Apparatus and method for performing data communication by using homomorphic encryption in wireless communication system

The method and device for recovering ciphertext modulus using homomorphic encryption in wireless systems address the challenges of modulus maintenance and recovery without bootstrapping, enhancing data communication efficiency in advanced communication environments.

WO2025263656A1PCT designated stage Publication Date: 2025-12-26LG ELECTRONICS INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/008518
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-20
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing wireless communication systems face challenges in effectively utilizing homomorphic encryption techniques, particularly in maintaining and recovering the modulus of ciphertext without bootstrapping operations, which hinders efficient data communication in environments demanding enhanced mobile broadband and massive machine type communications.

Method used

A method and device for recovering the modulus of a ciphertext using homomorphic encryption in a wireless communication system, involving a switching key and a public key of a third device, enabling ciphertext transformation and recovery without bootstrapping operations.

Benefits of technology

Enhances the effectiveness of homomorphic encryption in wireless communication systems, facilitating efficient data transmission and communication in environments requiring enhanced mobile broadband and massive machine type communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024008518_26122025_PF_FP_ABST
    Figure KR2024008518_26122025_PF_FP_ABST
Patent Text Reader

Abstract

The objective of the present disclosure is to perform data communication by using homomorphic encryption in a wireless communication system. This method performed by a first device may comprise the steps of: performing an initial access procedure; transmitting capability information; performing signaling for a configuration related to a service; and, on the basis of the service, transmitting, to a second device, a ciphertext encrypted using homomorphic encryption and a switching key for key switching of the ciphertext.
Need to check novelty before this filing date? Find Prior Art

Description

Device and method for performing data communication using homomorphic encryption in a wireless communication system

[0001] The present disclosure relates to a wireless communication system, and to a device and method for performing data communication using homomorphic encryption in a wireless communication system.

[0002] Wireless access systems are widely deployed to provide various types of communication services, such as voice and data. Typically, wireless access systems are multiple access systems that support communications with multiple users by sharing available system resources (e.g., bandwidth, transmission power). Examples of multiple access systems include code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), orthogonal frequency division multiple access (OFDMA), and single-carrier frequency division multiple access (SC-FDMA).

[0003] In particular, as numerous communication devices demand greater communication capacity, enhanced mobile broadband (eMBB) communication technologies are being proposed, improving upon existing radio access technology (RAT). Furthermore, massive machine type communications (mMTC), which connects multiple devices and objects to provide diverse services anytime and anywhere, as well as communication systems that consider reliability and latency-sensitive services / user equipment (UE), are being proposed. Various technological configurations are being proposed for these solutions.

[0004] The present disclosure relates to a device and method for effectively utilizing a homomorphic encryption technique in a wireless communication system.

[0005] The present disclosure relates to a device and method for maintaining the size of a modulus of a ciphertext based on homomorphic encryption in a wireless communication system.

[0006] The present disclosure relates to a device and method for recovering the modulus of a ciphertext based on homomorphic encryption in a wireless communication system.

[0007] The present disclosure relates to a device and method for recovering the modulus of a ciphertext based on homomorphic encryption in a wireless communication system without a bootstrapping operation.

[0008] The present disclosure relates to a device and method for recovering the modulus of a ciphertext based on homomorphic encryption using re-encryption in a wireless communication system.

[0009] The present disclosure relates to a device and method for recovering the modulus of a ciphertext based on homomorphic encryption based on the intervention of a third device in a wireless communication system.

[0010] The present disclosure relates to a device and method for recovering the modulus of a ciphertext using a switching key and a public key of a third device in a wireless communication system.

[0011] The present disclosure relates to a device and method for sharing information for recovering a modulus of a ciphertext in a wireless communication system.

[0012] The present disclosure relates to a device and method for transforming a ciphertext for recovery of a modulus in a wireless communication system.

[0013] The present disclosure relates to a device and method for providing a ciphertext to a third device for recovery of a modulus in a wireless communication system.

[0014] The technical objectives to be achieved in the present disclosure are not limited to those mentioned above, and other technical tasks not mentioned can be considered by a person having ordinary skill in the technical field to which the technical configuration of the present disclosure is applied from the embodiments of the present disclosure described below.

[0015] As an example of the present disclosure, a method performed by a first device in a wireless communication system may include the steps of performing an initial connection procedure, transmitting capability information, performing signaling for service-related settings, and transmitting to a second device an encrypted ciphertext using homomorphic encryption based on the service and a switching key for key switching of the ciphertext. The switching key may be used to recover a modulus as a key for converting a ciphertext encrypted with a first public key of the first device into a ciphertext encrypted with a second public key of a third device.

[0016] As an example of the present disclosure, in a wireless communication system, a first device includes a transceiver and a processor coupled to the transceiver, wherein the processor is configured to perform an initial connection procedure, transmit capability information, perform signaling for service-related settings, and transmit to a second device an encrypted ciphertext using homomorphic encryption based on the service and a switching key for key switching of the ciphertext. The switching key may be used to recover a modulus as a key for converting a ciphertext encrypted with a first public key of the first device into a ciphertext encrypted with a second public key of a third device.

[0017] As an example of the present disclosure, a communication device includes at least one processor, and at least one computer memory coupled to the at least one processor and storing instructions that, when executed by the at least one processor, direct operations, wherein the operations may include performing an initial connection procedure, transmitting capability information, performing signaling for setting up a service, and transmitting a ciphertext encrypted using homomorphic encryption based on the service and a switching key for key switching of the ciphertext. The switching key may be used to recover a modulus as a key for converting a ciphertext encrypted with a first public key of the first device into a ciphertext encrypted with a second public key.

[0018] As an example of the present disclosure, a non-transitory computer-readable medium storing at least one instruction includes at least one instruction executable by a processor, wherein the at least one instruction can instruct a device to perform an initial connection procedure, transmit capability information, perform signaling for setting up a service, and transmit ciphertext encrypted using homomorphic encryption based on the service and a switching key for key switching of the ciphertext. The switching key can be used to recover a modulus as a key for converting ciphertext encrypted with a first public key of the first device into ciphertext encrypted with a second public key.

[0019] The above-described aspects of the present disclosure are only some of the preferred embodiments of the present disclosure, and various embodiments reflecting the technical features of the present disclosure can be derived and understood by a person having ordinary skill in the art based on the detailed description of the present disclosure to be described below.

[0020] The following effects may be achieved by embodiments based on the present disclosure.

[0021] According to the present disclosure, homomorphic encryption techniques can be utilized more effectively in a communication environment.

[0022] The effects that can be obtained from the embodiments of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned can be clearly derived and understood by those skilled in the art to which the technical configuration of the present disclosure is applied, from the description of the embodiments of the present disclosure below. In other words, unintended effects resulting from implementing the configuration described in the present disclosure can also be derived from the embodiments of the present disclosure by those skilled in the art.

[0023] The accompanying drawings are intended to aid understanding of the present disclosure and, together with detailed descriptions, may provide embodiments of the present disclosure. However, the technical features of the present disclosure are not limited to specific drawings, and the features disclosed in each drawing may be combined with each other to form new embodiments. Reference numerals in each drawing may indicate structural elements.

[0024] Figure 1 illustrates an example of a communication system applicable to the present disclosure.

[0025] FIG. 2 illustrates an example of a wireless device applicable to the present disclosure.

[0026] FIG. 3 illustrates a method for processing a transmission signal applicable to the present disclosure.

[0027] Figure 4 illustrates a communication procedure between a terminal and a base station applicable to the present disclosure.

[0028] FIG. 5 illustrates an example of a communication structure that can be provided in a 6G (6th generation) system applicable to the present disclosure.

[0029] Figure 6 illustrates an electromagnetic spectrum applicable to the present disclosure.

[0030] Figure 7 illustrates a transmitter structure applicable to the present disclosure.

[0031] Figure 8 illustrates an example of a functional framework for application of artificial intelligence technology applicable to the present disclosure.

[0032] Figure 9 illustrates an example of a procedure for utilizing an artificial intelligence model applicable to the present disclosure.

[0033] Figure 10 illustrates a communication procedure based on AI (artificial intelligence) technology applicable to the present disclosure.

[0034] Figure 11 illustrates the framework of CKKS.

[0035] Figure 12 illustrates an example of rescaling for a ciphertext based on homomorphic encryption.

[0036] Figure 13 illustrates an example of a bootstrapping operation for a ciphertext based on homomorphic encryption.

[0037] Figure 14 shows an example of data changes due to bootstrapping.

[0038] Figure 15 illustrates an example of a ciphertext initialization operation using a communication environment.

[0039] FIG. 16 illustrates an example of a procedure for performing communication of a device according to one embodiment of the present disclosure.

[0040] FIG. 17 illustrates an example of a procedure for performing a homomorphic operation including recovery of a modulus according to one embodiment of the present disclosure.

[0041] FIGS. 18A to 18C illustrate specific examples of homomorphic operations including recovery of modulus according to one embodiment of the present disclosure.

[0042] FIG. 19 illustrates an example of a wireless device applicable to the present disclosure.

[0043] Figure 20 illustrates an example of a portable device applicable to the present disclosure.

[0044] FIG. 21 illustrates an example of a vehicle or autonomous vehicle applicable to the present disclosure.

[0045] Figure 22 illustrates an example of a vehicle applicable to the present disclosure.

[0046] FIG. 23 illustrates an example of an extended reality (XR) device applicable to the present disclosure.

[0047] Figure 24 illustrates an example of a robot applicable to the present disclosure.

[0048] Figure 25 illustrates an example of an AI device applicable to the present disclosure.

[0049] The following embodiments combine the components and features of the present disclosure in a predetermined form. Each component or feature may be considered optional unless explicitly stated otherwise. Each component or feature may be implemented without being combined with other components or features. Furthermore, some components and / or features may be combined to form embodiments of the present disclosure. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment or may be replaced with corresponding components or features of another embodiment.

[0050] In the description of the drawings, procedures or steps that may obscure the gist of the present disclosure are not described, and procedures or steps that can be understood by a person skilled in the art are also not described.

[0051] Throughout the specification, when a part is said to "comprising" or "including" a component, this does not mean that other components may be included, but rather that other components may be excluded, unless otherwise specifically stated. In addition, terms such as "...part," "...unit," and "module" described in the specification mean a unit that processes at least one function or operation, which may be implemented by hardware, software, or a combination of hardware and software. In addition, the words "a" or "an," "one," "the," and similar related words may be used in the context of describing the present disclosure (especially in the context of the claims below) to include both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context.

[0052] Embodiments of the present disclosure described herein focus on the data transmission and reception relationship between a base station and a mobile station. Here, the base station is understood as a terminal node of a network that directly communicates with the mobile station. Certain operations described herein as being performed by the base station may, in some cases, be performed by an upper node of the base station.

[0053] That is, in a network consisting of multiple network nodes including a base station, various operations performed for communication with a mobile station may be performed by the base station or other network nodes other than the base station. In this case, the term 'base station' may be replaced by terms such as fixed station, Node B, eNB (eNode B), gNB (gNode B), ng-eNB, advanced base station (ABS), or access point.

[0054] Additionally, in the embodiments of the present disclosure, the term terminal may be replaced with terms such as user equipment (UE), mobile station (MS), subscriber station (SS), mobile subscriber station (MSS), mobile terminal, or advanced mobile station (AMS).

[0055] Additionally, a transmitter refers to a fixed and / or mobile node that provides data or voice services, and a receiver refers to a fixed and / or mobile node that receives data or voice services. Therefore, for uplink, a mobile station can be the transmitter, and a base station can be the receiver. Similarly, for downlink, a mobile station can be the receiver, and a base station can be the transmitter.

[0056] Embodiments of the present disclosure may be supported by standard documents disclosed in at least one of wireless access systems, such as IEEE 802.xx system, 3rd Generation Partnership Project (3GPP) system, 3GPP Long Term Evolution (LTE) system, 3GPP 5th generation (5G) NR (New Radio) system and 3GPP2 system, and in particular, embodiments of the present disclosure may be supported by 3GPP TS (technical specification) 38.211, 3GPP TS 38.212, 3GPP TS 38.213, 3GPP TS 38.321 and 3GPP TS 38.331 documents.

[0057] Furthermore, the embodiments of the present disclosure can be applied to other wireless access systems and are not limited to the systems described above. For example, they can be applied to systems implemented after the 3GPP 5G NR system and are not limited to a specific system.

[0058] That is, obvious steps or parts not described in the embodiments of the present disclosure can be explained by referring to the above documents. In addition, all terms disclosed in this document can be explained by the above standard documents.

[0059] Hereinafter, preferred embodiments according to the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description set forth below, together with the accompanying drawings, is intended to illustrate exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the technical configurations of the present disclosure may be implemented.

[0060] Additionally, specific terms used in the embodiments of the present disclosure are provided to aid in understanding of the present disclosure, and the use of such specific terms may be changed to other forms without departing from the technical spirit of the present disclosure.

[0061] The following technology can be applied to various wireless access systems such as CDMA (code division multiple access), FDMA (frequency division multiple access), TDMA (time division multiple access), OFDMA (orthogonal frequency division multiple access), and SC-FDMA (single carrier frequency division multiple access).

[0062]

[0063] For clarity, the following description is based on 3GPP communication systems (e.g., LTE, NR, etc.), but the technical spirit of the present disclosure is not limited thereto. LTE may refer to technology after 3GPP TS 36.xxx Release 8. Specifically, LTE technology after 3GPP TS 36.xxx Release 10 may be referred to as LTE-A, and LTE technology after 3GPP TS 36.xxx Release 13 may be referred to as LTE-A pro. 3GPP NR may refer to technology after TS 38.xxx Release 15. 3GPP 6G may refer to technology after TS Release 17 and / or Release 18. "xxx" refers to a standard document detail number. LTE / NR / 6G may be collectively referred to as a 3GPP system.

[0064] For background information, terms, abbreviations, etc. used in this disclosure, reference may be made to standard documents published prior to this disclosure. For example, reference may be made to standard documents 36.xxx and 38.xxx.

[0065]

[0066] Communication system applicable to the present disclosure

[0067] Although not limited thereto, the various descriptions, functions, procedures, proposals, methods and / or operational flowcharts of the present disclosure disclosed in this document may be applied to various fields requiring wireless communication / connectivity (e.g., 5G) between devices.

[0068] Hereinafter, more specific examples will be provided with reference to the drawings. In the drawings / descriptions below, the same drawing reference numerals may represent identical or corresponding hardware blocks, software blocks, or functional blocks, unless otherwise described.

[0069] Figure 1 illustrates an example of a communication system applied to the present disclosure.

[0070] Referring to FIG. 1, a communication system (100) applied to the present disclosure includes a wireless device, a base station, and a network. Here, the wireless device refers to a device that performs communication using a wireless access technology (e.g., LTE, LTE-A, LTE-A pro, NR, 5G, 5G-A, 6G) and may be referred to as a communication / wireless / 5G device. Although not limited thereto, the wireless device may include a robot (100a), a vehicle (100b-1, 100b-2), an XR (extended reality) device (100c), a hand-held device (100d), a home appliance (100e), an IoT (Internet of Things) device (100f), and an AI (artificial intelligence) device / server (100g). For example, the vehicle may include a vehicle equipped with a wireless communication function, an autonomous vehicle, a vehicle capable of performing vehicle-to-vehicle communication, etc. Here, the vehicles (100b-1, 100b-2) may include unmanned aerial vehicles (UAVs) (e.g., drones). The XR devices (100c) include augmented reality (AR) / virtual reality (VR) / mixed reality (MR) devices, and may be implemented in the form of head-mounted devices (HMDs), head-up displays (HUDs) installed in vehicles, televisions, smartphones, computers, wearable devices, home appliances, digital signage, vehicles, robots, etc. The portable devices (100d) may include smartphones, smart pads, wearable devices (e.g., smartwatches, smart glasses), computers (e.g., laptops, etc.), etc. The home appliances (100e) may include TVs, refrigerators, washing machines, etc. The IoT devices (100f) may include sensors, smart meters, etc.For example, the base station (120) and the network (130) may also be implemented as wireless devices, and a specific wireless device (120a) may act as a base station / network node to other wireless devices.

[0071] Wireless devices (100a to 100f) can be connected to a network (130) via a base station (120). AI technology can be applied to the wireless devices (100a to 100f), and the wireless devices (100a to 100f) can be connected to an AI server (100g) via a network (130). The network (130) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR), or a 6G network. The wireless devices (100a to 100f) can communicate with each other via the base station (120) / network (130), but can also communicate directly (e.g., sidelink communication) without going through the base station (120) / network (130). For example, vehicles (100b-1, 100b-2) can communicate directly (e.g., V2V (vehicle to vehicle) / V2X (vehicle to everything) communication). Additionally, an IoT device (100f) (e.g., a sensor) can communicate directly with another IoT device (e.g., a sensor) or another wireless device (100a to 100f).

[0072] Wireless communication / connection (150a, 150b, 150c) can be established between wireless devices (100a to 100f) / base stations (120), and base stations (120) / base stations (120). Here, the wireless communication / connection can be established through various wireless access technologies such as uplink / downlink communication (150a), sidelink communication (150b) (or D2D communication), and base station-to-base station communication (150c) (e.g., relay, IAB (integrated access backhaul)). Through the wireless communication / connection (150a, 150b, 150c), the wireless device and base station / wireless device, and base stations and base stations can transmit / receive wireless signals to / from each other. For example, the wireless communication / connection (150a, 150b, 150c) can transmit / receive signals through various physical channels. To this end, based on various proposals of the present disclosure, at least some of various configuration information setting processes for transmitting / receiving wireless signals, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), resource allocation processes, etc. may be performed.

[0073]

[0074] Devices applicable to the present disclosure

[0075] FIG. 2 illustrates an example of a wireless device applicable to the present disclosure.

[0076] Referring to FIG. 2, the wireless device (200) can transmit and receive wireless signals via various wireless access technologies (e.g., LTE, LTE-A, LTE-A pro, NR, 5G, 5G-A, 6G). The wireless device (200) includes at least one processor (202) and at least one memory (204), and may additionally include at least one transceiver (206) and / or at least one antenna (208).

[0077] The processor (202) controls the memory (204) and / or the transceiver (206), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this document. For example, the processor (202) may process information in the memory (204) to generate first information / signal, and then transmit a wireless signal including the first information / signal via the transceiver (206). In addition, the processor (202) may receive a wireless signal including second information / signal via the transceiver (206), and then store information obtained from signal processing of the second information / signal in the memory (204). The memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, the memory (204) may store software code including instructions for performing some or all of the processes controlled by the processor (202), or for performing the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein. Here, the processor (202) and the memory (204) may be part of a communication modem / circuit / chip designed to implement wireless communication technology. The transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals via at least one antenna (208). The transceiver (206) may include a transmitter and / or a receiver. The transceiver (206) may be used interchangeably with an RF (radio frequency) unit. In the present disclosure, a wireless device may also mean a communication modem / circuit / chip.

[0078] Hereinafter, the hardware elements of the wireless device (200) will be described in more detail. Although not limited thereto, at least one protocol layer may be implemented by at least one processor (202). For example, at least one processor (202) may implement at least one layer (e.g., a functional layer such as physical (PHY), media access control (MAC), radio link control (RLC), packet data convergence protocol (PDCP), radio resource control (RRC), and service data adaptation protocol (SDAP)). At least one processor (202) may generate at least one Protocol Data Unit (PDU) and / or at least one Service Data Unit (SDU) according to the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. At least one processor (202) may generate a message, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. At least one processor (202) can generate a signal (e.g., a baseband signal) including a PDU, an SDU, a message, control information, data or information according to the functions, procedures, proposals and / or methods disclosed in this document, and provide the signal to at least one transceiver (206). At least one processor (202) can receive a signal (e.g., a baseband signal) from at least one transceiver (206) and obtain the PDU, SDU, message, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed in this document.

[0079] At least one processor (202) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer. The at least one processor (202) may be implemented by hardware, firmware, software, or a combination thereof. For example, at least one application specific integrated circuit (ASIC), at least one digital signal processor (DSP), at least one digital signal processing device (DSPD), at least one programmable logic device (PLD), or at least one field programmable gate array (FPGA) may be included in the at least one processor (202). The descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. The descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document may be included in the at least one processor (202), or may be stored in at least one memory (204) and driven by the at least one processor (202). The descriptions, functions, procedures, suggestions, methods and / or flowcharts disclosed in this document may be implemented using firmware or software in the form of code, instructions and / or sets of instructions.

[0080] At least one memory (204) can be connected to at least one processor (202) and can store various forms of data, signals, messages, information, programs, codes, instructions and / or commands. The at least one memory (204) can be configured as a read only memory (ROM), a random access memory (RAM), an erasable programmable read only memory (EPROM), a flash memory, a hard drive, a register, a cache memory, a computer readable storage medium and / or a combination thereof. The at least one memory (204) can be located internally and / or externally to the at least one processor (202). In addition, the at least one memory (204) can be connected to the at least one processor (202) via various technologies such as a wired or wireless connection.

[0081] At least one transceiver (206) can transmit user data, control information, wireless signals / channels, etc., mentioned in the methods and / or flowcharts of this document to at least one other device. At least one transceiver (206) can receive user data, control information, wireless signals / channels, etc. mentioned in the descriptions, functions, procedures, proposals, methods and / or flowcharts disclosed in this document from at least one other device. For example, at least one transceiver (206) can be connected to at least one processor (202) and can transmit and receive wireless signals. For example, at least one processor (202) can control at least one transceiver (206) to transmit user data, control information, or wireless signals to at least one other device. Furthermore, at least one processor (202) can control at least one transceiver (206) to receive user data, control information, or wireless signals from at least one other device. In addition, at least one transceiver (206) may be connected to at least one antenna (208), and at least one transceiver (206) may be configured to transmit and receive user data, control information, wireless signals / channels, etc. mentioned in the descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed in this document through at least one antenna (208). In this document, at least one antenna may be a plurality of physical antennas or a plurality of logical antennas (e.g., antenna ports). At least one transceiver (206) may convert the received wireless signals / channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc. using at least one processor (202). At least one transceiver (206) may convert the processed user data, control information, wireless signals / channels, etc. from baseband signals to RF band signals using at least one processor (202).For this purpose, at least one transceiver (206) may include an (analog) oscillator and / or filter.

[0082] The components of the wireless device described with reference to FIG. 2 may be referred to by different terms in terms of functionality. For example, the processor (202) may be referred to as a control unit, the transceiver (206) as a communication unit, and the memory (204) as a storage unit. In some cases, the communication unit may be used to mean at least a portion of the processor (202) and the transceiver (206).

[0083] The structure of the wireless device described with reference to FIG. 2 can be understood as the structure of at least a portion of various devices. For example, the structure of the wireless device illustrated in FIG. 2 can be at least a portion of various devices described with reference to FIG. 1 (e.g., a robot (100a), a vehicle (100b-1, 100b-2), an XR device (100c), a portable device (100d), a home appliance (100e), an IoT device (100f), an AI device / server (100g)). Furthermore, according to various embodiments, in addition to the components illustrated in FIG. 2, the device may further include other components.

[0084] For example, the device may be a portable device such as a smartphone, a smart pad, a wearable device (e.g., a smart watch, smart glasses), or a portable computer (e.g., a laptop, etc.). In this case, the device may further include at least one of a power supply unit that supplies power and includes a wired / wireless charging circuit, a battery, etc., an interface unit that includes at least one port for connection with another device (e.g., an audio input / output port, a video input / output port), and an input / output unit for inputting and outputting image information / signals, audio information / signals, data, and / or information input from a user.

[0085] For example, the device may be a mobile device such as a mobile robot, a vehicle, a train, an aerial vehicle (AV), a ship, etc. In this case, the device may further include at least one of a driving unit including at least one of an engine, a motor, a power train, wheels, brakes, and a steering unit of the device, a power supply unit including a wired / wireless charging circuit, a battery, etc. that supplies power, a sensor unit that senses status information, environmental information, and user information of the device or its surroundings, an autonomous driving unit that performs functions such as path maintenance, speed control, and destination setting, and a position measurement unit that obtains location information of the mobile device through a global positioning system (GPS) and various sensors.

[0086] For example, the device may be an XR device such as an HMD, a head-up display (HUD) installed in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, a digital signage, a vehicle, a robot, etc. In this case, the device may further include at least one of a power supply unit that supplies power and includes a wired / wireless charging circuit, a battery, etc., an input / output unit that obtains control information, data, etc. from the outside and outputs the generated XR object, and a sensor unit that senses status information, environmental information, and user information of the device or the surroundings of the device.

[0087] For example, the device may be a robot that can be classified into industrial, medical, household, military, etc. types depending on the purpose or field of use. In this case, the device may further include at least one of a sensor unit that senses status information, environmental information, and user information of the device or its surroundings, and a driving unit that performs various physical actions, such as moving the robot joints.

[0088] For example, the device may be an AI device such as a TV, a projector, a smartphone, a PC, a laptop, a digital broadcasting terminal, a tablet PC, a wearable device, a set-top box (STB), a radio, a washing machine, a refrigerator, digital signage, a robot, a vehicle, etc. In this case, the device may further include at least one of an input unit that acquires various types of data from the outside, an output unit that generates output related to sight, hearing, or touch, a sensor unit that senses status information, environmental information, and user information of the device or its surroundings, and a training unit that trains a model composed of an artificial neural network using learning data.

[0089] The structure of the wireless device illustrated in FIG. 2 may be understood as a part of a RAN node (e.g., a base station, DU, RU, RRH, etc.). That is, the device illustrated in FIG. 2 may be a RAN node. In this case, the device may further include a wired transceiver for front haul and / or back haul communications. However, if the front haul and / or back haul communications are based on wireless communications, at least one transceiver (206) illustrated in FIG. 2 may be used for front haul and / or back haul communications, and a wired transceiver may not be included.

[0090]

[0091] FIG. 3 illustrates a method for processing a transmission signal applicable to the present disclosure. For example, the transmission signal may be processed by a signal processing circuit. At this time, the signal processing circuit (300) may include scramblers (310), modulators (320), a layer mapper (330), a precoder (340), resource mappers (350), and signal generators (360). At this time, for example, the operation / function of FIG. 3 may be performed in the processor (202) and / or the transceiver (206) of FIG. 2. Furthermore, for example, the hardware elements of FIG. 3 may be implemented in the processor (202) and / or the transceiver (206) of FIG. 2. For example, blocks 310 to 360 may be implemented in the processor (202) of FIG. 2. Additionally, blocks 310 to 350 may be implemented in the processor (202) of FIG. 2, and block 360 may be implemented in the transceiver (206) of FIG. 2, and are not limited to the above-described embodiment.

[0092] The codeword can be converted into a wireless signal through the signal processing circuit (300) of FIG. 3. Here, the codeword is an encoded bit sequence of an information block. The information block may include a transport block (e.g., a UL-SCH transport block, a DL-SCH transport block). Here, the information block may include data related to AI (e.g., training data, AI model data, input data, output data, etc.), and the codeword may be an encoded bit sequence corresponding to the data related to AI. The wireless signal may be transmitted through various physical channels (e.g., a PUSCH, a PDSCH). Specifically, the codeword may be converted into a bit sequence scrambled by scramblers (310). The scramble sequence used for scrambling is generated based on an initialization value, and the initialization value may include ID information of the wireless device, etc. The scrambled bit sequence may be modulated into a modulation symbol sequence by modulators (320). Modulation schemes may include pi / 2-BPSK (pi / 2-binary phase shift keying), m-PSK (m-phase shift keying), m-QAM (m-quadrature amplitude modulation), etc.

[0093] A complex modulation symbol sequence can be mapped to at least one transport layer by a layer mapper (330). Here, a transport layer is a logical resource unit for mapping a signal or data transmitted through spatial resources to antenna ports, and one transport layer can correspond to one stream or one antenna port. Each of the complex modulation symbols included in the complex modulation symbol sequence is mapped to at least one transport layer, thereby determining which antenna port it will be transmitted through. The modulation symbols of each transport layer can be mapped to the corresponding antenna port(s) by a precoder (340). The output z of the precoder (340) can be obtained by multiplying the output y of the layer mapper (330) by a precoding matrix W of NХM. Here, N is the number of antenna ports, and M is the number of transport layers. Here, the precoder (340) may perform precoding after performing transform precoding (e.g., discrete Fourier transform (DFT) transform) on complex modulation symbols. Additionally, the precoder (340) may perform precoding without performing transform precoding.

[0094] Resource mappers (350) can map modulation symbols of each antenna port to time-frequency resources. The time-frequency resources may include a plurality of symbols (e.g., CP-OFDMA symbols, DFT-s-OFDMA symbols) in the time domain and a plurality of subcarriers in the frequency domain. Signal generators (360) generate wireless signals from the mapped modulation symbols, and the generated wireless signals can be transmitted to other devices through each antenna. To this end, each of the signal generators (360) may include an inverse fast Fourier transform (IFFT) module, a cyclic prefix (CP) inserter, a digital-to-analog converter (DAC), a frequency uplink converter, etc.

[0095] The signal processing process for a received signal in a wireless device may be configured in reverse order of the signal processing process (310 to 360) of FIG. 3. For example, a wireless device (e.g., 200 of FIG. 2) may receive a wireless signal from the outside through an antenna port / transceiver. The received wireless signal may be converted into a baseband signal through a signal restorer. For this purpose, the signal restorer may include a frequency downlink converter, an analog-to-digital converter (ADC), a CP remover, and a fast Fourier transform (FFT) module. Thereafter, the baseband signal may be restored to a codeword through a resource demapper process, a postcoding process, a demodulation process, and a descrambling process. The codeword may be restored to the original information block through decoding. Therefore, a signal processing circuit (not shown) for a received signal may include a signal restorer, a resource demapper, a postcoder, a demodulator, a descrambler, and a decoder.

[0096] The signal processing circuit (300) described with reference to FIG. 3 is exemplified as including a plurality of scramblers (310), modulators (320), a plurality of resource mappers (350), and a plurality of signal generators (360). However, at least one of the scramblers, modulators, resource mappers, and signal generators may be implemented as a single integrated structure. That is, the number of at least one of the scramblers, modulators, resource mappers, and signal generators may be smaller than the number of layers. Furthermore, at least one of the components exemplified in FIG. 3 may be omitted.

[0097]

[0098] Figure 4 illustrates a communication procedure between a terminal and a base station applicable to the present disclosure. Figure 4 illustrates operations of a terminal (410) and a base station (420) transmitting and / or receiving data and operations performed prior thereto.

[0099] Referring to FIG. 4, in step 401, the terminal (410) and the base station (420) perform synchronization. For example, the terminal (410) performs an initial cell search operation. Specifically, the terminal (410) can detect at least one synchronization signal transmitted from the base station (420) according to a predefined rule. Here, the synchronization signal can include multiple synchronization signals classified according to structure or purpose (e.g., primary synchronization signal, secondary synchronization signal). Through this, the terminal (410) can check the boundary of the frame, subframe, slot, and / or symbol of the base station (420) and obtain information about the base station (420) (e.g., cell identifier).

[0100] In step 403, the terminal (410) obtains system information transmitted from the base station (420). The system information is information related to the properties, characteristics, and / or capabilities of the base station (420) required to access the base station (420) and use the service, and may be classified by content (e.g., whether it is essential for access), transmission structure (e.g., channel used, whether provided on-demand), etc., and may be classified into, for example, a master information block (MIB) and a system information block (SIB). If necessary, the terminal (410) may transmit a signal requesting system information before receiving the system information. The system information may include information related to an AI function. For example, the system information may include at least one of information related to an AI model, information related to training, and information related to inference / prediction, as information required for operations performed based on AI. However, the request and provision of the system information may be performed after a random access procedure described below.

[0101] In step 405, the terminal (410) and the base station (420) perform a random access procedure. The terminal (410) may transmit and / or receive at least one message (e.g., a random access preamble, a random access response (RAR) message, etc.) for the random access procedure based on information related to the random access channel of the base station (420) obtained through system information (e.g., channel position, channel structure, supported preamble structure, etc.). For example, the terminal (410) may transmit a preamble (e.g., MSG1) through the random access channel, receive an RAR message (e.g., MSG2), transmit a message (e.g., MSG3) including information related to the terminal (410) (e.g., identification information) to the base station (420) using scheduling information included in the RAR message, and receive a message (e.g., MSG4) for contention resolution and / or connection establishment. As another example, MSG1 and MSG3 may be sent and received as one message, or MSG2 and MSG4 may be sent and received as one message.

[0102] In step 407, the terminal (410) and the base station (420) perform signaling of control information. Here, the control information may be defined in various layers, such as a layer that controls a connection (e.g., a radio resource control (RRC) layer), a layer that handles mapping between logical channels and transport channels (e.g., a media access control (MAC) layer), and a layer that handles physical channels (e.g., a physical (PHY) layer). For example, the terminal (410) and the base station (420) may perform at least one of signaling for establishing a connection, signaling for determining settings related to communication, and signaling for indicating allocated resources. In addition, the signaling of the control information may be performed to convey information related to an AI function. For example, the information related to an AI function is information necessary for an operation performed based on AI, and may include at least one of information related to an AI model, information related to training, and information related to inference / prediction. More specifically, information related to the AI ​​function signaled in step 407 may be combined and / or combined with information related to the AI ​​function signaled in step 403, and the two may be defined in a hierarchical, mutually complementary, or substitutive structure.

[0103] In step 409, the terminal (410) and the base station (420) transmit and / or receive data. In other words, the terminal (410) and the base station (420) can process, transmit, and / or receive data based on the signaling of the control information. For example, when transmitting data, the terminal (410) or the base station (420) can perform at least one of channel encoding, rate matching, scrambling, constellation mapping, layer mapping, waveform modulation, antenna mapping, and resource mapping on the information bits. Conversely, when receiving data, the terminal (410) or the base station (420) can perform at least one of signal extraction from resources, waveform demodulation for each antenna, signal arrangement considering layer mapping, constellation demapping, descrambling, and channel decoding. Here, the transmitted data is data related to AI, and may include, for example, data for AI-based operations or data generated by AI-based operations.

[0104] Steps 401 to 409 illustrated with reference to FIG. 4 do not necessarily have to be performed in the order illustrated in FIG. 4, and the order of at least some of the steps may vary. Furthermore, at least some of steps 401 to 409 may be combined into a single step or omitted. That is, the steps illustrated in FIG. 4 may be performed in various modified forms.

[0105]

[0106] 6G communication systems and core implementation technologies of 6G systems

[0107] The 5G system defines various operating bands within FR1 (frequency range 1), which covers 410 MHz to 7125 MHz, and FR2 (frequency range 2), which covers 24,250 MHz to 71,000 MHz. Various frequencies are being discussed as operating bands for the subsequent 6G system, and the use of higher frequencies than 5G systems is also being considered for wider bandwidth and higher transmission speeds. One such band is the THz (terahertz) frequency band, which covers approximately 100 GHz to 10 THz. The THz frequency band is a band that has both the transparency of radio waves and the straightness of light waves, and communications using the THz frequency band are expected to play a transitional role from existing radio-centered communications to lightwave-based communications.

[0108] 6G systems utilizing the THz frequency band are aimed at *?*very high data rates per device, *?*a very large number of connected devices, *?*global connectivity, *?*very low latency, *?*lower energy consumption of battery-free IoT devices, *?*ultra-reliable connectivity, and *?*connected intelligence with machine learning capabilities. The vision of the 6G system can be divided into four aspects: "intelligent connectivity," "deep connectivity," "holographic connectivity," and "ubiquitous connectivity," and the 6G system can be designed to satisfy the requirements as shown in [Table 1] below.

[0109] Per device peak data rate1 TbpsE2E latency1 msMaximum spectral efficiency100 bps / HzMobility supportup to 1000 km / hrSatellite integrationFullyAIFullyAutonomous vehicleFullyXRFullyHaptic CommunicationFully

[0110] At this time, the 6G system may have key factors such as enhanced mobile broadband (eMBB), ultra-reliable low latency communications (URLLC), massive machine type communications (mMTC), AI integrated communication, tactile internet, high throughput, high network capacity, high energy efficiency, low backhaul and access network congestion, and enhanced data security. FIG. 5 illustrates an example of a communication structure that can be provided in a 6G system applicable to the present disclosure. Referring to FIG. 5, the 6G system is expected to have simultaneous wireless communication connectivity that is 50 times higher than that of a 5G wireless communication system. URLLC, a key feature of 5G, is expected to become an even more crucial technology in 6G communications, offering end-to-end latency of less than 1 ms. Furthermore, 6G systems will boast significantly higher volumetric spectral efficiency than the commonly used area spectral efficiency. 6G systems can offer extremely long battery life and advanced battery technologies for energy harvesting, eliminating the need for separate charging for mobile devices in 6G systems. New network characteristics in 6G may include:

[0111] - Satellite integrated network: 6G is expected to integrate with satellites to provide a global mobile network. The integration of terrestrial, satellite, and airborne networks into a single wireless communications system is crucial for 6G.

[0112] Connected Intelligence: Unlike previous generations of wireless communication systems, 6G is revolutionary, upgrading the wireless evolution from "connected objects" to "connected intelligence." AI can be applied at every stage of the communication process (or at every signal processing step, as described below).

[0113] - Seamless integration of wireless information and energy transfer: 6G wireless networks will transfer power to charge the batteries of devices such as smartphones and sensors. Therefore, wireless information and energy transfer (WIET) will be integrated.

[0114] - Ubiquitous super 3D connectivity: Access to networks and core network functions of drones and very low Earth orbit satellites will create super 3D connectivity in 6G ubiquitous.

[0115] Some general requirements for the new network characteristics of 6G, such as the above, may be as follows:

[0116] - Small cell networks: The concept of small cell networks was introduced to improve received signal quality in cellular systems by increasing throughput, energy efficiency, and spectral efficiency. Consequently, small cell networks are essential for 5G and beyond-5G (5GB) communication systems. Accordingly, 6G communication systems also adopt the characteristics of small cell networks.

[0117] Ultra-dense heterogeneous networks: Ultra-dense heterogeneous networks will be another key feature of 6G communication systems. Multi-tier networks comprised of heterogeneous networks improve overall QoS and reduce costs.

[0118] High-capacity backhaul: Backhaul connections are characterized by high-capacity backhaul networks to support high-volume traffic. High-speed fiber optics and free-space optics (FSO) systems may be potential solutions to this problem.

[0119] - Radar technology integrated with mobile technology: High-precision localization (or location-based services) through communications is a key feature of 6G wireless communication systems. Therefore, radar systems will be integrated with 6G networks.

[0120] - Softwarization and virtualization: Softwarization and virtualization are two critical features that form the foundation of the design process for 5GB networks to ensure flexibility, reconfigurability, and programmability. Furthermore, billions of devices can be shared on a shared physical infrastructure.

[0121] To satisfy the above-mentioned characteristics, the core implementation technologies of the 6G system may include artificial intelligence (AI), THz (terahertz) communication, optical wireless technology, FSO backhaul network, massive MIMO technology, blockchain, 3D networking, quantum communication, unmanned aerial vehicles, cell-free communication, wireless information and energy transfer (WIET), integration of sensing and communication, integration of access backhaul networks, holographic beamforming, big data analysis, and large intelligent surface (LIS).

[0122] For example, THz communication can be utilized in 6G systems. THz communication is a communication that utilizes a spectrum in a frequency band between 0.3 THz and 3 THz with a corresponding wavelength in the range of 0.1 mm to 1 mm, as shown in FIG. 6. Referring to FIG. 6, the frequency band of THz waves is located in the middle region between the infrared band and the millimeter wave band, and therefore, THz waves can be understood as radio waves with the shortest wavelength and light waves with the longest wavelength. Therefore, THz waves share some of the characteristics of infrared and microwave waves, and specifically, they can simultaneously have the transparency of electromagnetic waves and the straightness of light waves.

[0123]

[0124] Figure 7 illustrates a transmitter structure applicable to the present disclosure.

[0125] Referring to Figure 7, in order to modulate data into an optical signal, an optical source of a laser can be passed through an optical wave guide to change the phase of the signal, etc. At this time, data is loaded by changing the electrical characteristics through a microwave contact, etc. Therefore, the optical modulator output is formed as a modulated waveform.

[0126] Data may be provided from a data signal generator. Here, the data may include various user data, configuration information, control information, etc. transmitted through a channel. Furthermore, the data may include data related to AI-based operations, such as information for configuring an AI model, input / output data for tasks of the AI ​​model, etc. To this end, components related to AI functions (e.g., an AI processing unit) may be included in the data signal generator or may be linked to the data signal generator.

[0127] An optical / electronic converter (O / E converter) can generate THz pulses by optical rectification using a nonlinear crystal, photoelectric conversion using a photoconductive antenna, or emission from a bunch of relativistic electrons. The THz pulse generated in the above manner can have a length in the range of femtoseconds to picoseconds. The optical / electronic converter (O / E converter) performs down conversion by utilizing the nonlinearity of the device.

[0128] Considering the THz spectrum usage, it is likely that multiple contiguous GHz bands will be used for THz systems, either fixed or for mobile services. For an outdoor scenario, the available bandwidth can be categorized based on an oxygen attenuation of 10^2 dB / km in the spectrum up to 1 THz. Accordingly, a framework in which the available bandwidth is divided into multiple band chunks can be considered. As an example of this framework, if the THz pulse length for a single carrier is set to 50 ps, ​​the bandwidth (BW) becomes approximately 20 GHz.

[0129] Effective down-conversion from the infrared band to the THz band depends on how to utilize the nonlinearity of the optical / electrical converter (O / E converter). In other words, to down-convert to the desired THz band, it is necessary to design an O / E converter with the most ideal non-linearity for transferring to the THz band. If an O / E converter that is not suitable for the target frequency band is used, errors in the amplitude and phase of the pulse are likely to occur.

[0130] A THz transmission and reception system can be implemented using a single optical-to-electrical converter in a single-carrier system. Depending on the channel environment, optical-to-electrical converters may be required as many as the number of carriers in a multi-carrier system. This phenomenon will be particularly noticeable in a multi-carrier system that utilizes multiple broadbands according to the aforementioned spectrum usage plan. In this regard, a frame structure for the multi-carrier system may be considered. A signal down-frequency converted based on an optical-to-electrical converter may be transmitted in a specific resource region (e.g., a specific frame). The frequency region of the specific resource region may include multiple chunks. Each chunk may be composed of at least one component carrier (CC).

[0131]

[0132] 6G systems may introduce AI technology. Efficient resource management and optimization are required to maintain connectivity between various services and devices. AI technology may include technologies that perform data analysis, pattern recognition, and predictive modeling using AI / ML (artificial intelligence / machine learning) models. Here, an AI / ML model can be understood as a set of parameter values ​​and / or weight values ​​related to mathematical formulas or algorithms generated through learning to discover patterns in input data or make predictions. To create such an AI / ML model, an AI / ML model learning process is required, which builds an AI / ML model by learning the relationship between inputs and outputs in a data-driven manner. Various learning algorithms, such as supervised learning, unsupervised learning, and reinforcement learning, can be utilized as learning algorithms. To generate output, a user can input specific data into a trained AI / ML model, and the process of obtaining output data by inputting input data into an AI / ML model can be referred to as AI / ML "inference" or "prediction."

[0133] Network control parameters can be obtained as output through AI / ML inference using trained AI / ML models. Users can utilize the output parameter values ​​to improve network efficiency. For example, AI technology can be utilized in various fields, such as wireless network resource allocation, traffic management, fault prediction, and quality of service (QoS) management. In particular, machine learning can efficiently allocate resources even in dynamically changing network environments based on real-time data. Therefore, AI technology can be utilized to provide hyper-connectivity and ultra-low latency.

[0134] At this time, AI / ML inference can be performed based on a combination of various devices. For example, the UE and the network can jointly perform AI / ML inference, and such an AI / ML model can be referred to as a two-sided AI / ML model or a two-sided model. In this case, the UE can perform the first part of the inference first, and the base station can perform the remaining inference, or vice versa. Alternatively, inference can be performed entirely on the UE, and such an AI / ML model can be referred to as a UE-side AI / ML model or a UE-side model.

[0135] Additionally, life cycle management (LCM) can be performed for AI / ML models. Life cycle management can include model training, model deployment, model inference, model monitoring, and model updates. This may require support for data collection, model training, functional / model identification, model delivery / transfer, model inference operations, functional / model selection / activation / deactivation / fallback, functional / model monitoring, model updates, and UE capabilities.

[0136] For example, AI / ML technology can be operated based on a functional framework such as FIG. 8. FIG. 8 illustrates an example of a functional framework for application of AI / ML technology applicable to the present disclosure. First, a data collection function (810) performs data preparation on input data collected from objects (e.g., UE, RAN node, network node, etc.) to generate training data (801), monitoring data (803), and / or inference data (805) including processed input data. A model training function (820), which receives training data (801) from the data collection function (810), performs training on an AI / ML model using the training data (801) and provides a trained / updated model (813) to a model repository (840). The model repository (840) can store and retain the received trained / updated model (813).

[0137] A management function (830) may be used to control AI / ML model training. The management function (830) may control the operation of the AI / ML model or AI / ML functions, or supervise their performance. To this end, the management function (830) may receive monitoring data (830) from the data collection function (810) and inference output (809) from the inference function (840). The management function (830) manages the data received from the data collection function (810) and the inference function (840) so that the inference task can be performed efficiently. That is, the management function (830) may transmit performance feedback or a retraining request (807) to the model training function (820) to improve the inference task. Here, the performance feedback may be used to indicate a learning goal or as a reward for reinforcement learning. Additionally, the management function (830) can transmit management instructions (811) that instruct the inference function (840) to select AI / ML models or AL / ML-based functions to be used, activate / deactivate them, or switch to non-AI / ML operation.

[0138] The inference function (840) generates an inference output (809) by performing inference and / or prediction using the inference data (805) received by the data collection function (810). Here, the inference output (809) refers to the inference output of the AI / ML model used by the inference function (840), and the details of the inference output may vary depending on the use case. The AI / ML model used by the inference function (840) can be controlled by the management function (830). That is, the management function (830) can transmit a model transfer / forward request signal (815) to request a necessary AI / ML model to the model repository function (850), and the model repository function (850) can transmit the corresponding AI / ML model to the inference function (840) via a model transfer / forward signal (817). Therefore, the inference function (840) can perform inference using the AI / ML model (817) according to the received management instruction (811).

[0139] Additionally, the management function (830) may trigger or perform a designated task / action based on the inference output (809). Accordingly, the management function (830) may trigger a task / action for another entity (e.g., at least one UE, at least one RAN node, at least one network node, etc.) or for itself. Any one of the functions exemplified in FIG. 8 described above may be performed by two or more entities, including the RAN, the network node, the network operator's OAM, or the UE, in collaboration. This may be referred to as a split AI operation.

[0140] Not all of the functions (810 to 850) illustrated in FIG. 8 need to be used to utilize the AI / ML model, and the method of combining them is not limited to a specific method. Accordingly, the functions (810 to 850) may be operated in an integrated manner, or some functions may be omitted. Furthermore, the functions (810 to 850) illustrated in FIG. 8 are not necessarily limited to being implemented as separate devices or apparatuses. For example, some or all of the functions (810 to 850) may be included in the processor (202) of FIG. 2. Furthermore, the model storage function (850) may be included in the memory (204) of FIG. 2.

[0141]

[0142] FIG. 9 illustrates an example of a procedure for utilizing an AI model applicable to the present disclosure. FIG. 9 illustrates a case where a model training function (820) is included in a network node and a model inference function (840) is included in a RAN node. Referring to FIG. 9, in step 1, RAN node 1 and RAN node 2 transmit input data (e.g., training data) for training an AI model to the network node. Here, RAN node 1 and RAN node 2 may transmit data collected from the UE (e.g., measurements of the UE related to RSRP, RSRQ, SINR of the serving cell and neighboring cells, the UE's position, speed, etc.) together to the network node. In step 2, the network node trains the AI ​​model using the received training data. In step 3, the network node distributes / updates the AI ​​model to RAN node 1 and / or RAN node 2. RAN node 1 and / or RAN node 2 may also continue model training based on the received AI model. In this procedure, it is assumed that the AI ​​model is deployed / updated only to RAN node 1. In step 4, RAN node 1 receives input data (e.g., inference data) for AI model inference from UE and RAN node 2. In step 5, RAN node 1 performs AI model-based inference using the received inference data to generate output data (e.g., prediction or decision). In step 6, if applicable, RAN node 1 may transmit model performance feedback to network nodes. In step 7, RAN node 1, RAN node 2, and UE (or 'RAN node 1 and UE', or 'RAN node 1 and RAN node 2') perform actions based on the output data. For example, in case of load balancing operation, the UE may move from RAN node 1 to RAN node 2. In step 8, RAN node 1 and RAN node 2 transmit feedback information to network nodes.

[0143] Network nodes can manage AI models based on feedback information regarding the AI ​​model's inference results. For example, the network node can perform additional training on the AI ​​model or generate additional information about the AI ​​model (e.g., performance information, accuracy information, etc.). If additional training is performed on the AI ​​model, the network node can distribute the updated AI model to RAN node 1.

[0144] As described with reference to Figure 9, model training can be performed by network nodes, and inference using the model can be performed by RAN node 1. In other words, the model training and inference functions can be distributed. Typically, model training requires significant computational resources because it utilizes large amounts of data and complex algorithms for optimization. In contrast, inference, which uses a trained model to derive conclusions about new data, requires relatively fewer computational resources compared to model training. Therefore, using the procedure of Figure 9, model training can be performed through network nodes when the computational resources of the UE or RAN node are insufficient. Furthermore, security can be ensured for the AI ​​model because the AI ​​model is not disclosed to the UE.

[0145] FIG. 9 illustrates a case where a model training function (820) is included in a network node and a model inference function (840) is included in a RAN node, but the present disclosure is not limited thereto. For example, if the computational resources of the RAN node are sufficient, both the model training function (820) and the model inference function (840) may be included in RAN node 1. In this case, RAN node 1 receives training data for training an AI model from the UE and RAN node 2. RAN node 1 trains the AI ​​model using the received training data. Thereafter, RAN node 1 receives inference data for AI model inference from the UE and RAN node 2. RAN node 1 performs inference based on the AI ​​model using the received inference data to generate output data. Based on the output data, the UE, RAN node 1, and RAN node 2 may perform operations related to communication (e.g., handover, cell change). Thereafter, the UE and RAN node 2 may transmit feedback regarding the operations to RAN node 1. Therefore, RAN node 1 can learn the AI ​​model and update its own AI model using feedback information regarding the AI ​​model's inference results. According to the aforementioned method, signaling with the network is not required for AI model learning and inference, thereby reducing network load and delays until the AI ​​model is trained or inference results are received. Furthermore, since the UE performs inference using the AI ​​model, its personal information is not transmitted to network nodes, etc., thereby enhancing the security of personal information.

[0146] As another example, the model training function (820) may be included in the RAN node, and the model inference function (840) may be included in the UE. The RAN node receives training data for training an AI model from the UE, and trains the AI ​​model using the received training data. The RAN node distributes the trained AI model to the UE. The UE may perform inference based on the received AI model to generate output data. At this time, the data for inference may be received from the RAN node, or the UE may use data acquired on its own. The UE and the RAN node may perform communication-related operations based on the output data generated by inference. Thereafter, the UE may transmit feedback regarding the operation to the RAN node. Therefore, the RAN node may train the AI ​​model and distribute the updated AI model to the UE through feedback information regarding the inference result of the AI ​​model. According to the above-described method, the model training function (820) may be included in the RAN node, and the model inference function (840) may be included in the UE to perform inference, thereby reducing the load on the RAN node. Additionally, if the UE uses data acquired on its own to make inferences, even if the UE loses connection with the RAN node after receiving the AI ​​model, the UE can continue to infer the distributed AI model and perform operations based on the inference results.

[0147] According to the framework and procedures described above, an AI model can be trained and utilized in a wireless communication system. The model training function (820) and the model inference function (840) can be combined in various ways and are not necessarily limited to the case of FIG. 9. In the framework and procedures described above, various types of data, such as input data, training data, and inference data, are introduced, and the specific content of the data described above may vary depending on the task for which the AI ​​model is utilized. For example, information used in various embodiments of the present disclosure described below may be included in the data described above.

[0148]

[0149] Figure 10 illustrates an AI technology-based communication procedure applicable to the present disclosure. The detailed procedures illustrated in Figure 10 can be combined with various embodiments of the present disclosure described below. For example, data generated according to various embodiments of the present disclosure can be used for operations (e.g., configuration, training, inference, and / or data transmission / reception) in at least one of the detailed procedures illustrated in Figure 10. As another example, the results of the inference illustrated in Figure 10 can be used to transmit and / or receive data according to various embodiments of the present disclosure.

[0150] Referring to FIG. 10, in step S1001, at least one of the UE (1010), the RAN node (1020), and the network node (1030) performs an initial access procedure. For example, in this step, at least one of an initial cell search operation, a system information acquisition operation, a random access operation, and a registration operation may be performed. In step S1003, at least one of the UE (1010), the RAN node (1020), and the network node (1030) performs a configuration procedure. Through the configuration procedure, parameters, resources, connections, and / or entities necessary for performing subsequent procedures in layers between the UE (1010) and the RAN node (1020) and / or in at least one layer between the UE (1010) and the network node (1030) may be determined and / or created. In this case, the configuration procedure may be performed based on information, status, and / or characteristics of an AI model used for subsequent training and inference.

[0151] In step S1005, at least one of the UE (1010), the RAN node (1020), and the network node (1030) performs a model training procedure. At least one of the UE (1010), the RAN node (1020), and the network node (1030) may collect training data and perform learning using the training data. For example, the model training procedure may be performed as described with reference to FIG. 15, FIG. 16, or FIG. 17. If an offline-trained model is used, this step may be omitted.

[0152] In step S1007, at least one of the UE (1010), the RAN node (1020), and the network node (1030) performs a task using the trained model. That is, the task may be performed based on the results of inference and / or prediction using the trained model. For example, the task may be a procedure belonging to a communication protocol, and may be a preparatory operation for subsequent data transmission and / or reception, or may be related to data transmission and / or reception, or may be related to data processing (e.g., encoding, decoding, etc.).

[0153] In step S1009, at least one of the UE (1010), the RAN node (1020), and the network node (1030) transmits and / or receives data. At this time, the result of the task performed in step 1007 may be used. In some cases, the task performed in step 1007 may include transmitting and / or receiving data, in which case this step may be omitted as it is part of step 1007.

[0154]

[0155] Specific embodiments of the present disclosure

[0156] The present disclosure proposes a technique for recovering modulus through re-encryption using communication instead of performing bootstrapping when bootstrapping is required in connection with the use of homomorphic encryption.

[0157]

[0158] Homomorphic encryption is an encryption method that allows operations to be performed on encrypted data without decrypting it. Homomorphism is derived from homomorphism, a common concept in mathematics, and refers to a map that preserves operations between two algebraic structures of the same type. In other words, homomorphic encryption is a cryptographic system that preserves specific operations, such as addition and multiplication, by mapping elements in the plaintext space to elements in the ciphertext space. The result of operations using ciphertexts becomes a new ciphertext, and the plaintext obtained by decrypting the new ciphertext is identical to the result of the operations on the original data before encryption.

[0159] For example, the result of adding the ciphertexts Enc(M1) and Enc(M2) obtained by homomorphically encrypting the plaintexts M1 and M2 is the same value as the ciphertext Enc(M1+M2) corresponding to (M1+M2). Similarly, the result of multiplying the ciphertexts Enc(M1) and Enc(M2) obtained by encrypting the plaintexts M1 and M2 is the same value as the ciphertext Enc(M1×M2) corresponding to (M1×M2). In this way, since ciphertexts based on homomorphic encryption contain the same result as the ciphertext of the plaintext added or multiplied, decrypting the ciphertext yields the same value as the result of adding or multiplying the plaintext itself.

[0160] All Boolean operations on a computer can be expressed as exclusive or (XOR) and logical AND. Therefore, by extending the properties of homomorphic encryption to allow addition and multiplication without decrypting encrypted data, various data processing operations, such as statistical calculations and machine learning, can be easily performed without decrypting encrypted data.

[0161] Furthermore, homomorphic encryption can be applied to database systems. If a data owner requests data analysis but does not wish to expose the data, the data owner can provide homomorphically encrypted data to the data analyst. The data analyst can then generate ciphertext for the data analysis results through homomorphic encryption operations and transmit it to the data owner. If only the data owner possesses the private key, the data analyst cannot access the resulting data analysis results, and only the data owner, who possesses the private key, can decrypt them. Therefore, it is possible to obtain analysis results without exposing one's own data.

[0162]

[0163] The aforementioned homomorphic encryption can be classified into partial homomorphic encryption, some homomorphic encryption, and fully homomorphic encryption (FHE) depending on the types of operations that can be performed in an encrypted state and the number of possible operations. The widely used public key encryption algorithms, the Rivest Sharmir Adleman (RSA) algorithm and the ElGamal algorithm, can also be considered partially homomorphic encryption because they can perform multiplication operations in an encrypted state. On the other hand, finite homomorphic encryption refers to homomorphic encryption in which no more algebraic operations are possible after a certain number of operations due to the incompleteness of algebraic operations.

[0164] In 2009, Gentry announced the first-generation fully homomorphic encryption, which allows for infinite repetition of arbitrary operations in an encrypted state by adding an operation called bootstrapping to finite homomorphic encryption. However, although the first-generation fully homomorphic encryption was proven to be secure, it was difficult to implement efficiently. Encryption and decryption based on the first-generation fully homomorphic encryption are performed according to the following procedure. In encryption, a message is consultation is encoded. At this time, is a random vector with coefficients of {0,±1}, and the ciphertext is Here, means the rounding operator, In decryption, is calculated, The operation is performed. That is, the plaintext is is the result of.

[0165] In 2011, the BGV11 scheme was introduced by Brakerski-Gentry-Vaikuntanathan. BGV11 increased the number of possible multiplications without bootstrapping from linear to exponential with the ciphertext length by applying a method to reduce the noise generated during multiplication. This noise-reducing operation is called modulus / key switching, and techniques that employ this process are referred to as second-generation homomorphic encryption.

[0166] The BGV technique based on ring-learning with errors (RLWE) operates according to the following operations. In the following description, is a power of 2, modulus is an odd positive integer, Is The error distribution of the top, is the error distribution It means the bound of the length of the elements output by any integer. About can be defined. In key generation, security parameters and random values is selected, and the secret key is decided by is created, is calculated. Here, Is is a randomly selected error in the public key. and, In encryption, a message is a vector is converted to, is chosen randomly. And, the ciphertext is is determined by. Here, In decryption, the secret key and ciphertext As an input value, This is calculated. Next, Plaintext is converted by operation can be determined as follows. In homomorphic operations, addition is performed element by element, and the sum is the modulus It doesn't matter if it doesn't exceed . Multiplication is = = is performed as follows. New ciphertext is a new secret key can be decrypted. To solve the problem of the secret key increasing with each multiplication operation in the BGV technique, a key switching method was introduced. Key switching is Ciphertext for is generated after multiplication by cast , and change the ciphertext to a new ciphertext that encrypts the same plaintext. Convert to . At this time, am.

[0167] In 2013, Gentry-Sahai-Water introduced a technique that further reduces noise in the multiplication process and eliminates the relinearization process, which requires a large computational cost. Homomorphic encryption that utilizes this is called third-generation homomorphic encryption. In particular, the FHEW technique of Ducas-Micciancio and the fast fully homomorphic encryption (TFHE) technique of Chillotti-Gama-Georgieva-Izabachene, which enable very fast bootstrapping by limiting the plaintext to 1 bit, belong to this generation of homomorphic encryption.

[0168] The TRLWE technique or TFHE technique operates according to the following operations. In the following description, is a power of 2, , , is defined as A random element selected from has a coefficient of {0,1}. is a polynomial less than or equal to 1. In key generation, the security parameter About the secret key This is determined. In encryption, the message , error parameters About any mask , small error If so, the ciphertext is is determined by. Here, follows the B-bounded distribution. In decryption, the secret key and ciphertext This input is taken as the linear form of the ciphertext. -Lipschitz function is calculated. , is a function has a value close to the actual message, In a homomorphic linear combination, the same key encrypted with Dog's ciphertexts and polynomials with integer coefficients If exists, a new ciphertext is created by linear combination of the ciphertexts. can be obtained. At this time, the new ciphertext is and, Maintain.

[0169] In 2017, Cheon-Kim-Kim-Song announced a homomorphic encryption scheme called HEAAN (homomorphic encryption for arithmetic of approximate numbers), which allows a third operation, rounding, in addition to addition and multiplication. HEAAN utilizes the Cheon-Kim-Kim-Song (CKKS) technique.

[0170] The CKKS technique operates on the following operations: Any positive integer About, silver It is a circular ring. has a polynomial with few coefficients It represents the distribution of the top. Modulus Wow, the degree of the circle can be determined in advance prior to key generation. In key generation, the secret polynomial is selected. Any value from is selected, at is selected, is randomly selected. At this time, the secret key is , and the public key is , the evaluation key is is determined by . In encryption, a given message To encrypt, an arbitrary polynomial This is selected, is calculated. In decryption, the inner product operation between the secret key and the ciphertext This is performed. Specifically, = = = = The same operation can be performed. In a homomorphic operation, two ciphertexts and In this given case, homomorphic addition is element-wise addition . Homomorphic multiplication is an element-wise multiplication operation on two ciphertexts. and includes the operation of removing the square term. In summary, the multiplication operation is It is the same as .

[0171] While conventional homomorphic encryption can perform rounding operations, they require extremely complex calculations, similar to bootstrapping. The CKKS technique performs this operation at the speed of addition, significantly improving arithmetic performance. Furthermore, while conventional homomorphic encryption restricts the plaintext to bits or integers, Hyean allows for homomorphic encryption of real numbers and operations on encrypted states, offering greater usability.

[0172] Year of classificationCharacteristicsOperation unitISO standard1st generation2009First fully homomorphic encryptionBit2nd generation2011Applicable to real dataIntegerBGV, BFV3rd generation2013Effective for processing small dataBitTFHE4th generation2016Homomorphic encryption that supports operations up to real numbersReal numbers(integer)CKKS

[0173] The aforementioned homomorphic encryption technology can be applied in various fields.

[0174] For example, homomorphic encryption can be applied to IoT in fog or edge computing. Fog computing was initially proposed by CISCO to deploy scalable, large-scale IoT, and has evolved into the concept of edge computing in cellular networks for 5G / 6G communications. In fog computing, the layer between IoT devices and cloud services is defined as close to the devices as possible to preprocess data. To reduce bandwidth consumption and latency in IoT applications, it is crucial to perform preprocessing tasks close to the devices. In the above scenario, homomorphic encryption can provide privacy protection because preprocessing is performed in an encrypted state. However, there are several characteristics that must be considered when applying homomorphic encryption in fog or edge computing. Each data must be an event-based packet generated by a specific device, and each data must be moved through the network at a rate consistent with the device's data generation rate. In other words, data must be processed on a packet-by-packet basis. Therefore, data processing is delay-tolerant and the scope of data processing tasks is limited to the information contained in a single data packet (e.g., relevance / categorization assessment, formatting, encoding, expansion / compression, filtering, thresholding, real-time alert evaluation, etc.). Smart cities provide an example of how fog computing and homomorphic encryption can be connected, encompassing a wide range of applications such as intelligent transportation, efficient resource allocation (e.g., lighting, water and waste management), safety and security, or environmental monitoring. These applications share a common requirement: a network comprised of large-scale IoT devices deployed with small sensors that continuously feed data to smart city data collectors. The fog layer preprocesses data within intermediate gateways, and this preprocessing can be scalable. Homomorphic encryption can be applied to protect privacy.Specifically, sensors can encrypt data with the data collector's public key, and the encrypted data can be processed within the fog layer, but decryption can only be performed within the data collector. This approach not only prevents data leakage within fog nodes but also provides privacy protection for the data collector. Despite these advantages, the computational complexity and ciphertext size make homomorphic encryption difficult to apply to IoT devices. A significantly larger ciphertext size compared to plaintext increases communication overhead, and computational complexity leads to computational delays. This situation is further exacerbated by the limited hardware capabilities and computational load of IoT devices, as well as the bandwidth constraints of IoT communication standards. As an alternative, a hybrid protocol combining homomorphic encryption and symmetric key encryption (SKE) has been proposed. In hybrid homomorphic encryption (HHE), IoT devices perform symmetric key encryption with a randomly generated key and then encrypt the symmetric key with the data collector's homomorphic public key. Fog nodes, positioned between IoT nodes and data collectors, can perform homomorphic computations by converting symmetrically encrypted data into homomorphically encrypted data through key transformation. This method has the advantage of shifting the computation and ciphertext expansion problem from IoT devices to fog nodes. IoT devices only need to perform encryption using symmetric key encryption methods like AES. Fog or edge computing is not limited to smart city scenarios and can be expanded into new fields such as the industrial IoT and the Internet of Medical Things (IoMT).However, while hybrid protocols are effective when data is encrypted with the recipient's public key, they suffer from the problem of large ciphertext size in situations where IoT devices encrypt with their own public keys and communication must be bidirectional.

[0175] For example, homomorphic encryption can be applied to cloud computing. Fog computing is a distributed infrastructure, while cloud computing is a system where data processing is primarily query-responsive and large amounts of data from various applications are centralized. Homomorphic encryption can be an effective component for protecting personal information in cloud computing.

[0176] For example, homomorphic encryption can be applied to homomorphic proxy re-encryption. Most homomorphic encryption methods only support homomorphic operations on ciphertexts encrypted with the same public key, so the ciphertexts of different users must be transformed into ciphertexts encrypted with the same key. This is called homomorphic proxy re-encryption (HPRE). Proxy re-encryption itself is a non-homomorphic encryption technique used in cloud computing. It transforms the ciphertext of a person delegating data into ciphertext that can be decrypted by another user (e.g., the delegated user), who can decrypt the ciphertext without the delegated user's private key. In other words, the proxy can transform the ciphertext without knowing the plaintext or the user's private key. Homomorphic proxy re-encryption can achieve additional benefits because the cloud can perform homomorphic operations on the transformed ciphertext. Gentry's proposed method is as follows: First, the private key is encrypted with the public key of the delegated user. The person delegating encrypts the data with their public key. The proxy then performs the necessary decryption operations using a decryption circuit and re-encrypts the ciphertext with the delegator's public key. Gentry's method was vulnerable to collusion between the delegator and the proxy, allowing them to obtain the delegator's private key. However, several homomorphic proxy re-encryption techniques based on key switching have addressed this issue.

[0177] For example, homomorphic encryption can be applied to homomorphic authenticated encryption (HAE). Cloud users may pay for specific services, or data integrity may be critical, requiring assurance that data has been processed correctly. Even if the cloud is not particularly malicious, it may provide incorrect data to reduce or avoid the extensive computation required to process homomorphically encrypted data. In this case, users must be able to verify that the decrypted data correctly executes the commands they requested, and HAE satisfies this need. HAE is achieved by combining homomorphic encryption and homomorphic authentication (HA). Specifically, the user attaches a homomorphic signature to the ciphertext. This signature, similar to the ciphertext, can be used as a valid signature for data processed through homomorphic operations. Furthermore, if HE and HA are secure against chosen plaintext attacks, HEA (homomorphic encryption and authentication) satisfies CCA-1 (chosen ciphertext attack-1).

[0178] For example, homomorphic encryption can be applied to multiparty computation. Using homomorphic encryption, computations previously performed on personal computers can be performed in the cloud. However, when performing multiparty computations involving the interaction of multiple parties, various considerations arise. In particular, secure multiparty computation, which performs computations without revealing information about each party's inputs and without knowing the inputs of other parties except for the values ​​inferred from the output, is a suitable application of homomorphic encryption. Previous secure multiparty computations based on secret sharing and garbled circuits existed, and they were structured according to a preprocessing model in which the computation is divided into two stages. The first stage is the generation of secret sharing or garbled circuits. This stage is a cryptographic preparatory stage performed before the parties' inputs are defined, thereby accelerating the second stage. The second stage involves defining the parties' inputs and individually computing the circuits. While slightly less efficient than previous approaches, one promising approach for secure multi-party computation is Multi-Key Fully Homomorphic Encryption (MKFHE). Secure multi-party computation using MKFHE involves two rounds of communication. In the first round, each party encrypts the input with multiple keys and broadcasts the ciphertext to all parties. Each party then computes the circuit using homomorphic computation. In the second round, each party broadcasts a partially decrypted fragment of the output. Each party combines its partially decrypted value with the partially decrypted fragments of the other parties to obtain the output. However, this MKFHE-based multi-party computation requires the decrypted fragments of all parties holding the secret key fragments to succeed. Failure to transmit a single decrypted fragment will result in the protocol failing.The above problem can be solved by homomorphic encryption with quorum decryption, for example, threshold MKFHE (TMFHE), which allows a small number of parties exceeding a threshold to perform decryption.

[0179]

[0180] Second-generation homomorphic encryption methods, such as BFV and BGV, and fourth-generation homomorphic encryption methods, such as CKKS, require high computational time during bootstrapping. Therefore, reducing the computational time required for bootstrapping is essential for applying homomorphic encryption to real-world systems. First, bootstrapping for CKKS is explained as follows.

[0181] The framework of CKKS can be represented as shown in Fig. 11. Fig. 11 illustrates the framework of CKKS. CKKS is A dog's mistake or The number of dummy numbers can be encrypted. Encoding / decoding and encryption / decryption according to the CKKS technique can be performed as follows.

[0182]

[0183] Encoding / Decoding

[0184] The dog's mistake / 2 can be converted into imaginary numbers and converted into a polynomial on a ring through an encoding process. For this purpose, parameters such as [Mathematical Formula 1] can be set.

[0185]

[0186] In [Equation 1], are the CKKS design parameters, is the number of real numbers being encrypted, is a Euler function, which outputs the number of coprimes of the input number. silver A set defined by silver A set containing only odd elements, is a natural projection, is a canonical embedding, Is and The greatest common divisor of, Is A set that satisfies silver A ring defined as is the order Having Degree 1 polynomial ( -th cyclotomic polynomial with degree ) means.

[0187] The encoding process is It performs the operation of , The elements of the top It is transformed into a polynomial. First, the transform matrix is ​​defined as in [Mathematical Formula 2] below.

[0188]

[0189] In [Equation 2], is the transformation matrix, It means. Here, Satisfies. The size of is. Message is a polynomial It can be converted as shown in [Mathematical Formula 3] below using .

[0190]

[0191] In [Equation 3], is a plaintext expressed in the form of a polynomial vector, A vector expressing the coefficients in ascending order of degree, is the transformation matrix, is a proportional constant to reduce the impact of errors on the message, is the number of real numbers being encrypted, is a message, Is is the conjugate of .

[0192] The decoding process is can be expressed by the operation of , The polynomial of the above It is converted into an element of the above. Decoding can be understood as the inverse transformation of encoding, and decoding, which performs an inverse transformation using the transformation matrix obtained above, can be performed as shown in [Mathematical Formula 4] below.

[0193]

[0194] In [Equation 4], is a message, is the transformation matrix, is a polynomial A vector expressing the coefficients in ascending order of degree, is a proportional constant to reduce the impact of errors on the message, refers to the number of real numbers being encrypted.

[0195] A specific example of the encoding process is as follows. The parameters for encoding can be set as in [Mathematical Formula 5].

[0196]

[0197] In [Equation 5], are the CKKS design parameters, is the number of real numbers being encrypted, is the Euler function, is the order Having Degree 1 polynomial ( -th cyclotomic polynomial with degree ), is a variable that forms a polynomial, silver A set containing only odd elements, Is A set that satisfies Is , is a proportional constant that reduces the impact of errors on messages.

[0198] message When encoding, the plaintext is encoded using a transformation matrix as shown in [Mathematical Formula 6] below. This can be obtained.

[0199]

[0200] In [Equation 6], is a plaintext expressed in vector form, and is a polynomial A vector expressing the coefficients in ascending order of degree, is a proportional constant to reduce the impact of errors on the message, is the number of real numbers being encrypted, is the transformation matrix, means the message.

[0201] Obtained in this way Decoding for is , It can be performed as follows.

[0202]

[0203] Encryption / decryption

[0204] According to the CKKS technique, by encoding The plaintext on the table The process of encrypting a ciphertext and the process of decrypting the ciphertext back into plaintext can be performed as follows. Encryption / decryption are based on the difficulty of the ring-LWE problem, which is a learning with error (LWE) problem defined on a ring.

[0205] The encryption process is as follows: Ring Plain text, the element of the above In this given situation, an operation like [Equation 7] is performed.

[0206]

[0207] In [Equation 7], is a ciphertext, is distributed The values ​​sampled from, is the public key, Silver is plain text, is distributed It refers to the error values ​​sampled from. Here, , , Each value can be obtained through sampling such as . In addition, , , Each value can be obtained through sampling such as . Here, Is It is a secret key in the form of . Also, Is has a coefficient of -1 or 1 with probability of A length with a coefficient of 0 with probability It is a distribution that samples vectors. is the parameter is a discrete Gaussian distribution, is the Hamming weight length of person It is a distribution that samples vectors uniformly. silver It is a distribution that samples the elements of the above evenly.

[0208] The decryption process is as follows: Ciphertext If given, Plain text This can be obtained. At this time, can lead to, If this is small enough, the original plaintext It is possible to recover plaintext that is almost identical to the original text.

[0209]

[0210] Bootstrapping

[0211] When performing a multiplication operation based on the homomorphic encryption described above, a rescaling operation is performed. The modulus gradually decreases due to the rescaling operation. The concept of the rescaling operation is as shown in Figure 12. Figure 12 illustrates an example of rescaling for ciphertexts based on homomorphic encryption. Referring to Figure 12, each of the two ciphertexts has a size , and contains a message (e.g., m1, m2) in part of the modulus. If we perform a homomorphic multiplication of two ciphertexts, an error (e.g., e) is generated. * ) occurs. Accordingly, a rescaling operation is performed to control the increasing error. At this time, Rescaling is performed as follows, and as a result, the modulus of the ciphertext is at It decreases to . In Fig. 12, the modulus By rescaling, the modulus is If this rescaling is performed repeatedly, the modulus may become so small that it can no longer be rescaled. Therefore, to perform additional homomorphic multiplication, it is essential to restore the modulus to a value as large as the original modulus. For example, the modulus can be restored by a bootstrapping operation.

[0212] The bootstrapping operation can be performed as shown in Figure 13. Figure 13 illustrates an example of a bootstrapping operation for a ciphertext based on homomorphic encryption. Bootstrapping is performed in five steps. Specifically, bootstrapping includes the following steps: a) modulo raise, b) coefficient to slot, c) evaluation exponential, d) imaginary extraction, and e) slot to coefficient. The detailed operations at each step are as follows.

[0213] a) modulo raise

[0214] In the first step, the device is given a password that requires bootstrapping. Modulo of If we simply raise the modulus, the result of decrypting the ciphertext is This may not come out. That is, as, This can be. Therefore, the device isomorphically about By performing the operation, Bootstrapping is performed to ensure this is satisfied. At this time, To perform isomorphically, an approximate function such as [Equation 8] can be used.

[0215]

[0216] In [Equation 8], is an approximation function, is the size of the modulus, is a function It means the input variable of .

[0217]

[0218] b) coefficient to slot

[0219] In the second step, the device The coefficients of are converted into the message domain. To do this, the process described in decoding is performed homomorphically, and through this The coefficients of the ciphertext converted to the message domain This can be obtained. At this time, in the message domain Since only complex values ​​of the dog can be stored, the total To convert the coefficients of the dog into the message domain, two ciphertexts are generated. The ciphertexts are generated as shown in [Equation 9] below. [Equation 9] follows the form of the operation in the message domain.

[0220]

[0221] In [Equation 9], is the plaintext value included in the converted ciphertext, is the number of real numbers being encrypted, is the transformation matrix, means the message.

[0222] Accordingly, Ciphertext for , Ciphertext for This is obtained.

[0223]

[0224] c) evaluation exponential

[0225] In the third step, the device is obtained from the previous step. The complex exponential of the values ​​is evaluated. In this case, the evaluation is also performed isomorphically.

[0226]

[0227] d) imaginary extraction

[0228] In the fourth step, the device calculates the imaginary part value using the multiple exponent values ​​obtained in c), and consequently obtains the sin value. The process is as shown in [Mathematical Formula 10].

[0229]

[0230] In [Equation 10], is the size of the modulus, Is It refers to the input variable of the function.

[0231] Through the obtained sin value, an approximated value like [Mathematical Formula 8] above is obtained. The operation becomes possible. The obtained ciphertexts are each , is defined as

[0232]

[0233] e) slot to coefficient

[0234] Finally, the device obtained above , The values ​​in the message domain are converted to the plaintext domain. To this end, the device performs the operations described in the encoding process homomorphically, and the corresponding operation can be expressed in a formula as shown in [Mathematical Formula 11].

[0235]

[0236] In [Equation 11], is a message, is the transformation matrix, Silver is plain text, is a ciphertext , It means the plaintext value contained in .

[0237] The ciphertext obtained in this way Is becomes satisfied.

[0238] For the entire bootstrapping process described above, the data flow in the message domain, plaintext domain, and ciphertext domain is as shown in Figure 14. Figure 14 illustrates an example of data changes according to bootstrapping.

[0239] The aforementioned bootstrapping operations, including CoeffToSlot, EvalExp, ImgExt, and SlotToCoeff, all require complex homomorphic operations, resulting in high computational complexity. Therefore, to apply bootstrapping operations to communication procedures, a technique capable of recovering the modulus at a faster rate is needed.

[0240] First, the communication-based bootstrapping technology that has been studied previously can be expressed as in Fig. 15. Fig. 15 illustrates an example of a ciphertext initialization operation using a communication environment. Referring to Fig. 15, when a ciphertext requiring bootstrapping is generated, the server (1520) directly transmits the ciphertext to a client (1510) capable of encrypting / decrypting it, thereby re-encrypting it with a high modulus and performing a communication process of receiving it. At this time, in order to prevent exposure of the server's computational information, the server (1520) adds a random message to the ciphertext. After homomorphically summing, it is transmitted to the client (1510). The client (1510) decrypts the received ciphertext, encrypts it again with a higher modulus, and transmits it to the server (1520). The server (1520) receives the re-encrypted ciphertext and the previously summed random message can be subtracted homomorphically and the original homomorphic operation can be performed subsequently.

[0241] According to a procedure similar to that illustrated in Figure 15, the modulus of the ciphertext can be recovered without performing complex bootstrapping operations by re-encrypting the ciphertext using a communication environment. However, the aforementioned technique requires continuous communication with the client while the server performs all homomorphic operations. Therefore, to establish a zero-touch network, a technique is needed to mitigate this need for continuous client-server communication.

[0242] Accordingly, the present disclosure proposes a technique for recovering the modulus of ciphertext using a communication-based re-encryption method instead of bootstrapping. Specifically, the present disclosure proposes a technique for implementing a zero-touch network, in which a client encrypts and transmits data it wishes to compute to a server, and only receives the ciphertext for which the computation has been completed, without an intermediate communication process for bootstrapping. The communication-based bootstrapping technique proposed in the present disclosure is as follows.

[0243]

[0244] Figure 16 illustrates an example of a procedure for performing communication by a device according to one embodiment of the present disclosure. Figure 16 illustrates a method performed by a terminal performing communication using homomorphic encryption. For example, the terminal may perform encryption using homomorphic encryption or perform homomorphic operations on ciphertext(s) based on homomorphic encryption.

[0245] Referring to FIG. 16, in step S1601, the terminal performs an initial access procedure. The terminal may detect a synchronization signal from a base station, receive system information, and perform a random access procedure. Specifically, the terminal may acquire information related to a random access channel included in the system information and transmit a random access preamble based on the acquired information. At this time, the terminal may select an RO (random access channel occasion) for transmitting the random access preamble based on the detected synchronization signal.

[0246] In step S1603, the terminal transmits capability information. The capability information includes information indicating the hardware or software capabilities of the terminal. Although not illustrated in FIG. 16, the terminal may receive a request message for capability information from the base station and transmit a message including the capability information in response to the request message. According to one embodiment, the capability information may include at least one of information related to homomorphic encryption, including information indicating support for homomorphic encryption, information indicating support for a modulus recovery technique according to the proposed technique, and information related to a third-party device (e.g., a server, a core network entity, etc.) participating in the modulus recovery procedure. According to another embodiment, the information related to homomorphic encryption may be transmitted through a procedure other than the capability information. For example, the information related to homomorphic encryption may be transmitted through signaling in step S1605 below.

[0247] In step S1605, the device performs signaling for configuration related to a service. For example, the terminal may perform control signaling with a base station or a core network entity for configuration necessary for performing communication. Specifically, the terminal may establish connections in various layers, configure an operation mode, configure resources for operation (e.g., slices, carriers, bandwidth part (BWP), flows, channels, etc.), or configure a service. Alternatively, the terminal may receive physical layer parameters necessary for transmitting and / or receiving a signal, such as power, modulation and coding scheme (MCS), scheduling information, and hybrid automatic repeat request (HARQ) parameters.

[0248] In step S1607, the terminal performs data communication using homomorphic encryption. That is, the terminal can utilize homomorphic encryption for the configured service. Here, data communication using homomorphic encryption can be understood as an operation of transmitting and / or receiving encrypted data, i.e., ciphertext, based on homomorphic encryption. For example, the terminal may perform encryption and then transmit the ciphertext. At this time, according to one embodiment, the terminal may also transmit a switching key for key switching of the ciphertext. In another example, the terminal may receive the ciphertext, decrypt the ciphertext, re-encrypt the plaintext, perform key switching, and then transmit the ciphertext. In another example, the terminal may receive the ciphertext and perform a homomorphic operation. At this time, according to various embodiments, the device may perform at least one operation to restore the modulus reduced by the homomorphic operation. The at least one operation may vary depending on the role of the terminal, i.e., whether the terminal performs encryption or a homomorphic operation.

[0249]

[0250] FIG. 17 illustrates an example of a procedure for performing a homomorphic operation including modulus recovery according to one embodiment of the present disclosure. FIG. 17 illustrates signal exchanges among a first device (1710), a second device (1720), and a third device (1730), which are procedures for performing a homomorphic operation on ciphertext(s) based on homomorphic encryption, and include modulus recovery operations according to various embodiments. Here, either the first device (1710) or the second device (1720) may be a terminal. The third device (1730) may be understood as a third device different from the terminal, or as a logically separated entity within the terminal, such as through virtualization.

[0251] Referring to FIG. 17, in step S1701, a first device (1710) generates an encryption key. Similarly, in step S1703, a third device (1730) generates an encryption key. An encryption key is a key used to generate an ciphertext based on homomorphic encryption and may include a pair of a secret key and a public key. Here, the public key is information shared with other devices. Specifically, each of the first device (1710) and the third device (1730) may determine parameter values ​​for key generation and generate a secret key and a public key based on the determined parameter values. For convenience of explanation below, the secret key of the first device (1710) is referred to as a first secret key, the public key of the first device (1710) is referred to as a first public key, the secret key of the third device (1730) is referred to as a second secret key, and the public key of the third device (1730) is referred to as a second public key. At this time, the encryption key of the first device (1710) and the encryption key of the third device (1730) are generated differently based on different random values. Furthermore, each of the first device (1710) and the third device (1730) can further generate a public key (hereinafter, “public key for switching”) used to generate a switching key.

[0252] In step S1705, the first device (1710) generates a switching key. The switching key is a key used to convert a ciphertext generated based on the first encryption key into a ciphertext generated based on the second encryption key. The first device (1710) may obtain a public key for switching of the second device (1720), and based on at least one parameter used to generate the encryption key of the first device (1710) and the public key for switching of the second device (1720), generate a switching key (hereinafter, “the first switching key”) that converts a ciphertext encrypted with the first public key into a ciphertext encrypted with the second public key. Similarly, in step S1707, the third device (1730) generates a switching key. In other words, the third device (1730) generates a switching key (hereinafter, “the second switching key”) that converts a ciphertext encrypted with the second public key into a ciphertext encrypted with the first public key.

[0253] In step S1709, the first device (1710) generates a ciphertext. That is, the first device (1710) can generate at least one ciphertext by encrypting plaintext using the first public key. For example, the first device (1710) can obtain at least one ciphertext based on the first public key by applying a function for encryption to the plaintext. In step S1711, the first device (1710) transmits at least one ciphertext and a switching key to the second device (1720). Here, the ciphertext is a ciphertext generated using the first public key, and the switching key is the first switching key.

[0254] In step S1713, the second device (1720) performs a homomorphic operation on at least one received ciphertext. Here, the performed homomorphic operation may include various operations. For example, the homomorphic operation may include a multiplication operation, and the modulus of the ciphertext may be reduced due to the rescaling included in the multiplication operation. The result of performing the homomorphic operation on at least one ciphertext is also a ciphertext that can be decrypted with the same secret key. In step S1715, the second device (1720) performs key switching on the homomorphically operated ciphertext. That is, the second device (1720) converts the ciphertext based on the first public key into the ciphertext based on the second public key. Then, in step S1707, the second device (1720) transmits the ciphertext based on the second public key to the third device (1730). That is, the second device (1720) transmits a ciphertext to the third device (1730) for recovery of the reduced modulus. At this time, although not shown in FIG. 17, information related to recovery of the modulus (e.g., recovery request indicator, information required for recovery, etc.) may be transmitted together.

[0255] In step S1719, the third device (1730) performs decryption on the received ciphertext. Since the received ciphertext has been converted into an encrypted state using the second public key through key switching, it can be decrypted using the second secret key held by the third device (1730). Through the decryption, the third device (1730) obtains the plaintext of the homomorphic ciphertext. Next, in step S1721, the third device (1730) generates a ciphertext. In other words, the third device (1730) generates a ciphertext by encrypting the plaintext obtained in step S1719. Accordingly, a new ciphertext encrypted using the second public key is obtained. Here, since the new ciphertext has not undergone a homomorphic operation, it can have a modulus larger than the modulus reduced by rescaling, that is, a modulus of the original size.

[0256] In step S1723, the third device (1730) performs key switching on the ciphertext. That is, the third device (1730) converts the ciphertext based on the second public key into ciphertext based on the first public key. Then, in step S1725, the third device (1730) transmits the ciphertext encrypted with the second public key to the second device (1720). In step S1727, the second device (1720) performs a homomorphic operation. Here, the homomorphic operation includes an operation that does not include rescaling. If rescaling is performed, steps S1715 to S1723 described above may be repeated. In some cases, step S1727 may be omitted. When the homomorphic operation is completed, in step S1729, the second device (1720) transmits the homomorphically operated ciphertext to the first device (1710).

[0257]

[0258] Referring to FIGS. 18A to 18C, a technique for recovering a modulus according to various embodiments (hereinafter referred to as the "modulus recovery technique") includes an initialization step (1801), an encryption and switching key generation step (1803), a homomorphic operation and key switching step (1805), a re-encryption step (1807), and a homomorphic operation and decryption step (1809). The present disclosure will now describe each step.

[0259]

[0260] (1) Initialization phase (1801)

[0261] The initialization step (1801) is an initial key generation process for using homomorphic encryption. As an initialization process for performing a modulus recovery technique according to various embodiments, the client (1810) and the second server (1820-2) generate different keys for fully homomorphic encryption. Hereinafter, the key of the client (1810) is referred to as the key of the second server (1820-2). Each key can be generated based on the aforementioned Ring LWE. The generation operation of each key can be expressed as in [Mathematical Formula 12] below.

[0262]

[0263] In [Equation 12], and are public keys, and are secret keys, and Is Values ​​randomly sampled from, and Is Values ​​sampled from, and Is Values ​​sampled from, is the maximum level It means the modulus in .

[0264] The public keys used to generate a switching key can be generated as shown in [Mathematical Formula 13] below.

[0265]

[0266] In [Equation 13], Is The public key used to generate the Is The public key used to generate the and silver and Values ​​sampled from, and Is Values ​​sampled from, and Is Values ​​sampled from, is the maximum level It means the modulus in .

[0267]

[0268] (2-1) Encryption and switching key generation step (1803)

[0269] Switching key generation is performed on the client (1810) and the second server (1820-2). The switching key of the client (1810) is the public key of the second server (1820-2). Using the client's (1810) secret key It can be obtained by encrypting. For example, the switching key generation of the client (1810) can be expressed as in [Mathematical Formula 14] below.

[0270]

[0271] In [Equation 14], is a switching key, silver The values ​​sampled from, Is The public key used to generate the Is The values ​​sampled from, is a natural number value for the switching key, and Is Values ​​sampled from, is the level where bootstrapping operation of the ciphertext is required on the first server (1820-1). It means the modulus in .

[0272] The switching key generated by the second server (1820-2) is the public key of the client (1810). Using the client's (1810) secret key For example, the generation of the switching key of the second server (1820-2) can be expressed as in [Mathematical Formula 15] below.

[0273]

[0274] In [Equation 15], is a switching key, silver The values ​​sampled from, Is The public key used to generate the Is The values ​​sampled from, is a natural number value for the switching key, and Is Values ​​sampled from, The maximum level at which homomorphic operations can be performed on the first server (1820-1) It means the modulus in .

[0275] Client (1810) is plaintext to your public key By encrypting using ciphertext For example, the encryption process can be expressed as in [Mathematical Formula 16] below.

[0276]

[0277] In [Equation 16], Silver ciphertext, is an encryption function, Is A vector or polynomial sampled from, is the public key, Silver is plain text, and are error values ​​included in the ciphertext, The maximum level at which homomorphic operations can be performed on the first server (1820-1) It means the modulus in .

[0278] Afterwards, the client (1810) sends the ciphertext and switching keys is transmitted to the first server (1820-1).

[0279]

[0280] (2-2) Homomorphic operation and key switching step (1805)

[0281] The first server (1820-1) performs operations for homomorphic operations and key switching. The first server (1820-1) receives the ciphertext from the client (1810). Homomorphic operations on can be performed. As shown in Figs. 18a to 18c, By repeatedly performing a multiplication operation while performing a homomorphic operation on , the ciphertext is It can be a low-level ciphertext such as . In this case, it is necessary to recover the modulus in order to perform an additional multiplication operation. For this purpose, the first server (1820-1) receives the switching key received from the client (1810). By using The secret key for can be switched. For example, switching for the secret key can be expressed as follows [Mathematical Formula 17].

[0282]

[0283] In [Equation 17], is a ciphertext with key switching applied, is a switching key, is the received ciphertext, stands for ciphertext for a random message.

[0284] At this time, in order to hide information about the plaintext being subjected to homomorphic operation, the first server (1820-1) sends a random message isomorphically added to the modulus The ciphertext given above Switching keys given for The key switching operation for can be expressed as follows [Mathematical Formula 18].

[0285]

[0286] In [Equation 18], is a ciphertext, and are elements of the ciphertext, is a natural number value for the switching key, is a switching key, is the level that requires bootstrapping operations It means the modulus in .

[0287] [Mathematical formula 18] is the level As a key switching in The first server (1820-1) is obtained as above. is transmitted to the second server (1820-2). Afterwards, the key-switched ciphertext is used to recover the modulus.

[0288]

[0289] (2-3) Re-encryption step (1807)

[0290] Re-encryption is performed by the second server (1820-2). The second server (1820-2) re-encrypts the ciphertext received from the first server (1820-1) using the switching key generated in the encryption and switching key generation step (1803), thereby restoring the modulus of the ciphertext. First, the decryption process can be expressed as in [Mathematical Formula 19] below.

[0291]

[0292] In [Equation 19], is the restored plaintext, is a random message, is a decryption function, means a ciphertext to which key switching is applied.

[0293] The second server (1820-2) received The secret key of the second server (1820-2) It can be decrypted using . Decryption can be expressed as in [Mathematical Formula 20] below.

[0294]

[0295] In [Equation 20], is the restored plaintext, is a random message, is a ciphertext with key switching applied, is a secret key, is the level that requires bootstrapping operations It means the modulus in .

[0296] The plaintext obtained through decryption is is as follows. Here, Since it is a random message that the second server (1820-2) does not know, the second server (1820-2) The value of is also unknown. The second server (1820-2) is plaintext Encryption for modulus It proceeds on the top. Encryption can be expressed as in [Mathematical Formula 21] below.

[0297]

[0298] In [Equation 21], is the modulus ciphertext with, is an encryption function, refers to the plaintext obtained through decryption.

[0299] The encrypted ciphertext is modulus is defined above As a ciphertext with plaintext, The modulus for the ciphertext has a recovered form. Before transmitting the ciphertext to the first server (1820-1), key switching to the secret key with which the original ciphertext was encrypted may be performed. For example, key switching may be expressed as in [Mathematical Formula 22] below.

[0300]

[0301] In [Equation 22], is a ciphertext encrypted with the key of the client (1810), is a switching key, means a ciphertext encrypted with the key of the second server (1820-2).

[0302] Modulus The ciphertext given above Switching keys given for A key switching operation can be performed. The key switching operation can be expressed as in [Mathematical Formula 23] below.

[0303]

[0304] In [Equation 23], is a ciphertext, is a switching key, and are elements of the ciphertext, is a natural number value for the switching key, The maximum level at which homomorphic operations can be performed on the first server (1820-1) It means the modulus in .

[0305] [Mathematical formula 23] is the level Since it corresponds to key switching in , Take.

[0306]

[0307] (2-4) Homomorphic operation and decryption step (1809)

[0308] The homomorphic operation and decryption step (1809) corresponds to the homomorphic operation of the first server (1820-1) and the decryption process of the client (1810). The first server (1820-1) receives the re-encrypted ciphertext transmitted from the second server (1820-2). The previously performed homomorphic operation is continued using . If additional bootstrapping is required, steps (2-2) and (2-3) above can be performed repeatedly. Finally, when the homomorphic operation is completed, the first server (1820-1) receives the ciphertext, which is the result. is sent to the client (1810).

[0309] The client (1810) receives the received ciphertext The secret key of the client (1810) can be used for decryption. Through this, the final plaintext is obtained. The final plaintext can be expressed as shown in [Mathematical Formula 24] below.

[0310]

[0311] In [Equation 24], is the final plaintext, is a decryption function, means ciphertext.

[0312] Additionally, the decryption process can be expressed as in [Mathematical Formula 25] below.

[0313]

[0314] In [Equation 25], is the final plaintext, is a ciphertext, is a secret key, refers to the modulus in which bootstrapping is performed.

[0315] Through this, the client (1810) can send its plaintext Operation value for can be received from the first server (1820-1). The first server (1820-1) receives a plaintext By performing homomorphic operations on the encrypted plaintext, Information about may not be leaked.

[0316]

[0317] This disclosure proposes a modulus recovery technique for ciphertext of homomorphic encryption that utilizes a communication environment and enables a zero-touch network environment. Previously proposed modulus recovery techniques using re-encryption at the client (1810) have the disadvantage of requiring communication between the server and the client (1810) to be maintained until the server completes all homomorphic operations. Therefore, to overcome this drawback, this disclosure proposes a technique that enables re-encryption of ciphertext on a third-party device, other than the client (1810), based on a switching key. This allows the system to operate so that the client (1810) requests a homomorphic operation on its own data from the server and receives only the resulting ciphertext, making the proposed technique applicable to zero-touch networks.

[0318] Furthermore, the present disclosure proposes a technique for recovering the modulus of a ciphertext based on the communication environment, with shorter communication delays than conventional bootstrapping operations. The proposed technique enables homomorphic encryption-based communication in high-quality communication environments.

[0319]

[0320] Below, examples of wireless device utilization to which various embodiments of the present disclosure are applied are described.

[0321] Figure 19 illustrates an example of a wireless device applicable to the present disclosure. The wireless device may be implemented in various forms depending on the use case / service (see Figure 1).

[0322] Referring to FIG. 19, the wireless device (200) corresponds to the wireless device (200) of FIG. 2 and may be composed of various elements, components, units / units, and / or modules. For example, the wireless device (200) may include a communication unit (210), a control unit (220), a memory unit (230), and additional elements (240). The communication unit may include a communication circuit (212) and a transceiver(s) (214). For example, the communication circuit (212) may include one or more processors (202) and / or one or more memories (204) of FIG. 2. For example, the transceiver(s) (214) may include one or more transceivers (206) and / or one or more antennas (208) of FIG. 2. The control unit (220) is electrically connected to the communication unit (210), the memory unit (230), and the additional elements (240) and controls the overall operations of the wireless device. For example, the control unit (220) can control the electrical / mechanical operations of the wireless device based on the program / code / command / information stored in the memory unit (230). In addition, the control unit (220) can transmit information stored in the memory unit (230) to an external device (e.g., another communication device) via a wireless / wired interface through the communication unit (210), or store information received from an external device (e.g., another communication device) via a wireless / wired interface in the memory unit (230).

[0323] The additional element (240) may be configured in various ways depending on the type of the wireless device. For example, the additional element (240) may include at least one of a power unit / battery, an input / output unit (I / O unit), a driving unit, and a computing unit. Although not limited thereto, the wireless device may be implemented in the form of a robot (Fig. 1, 100a), a vehicle (Fig. 1, 100b-1, 100b-2), an XR device (Fig. 1, 100c), a portable device (Fig. 1, 100d), a home appliance (Fig. 1, 100e), an IoT device (Fig. 1, 100f), a digital broadcasting terminal, a hologram device, a public safety device, an MTC device, a medical device, a fintech device (or a financial device), a security device, a climate / environmental device, an AI server / device (Fig. 1, 400), a base station (Fig. 1, 200), a network node, etc. Wireless devices may be mobile or stationary depending on the use / service.

[0324] In FIG. 19, various elements, components, units / parts, and / or modules within the wireless device (200) may be entirely interconnected via a wired interface, or at least some may be wirelessly connected via a communication unit (210). For example, within the wireless device (200), the control unit (220) and the communication unit (210) may be wired, and the control unit (220) and a first unit (e.g., 230, 240) may be wirelessly connected via the communication unit (210). In addition, each element, component, unit / part, and / or module within the wireless device (200) may further include one or more elements. For example, the control unit (220) may be composed of a set of one or more processors. For example, the control unit (220) may be composed of a set of a communication control processor, an application processor, an electronic control unit (ECU), a graphics processing processor, a memory control processor, etc. As another example, the memory unit (130) may be composed of RAM (Random Access Memory), DRAM (Dynamic RAM), ROM (Read Only Memory), flash memory, volatile memory, non-volatile memory, and / or a combination thereof.

[0325] Below, the implementation example of Fig. 19 is described in more detail with reference to the drawings.

[0326] Figure 20 illustrates examples of portable devices applicable to the present disclosure. Portable devices may include smartphones, smart pads, wearable devices (e.g., smartwatches, smartglasses), and portable computers (e.g., laptops). Portable devices may also be referred to as mobile stations (MS), user terminals (UT), mobile subscriber stations (MSS), subscriber stations (SS), advanced mobile stations (AMS), or wireless terminals (WT).

[0327] Referring to FIG. 20, the portable device (200) may include an antenna unit (208), a communication unit (210), a control unit (220), a memory unit (230), a power supply unit (240a), an interface unit (240b), and an input / output unit (240c). The antenna unit (208) may be configured as a part of the communication unit (210). Blocks 210 to 230 / 240a to 240c of FIG. 20 correspond to blocks 210 to 230 / 240 of FIG. 19, respectively.

[0328] The communication unit (210) can transmit and receive signals (e.g., data, control signals, etc.) with other wireless devices and base stations. The control unit (220) can control components of the mobile device (200) to perform various operations. The control unit (220) can include an AP (Application Processor). The memory unit (230) can store data / parameters / programs / codes / commands required for operating the mobile device (200). In addition, the memory unit (230) can store input / output data / information, etc. The power supply unit (240a) supplies power to the mobile device (200) and can include a wired / wireless charging circuit, a battery, etc. The interface unit (240b) can support connection between the mobile device (200) and other external devices. The interface unit (240b) can include various ports (e.g., audio input / output ports, video input / output ports) for connection with external devices. The input / output unit (240c) can input or output video information / signals, audio information / signals, data, and / or information input from a user. The input / output unit (240c) may include a camera, a microphone, a user input unit, a display unit (240d), a speaker, and / or a haptic module.

[0329] For example, in the case of data communication, the input / output unit (240c) obtains information / signals (e.g., touch, text, voice, image, video) input by the user, and the obtained information / signals can be stored in the memory unit (230). The communication unit (210) converts the information / signals stored in the memory into wireless signals, and can directly transmit the converted wireless signals to other wireless devices or to a base station. In addition, the communication unit (210) can receive wireless signals from other wireless devices or base stations, and then restore the received wireless signals to the original information / signals. The restored information / signals can be stored in the memory unit (230) and then output in various forms (e.g., text, voice, image, video, haptic) through the input / output unit (240c).

[0330] Figure 21 illustrates examples of vehicles or autonomous vehicles applicable to the present disclosure. The vehicles or autonomous vehicles may be implemented as mobile robots, cars, trains, manned / unmanned aerial vehicles (AVs), ships, etc.

[0331] Referring to FIG. 21, a vehicle or autonomous vehicle (200-1) may include an antenna unit (208-1), a communication unit (210-1), a control unit (220-1), a driving unit (240a-1), a power supply unit (240b-1), a sensor unit (240c-1), and an autonomous driving unit (240d-1). The antenna unit (208-1) may be configured as a part of the communication unit (210-1). Blocks 210-1 / 230-1 / 240a-1 to 240d-1 of FIG. 21 correspond to blocks 210 / 230 / 240 of FIG. 19, respectively.

[0332] The communication unit (210-1) can transmit and receive signals (e.g., data, control signals, etc.) with external devices such as other vehicles, base stations (e.g., base stations, roadside base stations (ROS), etc.), and servers. The control unit (220-1) can control elements of the vehicle or autonomous vehicle (200-1) to perform various operations. The control unit (220-1) may include an ECU (Electronic Control Unit). The drive unit (240a-1) can drive the vehicle or autonomous vehicle (200-1) on the ground. The drive unit (240a-1) may include an engine, a motor, a power train, wheels, brakes, a steering device, etc. The power supply unit (240b-1) supplies power to the vehicle or autonomous vehicle (200-1) and may include a wired / wireless charging circuit, a battery, etc. The sensor unit (240c-1) can obtain vehicle status, surrounding environment information, user information, etc. The sensor unit (240c-1) may include an IMU (inertial measurement unit) sensor, a collision sensor, a wheel sensor, a speed sensor, an incline sensor, a weight detection sensor, a heading sensor, a position module, a vehicle forward / backward sensor, a battery sensor, a fuel sensor, a tire sensor, a steering sensor, a temperature sensor, a humidity sensor, an ultrasonic sensor, an illuminance sensor, a pedal position sensor, etc. The autonomous driving unit (240d-1) may implement a technology for maintaining a driving lane, a technology for automatically controlling speed such as adaptive cruise control, a technology for automatically driving along a set path, a technology for automatically setting a path and driving when a destination is set, etc.

[0333] For example, the communication unit (210-1) can receive map data, traffic information data, etc. from an external server. The autonomous driving unit (240d-1) can generate an autonomous driving route and driving plan based on the acquired data. The control unit (220-1) can control the drive unit (240a-1) so that the vehicle or autonomous vehicle (200-1) moves along the autonomous driving route according to the driving plan (e.g., speed / direction control). During autonomous driving, the communication unit (210-1) can irregularly / periodically acquire the latest traffic information data from an external server and can acquire surrounding traffic information data from surrounding vehicles. In addition, during autonomous driving, the sensor unit (240c-1) can acquire vehicle status and surrounding environment information. The autonomous driving unit (240d-1) can update the autonomous driving route and driving plan based on newly acquired data / information. The communication unit (210-1) can transmit information regarding the vehicle location, autonomous driving route, driving plan, etc. to an external server. The external server can predict traffic information data in advance using AI technology, etc. based on information collected from the vehicle or autonomous vehicles, and provide the predicted traffic information data to the vehicle or autonomous vehicles. If the device (220-2) is an autonomous vehicle, it can perform the same procedure as the vehicle or autonomous vehicle (200-1). In addition, if the device (220-2) is a base station or a roadside base station, the device (220-2) can transmit data, control signals, etc. to the vehicle or autonomous vehicle (200-1) through the communication unit (210-2).

[0334] Figure 22 illustrates an example of a vehicle applicable to the present disclosure. The vehicle may also be implemented as a means of transportation, a train, an aircraft, a ship, etc. Referring to Figure 22, the vehicle (200) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a), and a position measurement unit (240b). Here, blocks 210 to 230 / 240a to 240b correspond to blocks 210 to 230 / 240 of Figure 19, respectively.

[0335] The communication unit (210) can transmit and receive signals (e.g., data, control signals, etc.) with other vehicles or external devices such as base stations. The control unit (220) can control components of the vehicle (200) to perform various operations. The memory unit (230) can store data / parameters / programs / codes / commands that support various functions of the vehicle (100). The input / output unit (240a) can output AR / VR objects based on information in the memory unit (230). The input / output unit (240a) can include a HUD. The position measurement unit (240b) can obtain position information of the vehicle (200). The position information can include absolute position information of the vehicle (200), position information within a driving line, acceleration information, position information with respect to surrounding vehicles, etc. The position measurement unit (240b) can include GPS and various sensors.

[0336] For example, the communication unit (210) of the vehicle (200) can receive map information, traffic information, etc. from an external server and store them in the memory unit (230). The location measurement unit (240b) can obtain vehicle location information through GPS and various sensors and store the information in the memory unit (230). The control unit (220) can create a virtual object based on the map information, traffic information, and vehicle location information, and the input / output unit (240a) can display the created virtual object on the vehicle window (240a-1, 240a-2). In addition, the control unit (220) can determine whether the vehicle (200) is being driven normally within the driving line based on the vehicle location information. If the vehicle (200) abnormally deviates from the driving line, the control unit (220) can display a warning on the vehicle window through the input / output unit (240a). Additionally, the control unit (220) can broadcast a warning message regarding driving abnormalities to surrounding vehicles through the communication unit (210). Depending on the situation, the control unit (220) can transmit vehicle location information and information regarding driving / vehicle abnormalities to relevant authorities through the communication unit (210).

[0337] Figure 23 illustrates examples of XR devices applicable to the present disclosure. The XR devices may be implemented as HMDs, head-up displays (HUDs) installed in vehicles, televisions, smartphones, computers, wearable devices, home appliances, digital signage, vehicles, robots, and the like.

[0338] Referring to FIG. 23, the XR device (200a) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a), a sensor unit (240b), and a power supply unit (240c). Here, blocks 210 to 230 / 240a to 240c of FIG. 23 correspond to blocks 210 to 230 / 240 of FIG. 19, respectively.

[0339] The communication unit (210) can transmit and receive signals (e.g., media data, control signals, etc.) with external devices such as other wireless devices, portable devices, or media servers. The media data can include videos, images, sounds, etc. The control unit (220) can control components of the XR device (200a) to perform various operations. For example, the control unit (220) can be configured to control and / or perform procedures such as video / image acquisition, (video / image) encoding, metadata generation and processing, etc. The memory unit (230) can store data / parameters / programs / codes / commands required for driving the XR device (200a) / generating XR objects. The input / output unit (240a) can obtain control information, data, etc. from the outside, and output the generated XR object. The input / output unit (240a) can include a camera, a microphone, a user input unit, a display unit, a speaker, and / or a haptic module. The sensor unit (240b) can obtain the XR device status, surrounding environment information, user information, etc. The sensor unit (240b) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an RGB sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, and / or a radar. The power supply unit (240c) supplies power to the XR device (200a) and may include a wired / wireless charging circuit, a battery, etc.

[0340] For example, the memory unit (230) of the XR device (200a) may include information (e.g., data, etc.) required for creating an XR object (e.g., AR / VR / MR object). The input / output unit (240a) may obtain a command to operate the XR device (200a) from the user, and the control unit (220) may operate the XR device (200a) according to the user's operating command. For example, when the user attempts to watch a movie, news, etc. through the XR device (200a), the control unit (220) may transmit content request information to another device (e.g., a mobile device (200b)) or a media server through the communication unit (230). The communication unit (230) may download / stream content such as movies and news from another device (e.g., a mobile device (200b)) or a media server to the memory unit (230). The control unit (220) controls and / or performs procedures such as video / image acquisition, (video / image) encoding, and metadata generation / processing for content, and can generate / output an XR object based on information about surrounding space or real objects acquired through the input / output unit (240a) / sensor unit (240b).

[0341] In addition, the XR device (200a) is wirelessly connected to the mobile device (200b) through the communication unit (210), and the operation of the XR device (200a) can be controlled by the mobile device (200b). For example, the mobile device (200b) can act as a controller for the XR device (200a). To this end, the XR device (200a) can obtain 3D location information of the mobile device (200b), and then generate and output an XR object corresponding to the mobile device (200b).

[0342] Figure 24 illustrates examples of robots applicable to the present disclosure. Robots can be classified into industrial, medical, household, and military types, depending on their intended use or field.

[0343] Referring to FIG. 24, the robot (200) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a), a sensor unit (240b), and a driving unit (240c). Here, blocks 210 to 230 / 240a to 240c of FIG. 24 correspond to blocks 210 to 230 / 240 of FIG. 19, respectively.

[0344] The communication unit (210) can transmit and receive signals (e.g., driving information, control signals, etc.) with external devices such as other wireless devices, other robots, or control servers. The control unit (220) can control components of the robot (200) to perform various operations. The memory unit (230) can store data / parameters / programs / codes / commands that support various functions of the robot (200). The input / output unit (240a) can obtain information from the outside of the robot (200) and output information to the outside of the robot (200). The input / output unit (240a) can include a camera, a microphone, a user input unit, a display unit, a speaker, and / or a haptic module. The sensor unit (240b) can obtain internal information of the robot (200), surrounding environment information, user information, etc. The sensor unit (240b) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, a radar, etc. The driving unit (240c) may perform various physical operations, such as moving the robot joints. In addition, the driving unit (240c) may enable the robot (200) to drive on the ground or fly in the air. The driving unit (240c) may include an actuator, a motor, wheels, brakes, propellers, etc.

[0345] Figure 25 illustrates an example of an AI device applicable to the present disclosure.

[0346] AI devices can be implemented as fixed or mobile devices, such as TVs, projectors, smartphones, PCs, laptops, digital broadcasting terminals, tablet PCs, wearable devices, set-top boxes (STBs), radios, washing machines, refrigerators, digital signage, robots, and vehicles.

[0347] Referring to FIG. 25, the AI ​​device (200) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a / 240b), a learning processor unit (240c), and a sensor unit (240d). Blocks 210 to 230 / 240a to 240d of FIG. 25 correspond to blocks 210 to 230 / 140 of FIG. 19, respectively.

[0348] The communication unit (210) can transmit and receive wired and wireless signals (e.g., sensor information, user input, learning models, control signals, etc.) with external devices such as other AI devices (e.g., 100a to 100f, 120 of FIG. 1) or AI servers (e.g., 100g of FIG. 1) using wired and wireless communication technology. To this end, the communication unit (210) can transmit information within the memory unit (230) to the external device or transfer a signal received from the external device to the memory unit (230).

[0349] The control unit (220) may determine at least one executable operation of the AI ​​device (200) based on information determined or generated using a data analysis algorithm or a machine learning algorithm. In addition, the control unit (220) may control components of the AI ​​device (200) to perform the determined operation. For example, the control unit (220) may request, search, receive, or utilize data from the learning processor unit (240c) or the memory unit (230), and may control components of the AI ​​device (200) to perform at least one executable operation, a predicted operation, or an operation determined to be desirable. In addition, the control unit (220) may collect history information including the operation contents of the AI ​​device (200) or user feedback on the operation, and store the collected history information in the memory unit (230) or the learning processor unit (240c), or transmit the collected history information to an external device such as an AI server (FIG. 1, 100g). The collected history information may be used to update a learning model.

[0350] The memory unit (230) can store data that supports various functions of the AI ​​device (200). For example, the memory unit (230) can store data obtained from the input unit (240a), data obtained from the communication unit (210), output data of the learning processor unit (240c), and data obtained from the sensing unit (140). In addition, the memory unit (230) can store control information and / or software codes necessary for the operation / execution of the control unit (220).

[0351] The input unit (240a) can obtain various types of data from the outside of the AI ​​device (200). For example, the input unit (220) can obtain learning data for model learning, input data to which the learning model will be applied, etc. The input unit (240a) may include a camera, a microphone, and / or a user input unit. The output unit (240b) may generate output related to vision, hearing, or touch. The output unit (240b) may include a display unit, a speaker, and / or a haptic module, etc. The sensing unit (140d) can obtain at least one of internal information of the AI ​​device (200), information about the surrounding environment of the AI ​​device (200), and user information using various sensors. The sensing unit (140d) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an RGB sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, and / or a radar, etc.

[0352] The learning processor unit (240c) can train a model composed of an artificial neural network using learning data. The learning processor unit (240c) can perform AI processing together with the learning processor unit of the AI ​​server (Fig. 1, 100g). The learning processor unit (240c) can process information received from an external device via the communication unit (210) and / or information stored in the memory unit (230). In addition, the output value of the learning processor unit (240c) can be transmitted to an external device via the communication unit (210) and / or stored in the memory unit (230).

[0353]

[0354] The proposed methods described above can be implemented independently, but they can also be implemented as a combination (or merge) of some of the proposed methods. Rules can be defined so that the base station notifies the terminal of the applicability of the proposed methods (or information about the rules of the proposed methods) through a predefined signal (e.g., a physical layer signal or a higher layer signal).

[0355] The present disclosure may be embodied in other specific forms without departing from the technical ideas and essential features described herein. Therefore, the above detailed description should not be construed as limiting in all respects but rather as illustrative. The scope of the present disclosure should be determined by a reasonable interpretation of the appended claims, and all modifications within the equivalent scope of the present disclosure are intended to be included within the scope of the present disclosure. Furthermore, claims that are not explicitly cited in the claims may be combined to form an embodiment or incorporated into a new claim through a post-filing amendment.

[0356] The embodiments described herein may be applied to various wireless access systems. Examples of such wireless access systems include the 3rd Generation Partnership Project (3GPP) or 3GPP2 systems.

[0357] The embodiments described herein can be applied not only to the various wireless access systems described above, but also to all technical fields utilizing these various wireless access systems. Furthermore, the proposed method can be applied to mmWave and THz communication systems utilizing ultra-high frequency bands.

[0358] Additionally, the embodiments can be applied to various applications such as autonomous vehicles and drones.

Claims

1. A method performed by a first device in a wireless communication system, Steps to perform initial connection procedures; Step of transmitting capability information; A step for performing signaling for service-related settings; and A step of transmitting an encrypted ciphertext and a switching key for key switching of the ciphertext to a second device using a homomorphic encryption based on the above service, The above switching key is a key for converting a ciphertext encrypted with the first public key of the first device into a ciphertext encrypted with the second public key of the third device, and is used to recover the modulus.

2. In claim 1, A method further comprising the step of generating a first secret key, the first public key and the switching key for the homomorphic encryption.

3. In claim 1, The above modulus is recovered through decryption, encryption, and key switching by the third device.

4. In a method performed by a second device in a wireless communication system, A step of receiving a first ciphertext encrypted with a first public key of the first device and a switching key for key switching from the first device; A step of generating a second ciphertext by performing a homomorphic operation including rescaling on the first ciphertext; A step of converting the second ciphertext into a third ciphertext encrypted with the second public key of the third device using the switching key; A step of transmitting the third ciphertext to the third device; A method comprising the step of receiving a fourth ciphertext having a modulus recovered from the third device.

5. In claim 4, A method further comprising the step of transmitting the fourth ciphertext to the first device.

6. In claim 4, A step of generating a fifth ciphertext by performing an additional homomorphic operation on the fourth ciphertext; A method further comprising the step of transmitting the fifth ciphertext to the first device.

7. In claim 4, A method in which the fourth ciphertext includes a ciphertext encrypted with the first public key generated through decryption, encryption, and key switching by the third device.

8. In a method performed by a third device in a wireless communication system, An initialization procedure with a first device using a first public key, comprising: obtaining a switching key for converting a ciphertext encrypted with a second public key of the third device into a ciphertext encrypted with the first public key of the first device; A step of receiving a first ciphertext from the first device, and receiving a third ciphertext encrypted with the second public key, which includes the same plaintext as the second ciphertext, from a second device that generates a second ciphertext through a homomorphic operation on the first ciphertext; A step of generating a fourth ciphertext having a modulus recovered from the third ciphertext using the switching key and the second public key; A method comprising the step of transmitting the fourth ciphertext to the second device.

9. In claim 8, The step of generating the above fourth ciphertext is: A step of obtaining the plaintext by decrypting the third ciphertext; A step of generating a fourth ciphertext by encrypting the above plaintext with the above second public key; A method comprising the step of generating the fourth ciphertext encrypted with the first public key using the second ciphertext using the switching key.

10. In claim 8, A method wherein the first ciphertext comprises a ciphertext having a reduced modulus by a homomorphic operation including rescaling.

11. In a first device in a wireless communication system, Transmitter and receiver; and comprising a processor coupled to the above transceiver, The above processor, Perform the initial connection procedure, Transmit capability information, Performs signaling for service-related settings, It is configured to transmit to a second device an encrypted ciphertext using homomorphic encryption based on the above service and a switching key for key switching of the ciphertext, The switching key is a first device used to recover the modulus, which is a key for converting a ciphertext encrypted with the first public key of the first device into a ciphertext encrypted with the second public key of the third device.

12. In communication devices, At least one processor; At least one computer memory connected to said at least one processor and storing instructions that direct operations when executed by said at least one processor, The above actions are, Steps to perform initial connection procedures; Step of transmitting capability information; A step for performing signaling for service-related settings; and A step of transmitting an encrypted ciphertext using homomorphic encryption based on the above service and a switching key for key switching of the ciphertext, The above switching key is a communication device used to recover the modulus, which is a key for converting a ciphertext encrypted with the first public key of the first device into a ciphertext encrypted with the second public key.

13. In a non-transitory computer-readable medium storing at least one instruction, comprising at least one instruction executable by the processor, At least one of the above commands causes the device to: Perform the initial connection procedure, Transmit capability information, Performs signaling for service-related settings, Instructs to transmit a ciphertext encrypted using homomorphic encryption based on the above service and a switching key for key switching of the ciphertext, The above switching key is a computer-readable medium used to recover the modulus, as a key for converting a ciphertext encrypted with the first public key of the first device into a ciphertext encrypted with the second public key.

Citation Information

Patent Citations

  • Device for gas supply

    KR1020230149373A

  • Secure distributed key generation for multiparty homomorphic encryption

    US20210399874A1

  • SIMD interactive comparison using garbled circuits and interactive bootstrapping for homomorphic encryption

    US20230361986A1

  • KR20220004201A

  • KR20230087377A