operate the XR device (100a) according to the user's operating command. For example, when a user attempts to watch a movie, news, etc. through the XR device (100a), the control unit (120) may transmit content request information to another device (e.g., a mobile device (100b)) or a media server through the communication unit (130). The communication unit (130) may download / stream content such as movies and news from another device (e.g., a mobile device (100b)) or a media server to the memory unit (130). The control unit (120) controls and / or performs procedures such as video / image acquisition, (video / image) encoding, and metadata generation / processing for content, and can generate / output an XR object based on information about surrounding space or real objects acquired through the input / output unit (140a) / sensor unit (140b).
[0877] In addition, the XR device (100a) is wirelessly connected to the mobile device (100b) through the communication unit (110), and the operation of the XR device (100a) can be controlled by the mobile device (100b). For example, the mobile device (100b) can act as a controller for the XR device (100a). To this end, the XR device (100a) can obtain three-dimensional position information of the mobile device (100b), and then generate and output an XR object corresponding to the mobile device (100b).
[0878] Figure 52 illustrates robots applicable to various embodiments of the present disclosure. Robots may be classified into industrial, medical, household, military, and other categories depending on their intended use or field.
[0879] Referring to FIG. 52, the robot (100) may include a communication unit (110), a control unit (120), a memory unit (130), an input / output unit (140a), a sensor unit (140b), and a driving unit (140c). Here, blocks 110 to 130 / 140a to 140c correspond to blocks 110 to 130 / 140 of FIG. 47, respectively.
[0880] The communication unit (110) can transmit and receive signals (e.g., driving information, control signals, etc.) with external devices such as other wireless devices, other robots, or control servers. The control unit (120) can control components of the robot (100) to perform various operations. The memory unit (130) can store data / parameters / programs / codes / commands that support various functions of the robot (100). The input / output unit (140a) can obtain information from the outside of the robot (100) and output information to the outside of the robot (100). The input / output unit (140a) can include a camera, a microphone, a user input unit, a display unit, a speaker, and / or a haptic module. The sensor unit (140b) can obtain internal information of the robot (100), surrounding environment information, user information, etc. The sensor unit (140b) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, a radar, etc. The driving unit (140c) may perform various physical operations such as moving the robot joints. In addition, the driving unit (140c) may enable the robot (100) to drive on the ground or fly in the air. The driving unit (140c) may include an actuator, a motor, wheels, brakes, propellers, etc.
[0881] FIG. 53 illustrates an AI device applicable to various embodiments of the present disclosure.
[0882] AI devices can be implemented as fixed or mobile devices, such as TVs, projectors, smartphones, PCs, laptops, digital broadcasting terminals, tablet PCs, wearable devices, set-top boxes (STBs), radios, washing machines, refrigerators, digital signage, robots, and vehicles.
[0883] Referring to FIG. 53, the AI device (100) may include a communication unit (110), a control unit (120), a memory unit (130), an input / output unit (140a / 140b), a learning processor unit (140c), and a sensor unit (140d). Blocks 110 to 130 / 140a to 140d correspond to blocks 110 to 130 / 140 of FIG. 47, respectively.
[0884] The communication unit (110) can transmit and receive wired and wireless signals (e.g., sensor information, user input, learning models, control signals, etc.) with external devices such as other AI devices (e.g., FIG. W1, 100x, 200, 400) or AI servers (200) using wired and wireless communication technology. To this end, the communication unit (110) can transmit information within the memory unit (130) to the external device or transfer a signal received from the external device to the memory unit (130).
[0885] The control unit (120) may determine at least one executable operation of the AI device (100) based on information determined or generated using a data analysis algorithm or a machine learning algorithm. In addition, the control unit (120) may control components of the AI device (100) to perform the determined operation. For example, the control unit (120) may request, search, receive, or utilize data from the learning processor unit (140c) or the memory unit (130), and may control components of the AI device (100) to perform at least one executable operation, a predicted operation, or an operation determined to be desirable. In addition, the control unit (120) may collect history information including the operation contents of the AI device (100) or user feedback on the operation, and store the collected history information in the memory unit (130) or the learning processor unit (140c), or transmit the collected history information to an external device such as an AI server (FIG. W1, 400). The collected history information may be used to update a learning model.
[0886] The memory unit (130) can store data that supports various functions of the AI device (100). For example, the memory unit (130) can store data obtained from the input unit (140a), data obtained from the communication unit (110), output data of the learning processor unit (140c), and data obtained from the sensing unit (140). In addition, the memory unit (130) can store control information and / or software codes necessary for the operation / execution of the control unit (120).
[0887] The input unit (140a) can obtain various types of data from the outside of the AI device (100). For example, the input unit (120) can obtain learning data for model learning, input data to which the learning model will be applied, etc. The input unit (140a) may include a camera, a microphone, and / or a user input unit. The output unit (140b) may generate output related to sight, hearing, or touch. The output unit (140b) may include a display unit, a speaker, and / or a haptic module, etc. The sensing unit (140) can obtain at least one of internal information of the AI device (100), information about the surrounding environment of the AI device (100), and user information using various sensors. The sensing unit (140) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an RGB sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, and / or a radar, etc.
[0888] The learning processor unit (140c) can train a model composed of an artificial neural network using learning data. The learning processor unit (140c) can perform AI processing together with the learning processor unit of the AI server (Figure W1, 400). The learning processor unit (140c) can process information received from an external device via the communication unit (110) and / or information stored in the memory unit (130). In addition, the output value of the learning processor unit (140c) can be transmitted to an external device via the communication unit (110) and / or stored in the memory unit (130).
[0889] The claims described in the various embodiments of the present disclosure may be combined in various ways. For example, the technical features of the method claims of the various embodiments of the present disclosure may be combined and implemented as a device, and the technical features of the device claims of the various embodiments of the present disclosure may be combined and implemented as a method. Furthermore, the technical features of the method claims of the various embodiments of the present disclosure may be combined and implemented as a device, and the technical features of the method claims of the various embodiments of the present disclosure may be combined and implemented as a method.
Claims
1. In a method performed by a first node in a communication system, A step of transmitting at least one synchronization signal to a second node; A step of transmitting a control signal (control information) to the second node; A step of receiving a request for a quantum public key (QPK) from the second node; A step of transmitting the QPK based on the private key associated with the first node to the second node; A step of receiving a message on which encryption and quantum state encapsulation based on the QPK are performed from the second node, method.
2. In paragraph 1, The above message includes a first message based on a quantum public key encrypted packet (QPKE packet) and a second message based on a public key encrypted-ephemeral key packet (PKE-EK packet). method.
3. In paragraph 1, The above message is encrypted based on the above QPK, The above message is based on an ephemeral key, and the quantum state encapsulation is performed. method.
4. In paragraph 3, A step of transmitting a CP key (classical public key) related to the first node to the second node; Further comprising the step of receiving the temporary key encrypted based on the CP key from the second node, method.
5. In paragraph 4, A step of obtaining the temporary key through decryption of the encrypted temporary key based on the CP key; Further comprising a step of obtaining information of the message through decapsulation of the message based on the temporary key, The above CP key is transmitted in advance through a specific network. method.
6. In paragraph 5, Information of the message is obtained by performing compensation of the QPK using the private key for the message for which the decapsulation has been performed. method.
7. In paragraph 5, The above message in quantum state does not collapse unless decapsulation by the temporary key is performed within a set time. method.
8. In the method of operation of the second node in the communication system, A step of receiving at least one synchronization signal from a first node; A step of receiving a control signal (control information) from the first node; A step of transmitting a request for a quantum public key (QPK) to the first node; A step of receiving the QPK based on a private key associated with the first node from the first node; A step of transmitting a message on which encryption and quantum state encapsulation based on the QPK have been performed to the first node, method.
9. In paragraph 8, The above message includes a first message based on a quantum public key encrypted packet (QPKE packet) and a second message based on a public key encrypted-ephemeral key packet (PKE-EK packet). method.
10. In paragraph 8, The above message is encrypted based on the above QPK, The above message is based on an ephemeral key, and the quantum state encapsulation is performed. method.
11. In paragraph 10, A step of receiving a CP key (classical public key) related to the first node from the first node; Further comprising the step of transmitting the temporary key encrypted based on the CP key to the first node, method.
12. In paragraph 11, The information of the above message is decoded through decapsulation of the message based on the temporary key, The above temporary key is decrypted based on the above CP key, The above CP key is received in advance through a specific network. method.
13. In paragraph 12, Information of the message is obtained by performing compensation of the QPK using the private key for the message for which the decapsulation has been performed. method.
14. In paragraph 12, The above message in quantum state does not collapse unless decapsulation by the temporary key is performed within a set time. method.
15. In the first node of the communication system, Transmitter and receiver; at least one processor; and At least one memory operably connectable to said at least one processor and storing instructions that, when executed by said at least one processor, perform operations; The above actions are, Comprising all steps of the method according to one of claims 1 to 7, Node 1.
16. In the second node of the communication system, Transmitter and receiver; at least one processor; and At least one memory operably connectable to said at least one processor and storing instructions that, when executed by said at least one processor, perform operations; The above actions are, Comprising all steps of a method according to one of claims 8 to 14, Second node.
17. In a control device that controls a first node in a communication system, at least one processor; and comprising at least one memory operably connected to at least one of the processors; The at least one memory stores instructions for performing operations based on being executed by the at least one processor, The above actions are, Comprising all steps of the method according to one of claims 1 to 7, controller.
18. In a control device that controls a second node in a communication system, at least one processor; and comprising at least one memory operably connected to at least one of the processors; The at least one memory stores instructions for performing operations based on being executed by the at least one processor, The above actions are, Comprising all steps of a method according to one of claims 8 to 14, controller.
19. In one or more non-transitory computer-readable media storing one or more instructions, The one or more instructions perform operations based on being executed by one or more processors, The above actions are, Comprising all steps of the method according to one of claims 1 to 7, Computer readable medium.
20. In one or more non-transitory computer-readable media storing one or more instructions, The one or more instructions perform operations based on being executed by one or more processors, The above actions are, Comprising all steps of a method according to one of claims 8 to 14, Computer readable medium.
Citation Information
Patent Citations
Pattern distribution apparatus for palletizer
KR102296028B1
Communication apparatus based on transport layer security protocol, shared key extension method
KR102609406B1
Device and method for detecting and correcting entanglement error with respect to arbitrary n-qubit entanglement state in quantum communication system
WO2023128603A1
Method and device for performing error correction on asymmetric pauli channel in quantum communication system
WO2023128604A1
KR20200068079A