Method and apparatus for operating a wireless device

A quantum-resistant protection method for long-term subscriber identifiers in cellular networks is implemented using USIM to address vulnerabilities from quantum computers, ensuring secure communication and privacy.

WO2026012948A1PCT designated stage Publication Date: 2026-01-15KONINKLIJKE PHILIPS NV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/069215
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-11-15
Filing Date
2025-07-04
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

Current cellular networks are vulnerable to quantum computer attacks due to non-quantum-resistant cryptographic schemes used for protecting long-term subscriber identifiers, leading to potential privacy issues and security breaches.

Method used

Implementing a quantum-resistant protection method in user equipment (UE) using a Universal Subscriber Identity Module (USIM) to verify and protect long-term subscriber identifiers with quantum-resistant public-keys, employing techniques such as key encapsulation and encryption to ensure secure communication.

Benefits of technology

Enhances the security of long-term subscriber identifiers against quantum computer attacks, providing robust privacy protection and secure communication in cellular networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025069215_15012026_PF_FP_ABST
    Figure EP2025069215_15012026_PF_FP_ABST
Patent Text Reader

Abstract

This invention describes a method for quantum-resistant protection of the long-term subscriber's identifier that may be implemented in a user equipment (UE) wherein the UE comprises a mobile equipment (ME) and a USIM and the method comprises: storing, in the USIM, a first value enabling the verification of a quantum-resistant public-key, obtaining, by the UE, part of the quantum-resistant public-key, verifying, by the UE, the legitimacy of the obtained part of the quantum-resistant public-key, and upon successful verification, further performing by the UE: obtaining a quantum-resistant encapsulation key and using the quantum-resistant encapsulation key to protect the long-term subscriber's identifier by means of the quantum-resistant public key.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD AND APPARATUS FOR OPERATING A WIRELESS DEVICE

[0002] FIELD OF THE INVENTION

[0003] This invention relates to a method, apparatus, and system for operating a wireless device such as a user equipment capable of protection, e.g., quantum-resistant protection, of longterm subscriber's identifiers in a wireless system such as a cellular system, a Wi-Fi network or the like.

[0004] BACKGROUND OF THE INVENTION

[0005] In conventional cellular networks, a primary station serves a plurality of secondary stations located within a cell served by this primary station. Wireless communication from the primary station towards each secondary station is done on downlink channels. Conversely, wireless communication from each secondary towards the primary station is done on uplink channels. The wireless communication can include data traffic (sometimes referred to User Data), and control information (also referred sometimes as signalling). This control information typically comprises information to assist the primary station and / or the secondary station to exchange data traffic (e.g. resource allocation / requests, physical transmission parameters, information on the state of the respective stations).

[0006] In the context of cellular networks as standardized by 3GPP, the primary station is referred to a base station, or a gNodeB (or gNB) in 5G (NR) or an eNodeB (or eNB) in 4G (LTE). The eNB / gNB is part of the Radio Access Network RAN, which interfaces to functions in the Core Network (CN). In the same context, the secondary station corresponds to a mobile station, or a User Equipment (or a UE) in 4G / 5G, which is a wireless client device or a specific role played by such device. The term "node" is also used to denote either a UE or a gNB / eNB.

[0007] Additionally, for example, in the case of PC5 interface or Sidelink communication, it is possible to have Direct communication between secondary stations, here UEs. It is then also possible for UEs to operate as Relays to allow for example out of coverage UEs to get an inter-mediate (or indirect) connection to the eNB or gNB. To be able to work as a relay, a UE may use discovery messages to establish new connections with other UEs.

[0008] Therefore, the role of a relay node has been introduced in 3GPP. This relay node is a wireless communication station that includes functionalities for relaying communication between a primary station, e.g. a gNB and a secondary station, e.g. a UE. This relay function for example allows to extend the coverage of a cell to an out-of-coverage (OoC) secondary station. This relay node may be a mobile station or could be a different type of device. In the specifications for 4G, the Proximity Services (ProSe) functions are defined inter alia in TS 23.303, and TS 24.334 to enable - amongst others -connectivity for the cellular User Equipment (UE) that is temporarily not in coverage of the cellular network base station (eNB) serving the cell. This particular function is called ProSe UE-to-network relay, or Relay UE for short. The Relay UE relays application and network traffic in two directions between the OoC UE and the eNB. The local communication between the Relay UE and the OoC UE is called device-to-device (D2D) communication or Sidelink (also known as PC5) communication in TS 23.303 and TS 24.334. Once the relaying relation is established, the OoC-UE is, e.g., IP-connected via the Relay UE and acts in a role of "Remote UE". This situation means the Remote UE has an indirect network connection to selected functions of the Core Network as opposed to a direct network connection to all Core Network functions that is the normal case.

[0009] Further, it has been introduced the role of a UE-to-UE relay node, i.e., a relay node relaying the communication between two UE devices. The relay node relays the communications between UE devices. UEs may connect to the core network through a base station when in-coverage. In such relay scenarios, the relay devices may receive and store some information for some time before forwarding it towards the target device. This information that may be stored and forwarded may be discovery messages received from a source UE whereby the relay UE may release them at some point of time later. This information that may be stored and forwarded may be a System Information Block (SIB) that may contain a timestamp.

[0010] Furthermore, cellular networks are evolving to enable more mobile access devices such as satellites, unmanned aerial vehicles, buses or trains that are capable of storing data for some time before forwarding it further. An example relates to a satellite that receives and stores certain data when it is close to a terrestrial gateway and only releases it when the receiving party becomes in coverage, or vice versa. Such mobile access devices may work in a transparent manner or in a regenerative manner. In a transparent mode, the mobile access device acts as a reflector / smart repeater that retransmits the communication sent by, e.g., a gateway, e.g., a Non-Terrestrial Network gateway, towards a UE. In a regenerative mode, the mobile access device works as a base station and is able to setup a connection with a UE. In store and forward mode, the mobile access device may be able to cache same data obtained from the UE or NTN gateway and transmit it when it is within communication range of the receiver.

[0011] Current cellular systems protect, during the UE registration phase, the long-term subscriber's identifier using the public key of the home Public Land Mobile Network (PLMN). However, current public key cryptographic schemes used to protect the long-term subscriber's identifier are not quantum-resistant, making it prone to attacks using a quantum computer such as the harvest and decrypt attack. Furthermore, some parameters exchanged may not be protected leading to potential privacy issues. Similarly, the protection of the long-term subscriber's identifier may fail sometimes, leading in a similar manner, to potential privacy issues.

[0012] Post-quantum cryptography (PQC), also referred to as quantum-proof, quantum-safe, or quantum-resistant, is the development of cryptographic algorithms (usually public-key algorithms) that are expected to be secure against a cryptanalytic attack by a quantum computer. Most widely used public-key algorithms rely on the difficulty of one of three mathematical problems: the integer factorization problem, the discrete logarithm problem or the elliptic-curve discrete logarithm problem. However, these problems could be easily solved on a sufficiently powerful quantum computer running for example Shor's algorithm or possibly alternatives.

[0013] SUMMARY OF THE INVENTION

[0014] An aim of the invention is to address above problem providing a quantum resistant solution for the protection of long-term subscriber's identifiers.

[0015] In accordance with an aspect of the invention, it is proposed a method for protecting a longterm subscriber's identifier implemented in a user equipment (UE) wherein the UE comprises a Universal Subscriber Identity Module, USIM, and the method comprises: storing, in the USIM, a first value enabling verifying a first quantum-resistant public-key, obtaining, by the UE, at least part of the first quantum-resistant public-key, performing, by the UE, a legitimacy check of the obtained part of the first quantumresistant public-key, and if the legitimacy check is successful, performing by the UE: o obtaining a first quantum-resistant encapsulation key and o protecting the long-term subscriber's identifier using the first quantum-resistant encapsulation key, resulting in a protected long-term subscriber's identifier.

[0016] In accordance with a second aspect of the invention, it is proposed apparatus configured for protection of a long-term subscriber's identifier, wherein the apparatus comprises a Universal Subscriber Identity Module, USIM, a transmitter, a receiver, a controller, a storage unit including instructions, which when executed, cause the apparatus to: store, in the USIM, a first value enabling verifying a first quantum-resistant public-key, obtain at least part of the first quantum-resistant public-key, perform a legitimacy check of the obtained part of the first quantum-resistant publickey, and upon determination that the legitimacy check is successful, the apparatus is configured to: obtain a first quantum-resistant encapsulation key and protect the long-term subscriber's identifier using the first quantum-resistant encapsulation key, resulting in a protected long-term subscriber's identifier.

[0017] In accordance with a variant of the first aspect or the second aspect of the invention, the first value comprises multiple components, each component obtained as a function of a part of the first quantum-resistant public-key.

[0018] In another variant, the first value is a public key for digital signature verification.

[0019] In another variant, the method comprises storing, by the UE, in the USIM a URL wherein the URL indicates where the first quantum-resistant public-key can be retrieved from. Optionally, the performing the legitimacy check includes computing by the UE a function of the obtained part of the first quantum-resistant public key and comparing it with the stored first value. As an example, the performing of the legitimacy check includes verifying by the UE a digital signature attached to the obtained part of the first quantum-resistant public key.

[0020] In a first given variant, the method comprises: combining, by the UE, the first quantum-resistant encapsulation key with one or more second keys by means of a key derivation function to obtain an encryption key Ke and an integrity key Ki, using the encryption key Ke to encrypt the long-term subscriber's identifier by means of a symmetric encryption algorithm obtaining an encrypted long-term subscriber's identifier, using the integrity key Ki to obtain a message authentication code of the encrypted longterm subscriber's identifier.

[0021] In a second given variant, the method comprises: using, by the UE, the first quantum-resistant encapsulation key to protect the long-term subscriber's identifier, thereby obtaining a first subscriber's concealed identifier, using, by the UE, a second key to protect the first subscriber's concealed identifier, thereby obtaining a second subscriber's concealed identifier.

[0022] In a third given variant, the method comprises: using, by the UE, a second key to protect the long-term subscriber's identifier, thereby obtaining a first subscriber's concealed identifier, and using, by the UE, the first quantum-resistant encapsulation key to protect the first subscriber's concealed identifier, thereby obtaining a second subscriber's concealed identifier.

[0023] In an example that can be combined with the first, second or third given variants, the protected long-term subscriber's identifier is derived from the encrypted long-term subscriber's identifier or the second subscriber's concealed identifier and, wherein the method comprises transmitting, by the UE, the protected long-term subscriber's identifier including the identities of the public-keys used in the encryption and / or a protection profile identifier.

[0024] In another variant, the method comprises indicating, by the UE, quantum resistant capabilities and / or protection profiles of the UE and / or a mobile equipment, ME associated with the UE and / or the USIM in an initial registration request message.

[0025] In another variant, the method comprises a mobile equipment, ME, in the UE indicating its quantum resistant capabilities to the USIM. Alternatively, the method comprises the USIM indicating its quantum resistant capabilities to a mobile equipment, ME.

[0026] In another variant, the method comprises storing, by the UE, a configuration / policy determining the context / circumstances to protect the long-term subscriber's identifier by means of a QR algorithm and / or a non-QR algorithm.

[0027] In another variant, the method comprises downgrading, by the UE, the security level to protect the long-term subscriber's identifier by means of a non-quantum-resistant public key or protection scheme in case of emergency services.

[0028] In another variant, the method comprises downgrading, by the UE, the security level to encrypt the long-term subscriber's identifier by means of a non-quantum-resistant public key in case of interworking with a legacy network technology.

[0029] In another variant, the first quantum-resistant public-key is associated with metadata, the metadata comprising one or more of:

[0030] - a lifetime of the first quantum-resistant public-key;

[0031] - an allowed or disallowed usage in hybrid mode or standalone mode;

[0032] - an allowed or disallowed usage in protection scheme identifiers; and

[0033] - a public key type.

[0034] In another variant, the protecting, by the UE, the long-term subscriber's identifier using the first quantum-resistant public key comprises applying a domain separator field. Optionally, the method comprises transmitting, by the UE, the protected long-term subscriber's identifier with one or more fields of the domain separator field. Optionally, the domain separator field includes one or more of: - Device specific identifiers,

[0035] - User-specific identifiers,

[0036] - Environmental context,

[0037] - Session specific parameters, and

[0038] - Application level metadata.

[0039] In a variant of the first given variant and the previous variant, the method comprises signalling, by the UE, the order in which the first quantum-resistant encapsulation key and the one or more second keys are combined and / or used.

[0040] In another variant, the UE is configured with a policy determining the usage of a protection scheme based on a UE's context, wherein the protection scheme is one of a hybrid quantum-resistant and non-quantum resistant protection scheme, a hybrid quantum-resistant and quantum resistant protection scheme, a quantum-resistant protection scheme, a non-quantum resistant protection scheme; and the UE's context comprises one or more of a roaming status and a serving network identifier.

[0041] In another variant, the first quantum-resistant public-key is associated with a first network, and wherein the protecting the long-term subscriber's identifier by means of the first quantum-resistant public key is performed according to the policy of the first network.

[0042] In another variant, the protecting, by the UE, the long-term subscriber's identifier comprises protecting an unprotected home network identifier, such as a mobile network code and / or a mobile country code, and the long-term subscriber's identifier protected with a second network public key associated to a second network.

[0043] In another variant, the method comprises indicating, by the UE, the protection by means of a protection scheme identifier.

[0044] In another variant, the protecting the long-term subscriber's using the first quantum resistant public key comprises obtaining a multi-target encryption key as the result of applying a cryptographic function to a first input derived from a first quantum-resistant encapsulation key and a second input derived from a second encryption key, wherein the first quantumresistant encapsulation key is associated with a first network and wherein the second encryption key is associated with a second network; protecting the long-term subscriber's identifier using the multi-target encryption key. Optionally, the first network is a serving PLMN and the second network is a home PLMN.

[0045] In another variant, the method further comprises receiving, by the UE, a configuration update from a network, the configuration update comprising parameters associated with the protection of the long-term subscriber's identifier, performing, by the UE, based on the configuration update, the security procedure to protect the longterm subscriber's identifier, resulting in a protected long-term subscriber's identifier; determining, by the UE, whether the computation of the protected long-term subscriber's identifier was successful; and sending, by the UE, a response message to the first network, containing an acknowledgment of receipt in case of success, or failure message in case of failure.

[0046] In another variant, the method further comprises, in case of failing to protect the long-term subscriber's identifier, including, by the UE, an error code associated with the protected long term subscriber's identifier computation failure and a last used identifier in the registration request and / or in the identity response message, sent to the access management function, wherein the last used identifier is one of a globally unique temporary identifier and a Subscription Concealed Identifier, SUCL

[0047] In another variant, in case of failing to protect the long-term subscriber's identifier, the method comprises the following: search and select, by the UE, an access device associated with a network generation which does not require concealing the long term subscriber's identifier using the scheme or method subject to failure; attach or register, by the UE, to the network and send a message, indicating the error code associated with concealed long term identifier computation failure and / or parameters for replay protection, to request a parameters update; and receive updated parameters associated with concealed long term identifier computation.

[0048] In another variant, the method comprises a UE configured to perform, in case of failing to protect the long-term subscriber's identifier, a registration procedure, wherein the UE identifier is set to one of the following: subscriber concealed identifier computed using a null protection scheme; or subscriber permanent identifier protected using a different cryptographic algorithm / scheme; or the last used globally unique temporary identifier; or the last used subscription concealed identifier, SUCI; or the permanent equipment identifier.

[0049] In accordance with another aspect of the invention is proposed a computer program for quantum-resistant protection of the long-term subscriber's identifier, wherein the program comprises instructions implementing the apparatus of the second of this invention and their variants.

[0050] It shall be understood that a preferred embodiment of the invention can also be any combination of the dependent claims or above embodiments with the respective independent claim.

[0051] These and other aspects of the invention will be apparent from and elucidated with reference to the embodiments described hereinafter.

[0052] BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In the following drawings:

[0054] Fig. 1 schematically represents the overall cellular system including UEs, RAN, and core network;

[0055] Fig. 2 is a diagram representing a structure of a subscription concealed key;

[0056] Fig. 3 is a table representing the sizes of keys and ciphertexts; and

[0057] Fig. 4 is a table representing the size of keys and cipher texts for McEliece cryptographic procedures.

[0058] DETAILED DESCRIPTION OF EMBODIMENTS

[0059] Embodiments of the present invention are now described based on a cellular communication network environment, such as 5G. However, the present invention may also be used in connection with other wireless technologies, and in particular to the connection setup of devices trying to access a wireless network. A typical example is a cellular network, for example a 5G network, possibly including some relay nodes. These relay nodes may be implemented by UEs, such as Sidelink compatible UEs which can operate as relay nodes, or by other types of repeaters.

[0060] Throughout the present disclosure, the abbreviation "gNB" (5G terminology) or "BS" (base station) or the term "access device" is intended to mean a wireless access device such as a cellular base station or a WiFi access point or a ultrawide band (UWB) personal area network (PAN) coordinator. The gNB may consist of a centralized control plane unit (gNB-CU-CP), multiple centralized user plane units (gNB-CU-UPs) and / or multiple distributed units (gNB-DUs). The gNB is part of a radio access network (RAN), which provides an interface to functions in the core network (CN). The RAN is part of a wireless communication network. It implements a radio access technology (RAT). Conceptually, it resides between a communication device such as a mobile phone, a computer, or any remotely controlled machine and provides connection with its CN. The CN is the communication network's core part, which offers numerous services to customers who are interconnected via the RAN. More specifically, it directs communication streams over the communication network and possibly other networks.

[0061] Furthermore, the terms "base station" (BS) and "network" may be used as synonyms in this disclosure. This means for example that when it is written that the "network" performs a certain operation it may be performed by a CN function of a wireless communication network, or by one or more base stations that are part of such a wireless communication network, and vice versa. It can also mean that part of the functionality is performed by a CN function of the wireless communication network and part of the functionality by the base station.

[0062] Section: quantum-resistant protection of the long-term identifier

[0063] In the 5G system, the globally unique 5G subscription identifier is called SUPI, as defined in 3GPP TS 23.501. The SUPI is privacy protected over-the-air by using the Subscription Concealed Identifier (SUCI) which contains the concealed SUPI, see 3GPP TS 33.501, Clause 6.12. The protection schemes are the ones specified in 3GPP TS 33.501, Annex C, or the ones specified by the HPLMN. The UE constructs a scheme input from the subscription identifier part of the SUPI. The scheme output is contained in the SUCI, as visualized in Fig. 2 (corresponding to Fig 2.2B-1 from 3GPP TS 23.003). The various parts of the SUCI are described in detail in 3GPP TS 23.003 clause 2.2. All parts of the SUCI, apart from Scheme output when using Non-Null protection scheme, are sent in the clear, i.e., without encryption.

[0064] Quantum resistant (QR) algorithms are being standardized by standard development organizations (SDOs) such as NIST. QR algorithms may be also referred to as post-quantum (resistant) algorithms, i.e., PQ algorithms, or quantum-safe algorithms, i.e., QS algorithms. For instance, FIPS 203 is the upcoming Module-Lattice-Based Key-Encapsulation Mechanism Standard that provides algorithms for key generation, encapsulation, and decapsulation. Similarly, IETF is doing work to apply said quantum resistant algorithms to protocols such as TLS that are used in cellular networks.

[0065] The 5G system may protect the SUPI) by encrypting it with the public key of the home network by means of ECIES (Elliptic Curve Integrated Encryption Scheme). A simplified description of this scheme to encrypt a message m is as follows:

[0066] Step 1: the UE generates a random number r in [l,n-l] and computes the

[0067] ECC_public_key =rG; Step 2: the UE derives a shared secret: S=Px, where P=(Px,Py)=r*KB (and P*O), i.e., KB is the public key and the shared secret equals the first coordinate of P;

[0068] Step 3: the UE uses a key derivation function (KDF) to derive symmetric encryption keys and MAC keys: Ke | Ki = KDF(S | SI) where SI is a given metadata;

[0069] Step 4: the UE encrypts the message m by using a symmetric encryption algorithm E() that takes as input the encryption key Ke and the message m: c=E(Ke, m);

[0070] Step 5: the UE computes the tag of the encrypted message and S2: d=MAC(Ki;c |S2) by using an algorithm MAC() to obtain the message authentication code d where MAC() takes as input the integrity key and the concatenation of c and some metadata;

[0071] Step 6: UE outputs ECC_public_key | c | d

[0072] TS 31.102 defines further methods for the protection of the SUPI, in particular, in Clause 4.4.11.8 the file EFSUCI_Calc_lnfo is defined that includes the information required to perform the protection of the SUPL This clause indicates when the file is required and / or available to the ME:

[0073] Where Service n° 124 refers to the Subscription identifier privacy support and Service n° 125 refers to SUCI calculation by the USIM. Service nl25 is only considered if Service n° 124 is available.

[0074] QR algorithms such as QR key encapsulation schemes are usually bulkier, i.e., have longer public keys and longer cipher texts. The key sizes of FIPS 203 are shown in Fig. 3, where the ciphertext size goes from 768 bytes to 1568 bytes depending on the security level. Other NIST PQC candidates that have much longer history (i.e., are known for a much longer time) include McElicee https: / / classic.mceliece.org / index.html that is also featured by the shortest ciphertext as shown in Fig. 4 and may be standardized by ISO. This short ciphertext comes at the price of long public keys (from 200 KB up to 1.3 MB).

[0075] Finally, current USIMs may have a limited amount of memory, typically, from 8 KB to 256 KBs, and thus cannot store long keys Thus, the introduction of QR algorithms may require changes in the EFSUCI_Calc_lnfo file (as defined in TS 31.102). Thus, the following embodiments are proposed.

[0076] In an embodiment of the invention that may be combined with other embodiments or used independently, the USIM stores a function (e.g., the hash) of the public key, and the mobile equipment (ME) may store the public key. The public key of the operator may be available at a well- known location, e.g., at a server reachable at a given URL, where the URL may also be stored in and / or be accessible by the USIM and / or ME. The URL and the function of the public key may be stored in the USIM at configuration time, e.g., at a factory. The ME may be adapted to retrieve the function of the public key and the URL where public key can be obtained, and get said public key. The ME may be in charge of performing the encryption of a long term cellular identifier (e.g., SUPI) using the public key, and before doing that, the ME may need to retrieve the public key (from the server or local storage), compute the same function (e.g., the hash) of the public key, and checks that the function of the retrieved public key equals the function of the public key obtained from the USIM. Alternatively, the ME may send the function of the retrieved public key to the USIM for verification, the USIM may need to check that the outputs of the function (e.g., the hash) match, and indicates the match (or mismatch) to the ME. If the indication is positive, the ME may use the public key to compute the protected SUPI. It is to be noted that schemes such as FIPS 203 may have a public key that is short enough to still fit in a USIM. However, other schemes such as McEliecee featuring a shorter ciphertext have a much bigger public key that is very unlikely to fit in a USIM, but could easily fit in the ME.

[0077] Note that there are multiple options for the choice of the function F of the public key, e.g., a first value equal to a function of a part of a quantum-resistant public-key may be such that the first value equals the part of the quantum-resistant public-key when the function b=F(a) is the identity function, i.e, b=a. This definition allows storing the hash of the public-key when the function F is a hash function or store the public-key itself when the function F is the identity function , i.e., b=F(a) such that b=a.

[0078] In a further embodiment that may be combined with other embodiments or used independently, the USIM stores a function and / or value that allows for the verification of the public key or part of it. For instance, it may be a public-key of the HPLMN that allows verifying a digital signature received from the HPLMN where the digital signature is computed over a received / requested / obtained public-key where this public key may be a QR public key. Note that even if this invention focuses on QR public keys to ensure that the long-term subscriber's identifier is well protected (in view of, e.g., harvest and decrypt attacks) at a time when a quantum computer does not exist yet, the digital signature does not need to be quantum resistant as long as the quantum computer does not exist. The reason is that the verification of the QR public key by the UE happens at the current time. Note that in this embodiment, the UE (ME and / or USIM) may need to know the hosting location (e.g., URL) from which the public key of the HPLMN can be retrieved.

[0079] In a further embodiment that may be combined with other embodiments or used independently, the obtained (QR) public key is associated to certain metadata that may include one or more of e.g., the lifetime of the public key, the purpose (e.g., hybrid encryption or not), the public key identifier, the type of public key, URL from which it can be retrieved, etc. This metadata may be received / retrieved with the public key or may be stored in the USIM or ME. The verification check that may be done by means of the stored value in the USIM may require computing a function over the public key and metadata so that the metadata is also verified. For instance, the stored value in the USIM may be the hash function H() of H(public key | metadata) where | indicates concatenation, and the same operation may be repeated when the public key is retrieved / received, the USIM / ME may perform the same operation / function, and compare it with the stored value (for verification purposes).

[0080] In a further embodiment of the invention that may be combined with other embodiments or used independently, the metadata may also be used to check whether the public key, in particular QR public key, may be used for certain purposes, e.g., hybrid encryption, or at a given time (by checking the lifetime), etc. This may be advantageous because the higher bandwidth needs may not be required always, but only in those situations of higher risk.

[0081] In a further embodiment of the invention that may be combined with other embodiments or used independently, the USIM may store multiple values that are derived from different parts of the public key, such as the matrix A and the vector t in lines 5 and 18 of Algorithm 13 in FIPS 203. The ME may retrieve the public key from a server or local storage and may send the corresponding parts to the USIM for verification. For instance, matrix A has dimensions k x k and each entry corresponds to a polynomial with 256 coefficients in Rq. A value may be derived by computing a function (hash) of the concatenation of the 256 coefficients of a polynomial. The USIM computes the same function (e.g., the hash) of each part and compares it with the stored value. If all the values match, the USIM confirms the validity of the public key to the ME. Otherwise, the USIM rejects the public key and aborts the encryption / encapsulation process. Upon verification, the USIM may use each of the received components (entries of A or t) to perform the computations in the USIM. This embodiment may provide more security and robustness against attacks that try to tamper with the public key or forge a fake one. For example, an attacker may try to modify some elements of the matrix A or the vector t, but this would result in a mismatch with the stored values in the USIM. Alternatively, an attacker may try to generate a new public key that has the same function values as the original one, but this would require finding a collision for the function, which is assumed to be hard for a secure hash function. Therefore, storing multiple values that are linked to different parts of the public key may increase the difficulty for an adversary to compromise the encryption scheme. Additionally, the USIM may perform operations internally with each part of the public key, using its own secret key, without revealing any information to the ME or the attacker. For example, the USIM can use the matrix A and the vector t to generate a shared secret with the sender, as specified in FIPS 203, that can be used to protect the SUPI as per other embodiments. By performing these operations inside the USIM, the USIM can ensure the confidentiality and integrity of the data and prevent any leakage or modification of the secret key or the public key components.

[0082] In another embodiment of the invention that may be combined with other embodiments or used independently, the USIM may include a service that may indicate that the protection of the long-term subscriber's identity is performed by the USIM and ME.

[0083] In another embodiment of the invention that may be combined with other embodiments or used independently, the hybrid scheme to protect the SUPI may work as follows: Elliptic curve part: performing the first two steps of ECIES encryption, i.e.:

[0084] Step 1: the UE generates a random number r in [l,n-l] and calculates ECC public key component ECC_public_key =rG;

[0085] Step 2: the UE derives a shared secret: S=Px, where P=(Px,Py)=r*KB (and P*O)

[0086] FIPS 203 part (in general, QR part):

[0087] Step 3: UE obtains a key K and a ciphertext CT using the public key component FIPS203_public_key following algorithm 20 in FIPS 203;

[0088] Hybrid part

[0089] Step 4: UE combines K and S to obtain one or more shared secrets

[0090] Ke | Ki = KDF(S | K | additional data_l) where KDF is a key derivation function and additional_data_l may indicate the usage of a specific KDF or a hybrid scheme or some conditions for the usage of the derived keys. From this point of view, additional data_l acts as domain separator in the combiner function KDF. Additional data_l may include, but is not limited to, e.g., a protection scheme identifier that identifies how the public keys are required to be used, a combination e.g., concatenation of network entities identifiers e.g., access device identifier, and / or serving network identifier, and / or home network identifier, timing and / or location information (e.g., UTC-based counter, tracking area identifier), or a combination thereof, not precluding any other contextual information with the same effect of domain separation.

[0091] Domain separation is essential to ensure that cryptographic keys and functions are used in a way that minimizes the risk of collisions or misuse. In the context of cryptographic schemes, the "additional_data_l" serves as a domain separator. Below are some other parameters that could further enhance domain separation:

[0092] 1. Device-Specific Identifiers, including unique hardware identifiers or device-specific credentials, such as: IMEI (International Mobile Equipment Identity): A unique identifier for mobile devices. Device Serial Number: A manufacturer-specific unique serial number. Secure Element Identifier: Identifiers for secure chipsets within the device.

[0093] 2. User-Specific Identifiers, including parameters specific to individual users, such as: Subscriber Identity Module (SIM) Card Number: Unique SIM card identifiers. User Profile Information: Encrypted metadata about user preferences or settings.

[0094] 3. Environmental context, e.g., parameters based on the device's environment at the time of operation, such as: Geolocation Data: Latitude and longitude, or a broader region identifier. Time-Based Tokens: Current timestamps or UTC-based counters. Network Conditions: Indicators such as signal strength, type of connection (e.g., 4G, 5G), or roaming status. This information links a given transaction (generated key) to a given location / time so that the same transaction cannot be misused at a later point of time or from a different location.

[0095] 4. Session-Specific Parameters Data related to the specific session in which the cryptographic operation is being performed, such as Session ID: A randomly generated identifier for the session. Access Point Name (APN): Network access identifiers for session routing.

[0096] 5. Application-Level Metadata, e.g., information tied to specific apps or services using the cryptographic functions, including app Identifier: A unique ID for the application or service. Transaction Details: Context-specific information, such as transaction IDs or encrypted payload labels.

[0097] 6. Cryptographic Context, parameters directly related to the cryptographic operation itself: algorithm Version: Specifies the version of the algorithm being used, key Usage Policy: Flags or metadata indicating the type of cryptographic operation (e.g., encryption, signing).

[0098] These parameters can enhance domain separation by ensuring that cryptographic operations are uniquely contextualized to their intended use, improving both security and functionality in hybrid or quantum-resistant cryptographic schemes.

[0099] It is to be noted that even if the domain separator field is described here in the context of a hybrid scheme, the domain separator field may also be used when a single (public) key is used to protect the long-term identity. For instance, considering the environmental context, e.g., time or location, and using it as domain separator in the derivation of the symmetric keys used for the encryption of the long term identity may prevent, e.g., the reuse / misuse of a concealed long term identifier at a later time or from a different location. It is to be noted that in some cases, it may be preferred to obtain Ke and Ki as:

[0100] Ke | Ki = KDF(K | S | additional data_l)

[0101] Step 5: UE encrypts the long-term subscriber's identifier (e.g., SUPI) using Ke, e.g., c = E(Ke; SUPI).

[0102] Step 6: UE computes authentication tag as d = MAC(Ki; c | additional_data_2) where additional_data_2 may indicate that the derivation of a MAC uses a key derived by means of a hybrid scheme.

[0103] Step 7: UE returns [ECC_public_key, FIPS203_public_key, CT, c, d].

[0104] This embodiment has the advantage of requiring a single call to E() and MAC(), but it requires changes in the current logic of ECIES.

[0105] It is to be noted that in above embodiment (and following embodiments) the returned information (in above embodiment, in Step 7) may require further fields, e.g., similar to those in SUCI as described above. For instance, the protection scheme identifier may refer to a specific type of hybrid computation, e.g., as using two keys, a QR key and a non-QR key. Similarly, it may require the usage of two or more home network public key identifiers or that the home network public key identifier is such that it identifies a set of two or more keys.

[0106] In another embodiment of the invention that may be combined with other embodiments or used independently, the hybrid scheme to protect the SUPI may work as follows: Elliptic curve part: performing ECIES to protect SUPI according to above background description (and TS 33.501) obtaining m = ECC_public_key | c | d, where c is a ciphertext (?) and d is a MAC-tag

[0107] FIPS 203 part (in general, QR part): obtaining a key K and a ciphertext CT using the public key component FIPS203_public_key following algorithm 20 in FIPS 203.

[0108] Using K to obtain one or more shared secrets

[0109] Ke | Ki = KDF( K | additional data_l)

[0110] Encrypt c (and optionally d and ECC_public_key) in m using Ke, e.g., cc = E(Ke; c)

[0111] Compute authentication tag over cc (and optionally d and ECC_public_key (e.g., if not encrypted), e.g., as dd = MAC(Ki; cc | additional_data_2)

[0112] Return [ECC_public_key, FIPS203_public_key, CT, cc, dd]. If d is not encrypted next to c, then d may also be returned.

[0113] In other words, the ECIES protected SUPI is protected again using the key K in FIPS 203 (in general QR algorithm). This embodiment requires multiple calls to E() and MAC(), but it has the advantage that existing logic of ECIES can remain as it is, and additional QR protection can be added on top of it. In other words, this can be seen as a second layer of protection. In above embodiments, the encrypted long-term subscriber's identifier (e.g., 5G SUCI) may include the identifiers of the public-keys used to protect it (the encrypted long-term subscriber's identifier). Thus, in another embodiment of the invention that may be combined with other embodiments or used independently, when in hybrid mode, instead of including an identifier for the non-QR public key and the QR public key, a hybrid identifier may also be used where the hybrid identifier identifies the key pair (non-QR public key and QR public key) used in the hybrid protection of the long-term subscriber's identifier.

[0114] It is to be noted that even if the description in this invention of QR algorithms is mainly based on the key encapsulated algorithm defined in FIPS 203, other QR algorithms may be feasible as standardized by other SDOs such as ISO, IETF, or country SDOs such as OSCCA (China). Examples of those algorithms may include McEliecee, LAC, FRODO, NTRU, etc. Operators may make their own choices of the QR algorithms to use, and whether to use them in a hybrid mode or not. This means that while FIPS 203 is used in the description of previous algorithms, other QR encryption or key encapsulation mechanisms may be used instead.

[0115] In another embodiment of the invention that may be combined with other embodiments or used independently, the hybrid scheme to protect the SUPI may work as follows:

[0116] FIPS 203 part (in general, QR part): obtaining a key K and public key component FIPS203_public_key following algorithm 16 in FIPS 203.

[0117] Using K to obtain one or more shared secrets

[0118] Ke | Ki = KDF( K | additional data_l)

[0119] Encrypt SUPI using Ke, e.g., c = E(Ke; SUPI)

[0120] Compute authentication tag as d = MAC(Ki; c | additional_data)

[0121] Elliptic curve part: performing ECIES to protect SUPI according to above background description (and TS 33.501) where the input is m = c | d and returns cc | dd

[0122] Return [ECC_public_key, FIPS203_public_key, CT, cc, dd]

[0123] In other words, the FIPS 203 (in general, QR algorithm) is used first to obtain a key that is used to derive an encryption / integrity key used to protect the SUPI. The FIPS protected SUPI is then passed to ECIES. This embodiment requires multiple calls to E() and MAC(), but it has the advantage that existing logic of ECIES can remain as it is (unmodified).

[0124] In another embodiment of the invention that may be combined with other embodiments, the KDF may allow obtaining two 256 bit keys Ke and Ki. This may be done by using, e.g., two calls to a KDF based on HMAC_SHA256() or using the extensible output function of SHA3 and requiring an output of 512 bits, etc. In some situations, a SIM may be configured with a quantum-resistant key (or the hash of it) as owned by a network, e.g., the Home PLMN. However, the ME where the SIM is hosted may not have the corresponding post-quantum (PQ) capabilities, e.g., the capabilities to perform said operations / computations. In other cases, it may be the other way around, the SIM may not include a quantum-resistant key (or function of it), but the ME may be QR capable. Thus, in another embodiment of the invention that may be combined with other embodiments or used independently, the SIM card and ME may need to negotiate how the SUPI is protected. In particular, the ME may indicate to the USIM its capabilities when it does or does not support PQ encryption, and the SIM stores PQ keys. For instance, PQ capable MEs may indicate this capability to the SIM that may then rely on the ME to protect the SUPI (if the SIM cannot perform such protection by itself). Similarly, the USIM may indicate its QR capabilities to the ME. Based on the exchanged capabilities, the USIM and / or ME may determine a protection mode, or a feasible protection mode for the SUPI (or similar longterm identifier).

[0125] In another embodiment of the invention that may be combined with other embodiments or used independently, the UE (ME + USIM) may signal to the HPLMN if the protected SUPI is PQ or not. The UE may also signal its PQ capabilities, and so, trigger the configuration of a PQ public key (or fingerprint, i.e., the output of the hash function of the public key) in a SIM card. Storing the fingerprint is advantageous because of its smaller size compared to the public key itself.

[0126] In another embodiment that may be combined with other embodiments or used independently, the UE (ME + USIM) may signal to the HPLMN, e.g., during registration, its PQ capabilities, thus, allowing the network to determine how SUPI (and subsequent traffic) may, or ought to be protected. The SUPI protection procedure may support different schemes, which may depend on the capabilities of the ME and / or USIM. For instance, a USIM which does not have PQ capabilities may only check the public key's validity, as described in previous embodiments (e.g., comparing the output of the hash function taking as input the public key against the hash value corresponding to said public key stored at the USIM). For instance, a USIM with sufficient storage space may store the QR public key, however the computations (e.g., for confidentiality and integrity protection) may be performed by the ME. For instance, a USIM that is PQ capable, may be able to store PQ keys and perform computations to protect (e.g., confidentiality and integrity protect) SUPI. For instance, the non-PQ operations may be performed in the USIM while the PQ operations may be performed in the ME, and the USIM (or ME) may combine the keys and / or protect the (intermediate) values.

[0127] In another embodiment that may be combined with other embodiments or used independently, a USIM-less UE may, if the UE has in store a public key (K_pub) of a PLMN, protect its Permanent Equipment Identifier (PEI) using one of the hybrid schemes described above. K_pub may be shared between several PLMNs.

[0128] In another embodiment that may be combined with other embodiments or used independently and that is associated with emergency situations, UEs may be (pre-)configured to downgrade from QR ciphering / integrity algorithms to conventional cryptographic algorithms instead of using NULL ciphering / integrity algorithms. This has the advantage of providing minimal security protection for UE / user data. Alternatively, or additionally, depending on the UE and network (e.g., gNB, AMF) security policies / configurations, NULL ciphering / integrity algorithms may also be supported.

[0129] In another embodiment that may be combined with other embodiments or used independently and that is associated with interworking with a legacy network technology (e.g., 6G interworking with 5G), UEs may be (pre-)configured to downgrade from QR ciphering / integrity algorithms to conventional cryptographic algorithms instead of using NULL ciphering / integrity algorithms. This has the advantage of providing minimal security protection for UE / user data. Alternatively, or additionally, depending on the UE and network (e.g., gNB, AMF) security policies / configurations, NULL ciphering / integrity algorithms may also be supported.

[0130] In another embodiment of the invention that may be combined with other embodiments or used independently, the UE may indicate how the SUPI is protected in the SUCI message. For instance, the SUCI may include the public key identifiers of the public keys used to protect the SUPI, such as the ECIES public key and / or the FIPS 203 public key and the corresponding ciphertext to retrieve the shared secret. The order in which the keys are included may also indicate the order in which the protection was done (i.e., either first ECIES and then FIPS 203; or the other way around). Alternatively, this order may be indicated explicitly by a flag or a field in the SUCI message, or by a technical specification. This embodiment allows the HPLMN to know which public keys and which protection scheme were used by the UE, and thus to decrypt and verify the SUPI accordingly. This embodiment also allows adapting to different regional regulations that may require using a certain key as key in the KDF and other keys are additional input.

[0131] QR encryption may introduce a considerable overhead, and its usage, or a hybrid mode may not always be required. For instance, if the UE is connecting directly to the RAN of the HPLMN, the need of using hybrid mode may be lower; however, if the UE is connecting to the RAN while being abroad, the use of hybrid mode may be recommended or mandated. Thus, in another embodiment that may be combined with other embodiments or used independently, the UE may be configured with a configuration / policy determining the circumstances / context under which the longterm subscriber's identifier should be protected in a hybrid mode and / or using only a QR algorithm and / or using only a non-QR algorithm. And possibly also which QR algorithm and / or non-QR algorithm (e.g. key length)

[0132] It is to be noted that even if some of the embodiments rely on the derivation of a key encryption and a key integrity that are used in an encryption algorithm and in a message authentication code algorithm, other embodiments may be feasible wherein a single symmetric key is derived that is used, e.g., in an authenticated encryption algorithm such as GCM. In this case, a single call to the authenticated encryption algorithm is sufficient to cipher the payload and compute a message authentication.

[0133] In an embodiment that may be combined with other embodiments or used independently, a hybrid scheme may require the usage of two or more public key schemes, each using a different public key (identifier). Some of the public key schemes may be post quantum / quantum resistant (e.g., FIPS 203) and / or some may be classical, e.g., schemes based on elliptic curve cryptography. In some cases, the same public key (scheme) may be used together with multiple hybrid public key schemes, this has the advantage of reducing the storage needs, e.g., in the UE. For instance, a UE may store three keys for public key schemes 1, 2, and 3 e.g., based on ECIES, FIPS 203, and Classic McEliecee. Based on these keys, the following (hybrid) schemes may be used:

[0134] Hybrid scheme #1 = ECIES

[0135] Hybrid scheme #2 = FIPS 203

[0136] Hybrid scheme #3 = Classic McEliecee

[0137] Hybrid scheme #4 = ECIES + FIPS 203

[0138] Hybrid scheme #5 = ECIES + Classic McEliecee

[0139] Hybrid scheme #6 = FIPS 203 + Classic McEliecee

[0140] Hybrid scheme #7 = ECIES + FIPS 203 + Classic McEliecee

[0141] In such hybrid schemes, the wireless device may indicate which (hybrid) scheme is used to protect the long-term identifier:

[0142] Implicitly, e.g., by the public key identifiers included in the SUCI, explicitly, e.g., by a code indicating the hybrid scheme used.

[0143] It is to be noted that TS 31.102, Clause 4.4.11.8, defines a protection scheme identifier list data object that includes protection schemes, with different identifiers from highest to lowest priority, each of them linked to a key index identifier. In the embodiments of this invention, a protection scheme may be understood as a hybrid scheme, e.g., as above, and each protection scheme may include one or more key identifiers, e.g., Hybrid scheme #7 above would correspond to key identifiers for ECIES, FIPS 203 and Classic McEliecee.

[0144] In an embodiment that may be combined with other embodiments or used independently, a hybrid scheme may require the usage of two or more public key schemes, each using a different public key (identifier) and different hybrid schemes may be supported, each with a different combination of schemes. In some cases, each hybrid scheme is required to use a different public key, e.g., above, the FIPS 203 public key used in Hybrid scheme #4 is different than the FIPS 203 public key used in Hybrid scheme #6.

[0145] In an embodiment that may be combined with other embodiments or used independently, a public key is associated to a message field that indicates in which hybrid schemes said public key may be used.

[0146] To summarize, it is proposed a method for quantum-resistant protection of the longterm subscriber's identifier that may be implemented in a user equipment (UE) wherein the UE comprises a mobile equipment (ME) and a USIM and the method comprises: storing, in the USIM, a first value allowing for the verification of a quantumresistant public-key, obtaining, by the UE, part of the quantum-resistant public-key, checking, by the UE, the legitimacy of the obtained part of the quantumresistant public-key, and upon successful verification, further performing by the UE: o obtaining a quantum-resistant encapsulation key and o using the quantum-resistant encapsulation key to protect the long-term subscriber's identifier by means of the quantum-resistant public key.

[0147] Section: Protection of SUCI parameters such as MNC / MCC, Routing indicator

[0148] It is to be noted that currently the long-term subscriber's identity is the only identifier protected with the public-key of the home PLMN. It is to be noted that some fields such as the PLMN ID, i.e., MNC + MCC, or routing indicator are not protected. This means, e.g., that if a user of country A is roaming in country B, the fact that the user is a foreigner is easily detectable and trackable. For instance, when a UE transmits the SUCI, the MNC and MCC are in the clear so that it possible to identify those parameters and track a UE based on them. Furthermore, in some cases, the home PLMN may not enforce QR protection, but the serving PLMN may require it. It is an aim of the invention to address these limitations. In particular, the introduction of a hybrid scheme (as in above embodiments) may also allow using keys of multiple PLMNs to protect the long-term subscriber's identity as well as other fields, e.g., by means of the public key of the home PLMN and the public key of the serving PLMN.

[0149] In an embodiment that may be combined with other embodiments or used independently, a home PLMN may have a policy of not using a QR scheme, but the serving PLMN may require the usage of QR schemes. This policy may be known to the UE, e.g., because it is broadcasted / indicated in a SIB. Thus, a UE may be adapted to protect its SUPI using the (e.g., non-QR) public key of the home PLMN obtaining a first subscription concealed identifier (first SUCI). This first SUCI is then protected again using the (e.g., QR) public key of the serving PLMN obtaining a second SUCI. This second SUCI is the one exchanged over the air and sent to the serving PLMN. The serving PLMN removes the first layer of protection, and if it is done successfully, it forwards the recovered first SUCI to the home PLMN. This embodiment has multiple advantages. One of them is that the serving PLMN can have its own policy to protect the long-term subscriber's identifier over the air, e.g., with a QR public key algorithm, independently of the home PLMN. Another advantage is that other parameters of the home PLMN (e.g, the home PLMN identity (MCC + MNC)) can also be protected in the wireless interface by using the public key of the serving network. A UE may determine how it is supposed to protect its long-term subscriber identifier based on the system information that may be distributed by the serving network, e.g., a base station, and / or a policy configured by the home PLMN. For instance, the policy of the home PLMN may indicate that a non-QR public key is used, and the serving PLMN may indicate that it requires QR public key protection. For instance, the policy of the home PLMN may indicate that a non-QR public key is used and the UE may cipher / conceal its SUCI when roaming in a different country by using a specific network (e.g., a "preferred" serving network in the foreign country for which the home network has an agreement), and the serving PLMN may indicate that it requires public key protection to exchange UE's SUCI. In this case, the home PLMN may configure the public key of the home PLMN in the UE (e.g., USIM) as well as the public key of the "preferred" serving PLMN in the UE (e.g., USIM). In this case, a UE may first construct a first SUCI as

[0150] SUCH = Home PLMN ID | Concealed(SUPI)

[0151] And then obtain a second SUCI as:

[0152] SUCI2 = Serving PLMN ID | Concealed(SUCIl)

[0153] Where Concealed(SUPI) may refer to the encryption of long term identifier (e.g., 5G SUPI) using the public key of the home PLMN and Concealed(SUCIl) may refer to the encryption of SUCH (including MNC and MCC of the home PLMN) using the public key (PQ or non-PQ) of the serving PLMN1. It is to be noted that identifiers fields in the SUCI, e.g., SUCI2, may indicate how the long-term subscriber's identifier is protected. For instance, the protection scheme id may indicate whether the SUCI (i.e., SUCI2) received by the serving network (e.g., the AMF of the serving network) contains another SUCI (i.e., SUCH), and it may require the received SUCI (i.e., SUCI2) to be unprotected / verified (e.g., by the AMF / UDM of the serving network), and then upon decryption / verification, forward the decrypted / verified SUCH to the home PLMN. It is to be noted that in this case, the MCC / MNC in SUCI2 would be the MCC / MNC of the serving network instead of the home network. Similarly, the protection scheme ID may indicate a hybrid scheme, or performing QR protection first and then non- QR protection, or the other way around.

[0154] In an embodiment that may be combined with other embodiments or used independently, the UE may conceal the SUPI individually by using the public key of the home network and protect other parameters included in the SUCI such as MCC and MNC and that are not protected in technologies such as 5G R18 by using the public key of the serving network. This approach still allows the serving network to obtain the MCC, MNC, and other parameters, and use it to route the identifier in a suitable manner.

[0155] In general, it is described a method for confidential roaming that may be implemented in a user equipment (UE) wherein the method comprises:

[0156] - storing, in the UE, a first public key and a second public key, wherein the first public key is associated with the home PLMN and the second public key is associated with the serving PLMN

[0157] - computing, by the UE, a first SUCI, comprising the mobile network code, the mobile country code of the home PLMN and the long-term identifier of the UE encrypted by using the first public key,

[0158] - computing, by the UE, a second SUCI, comprising the mobile network code, the mobile country code of the serving PLMN and the first SUCI encrypted by using the second public key, and

[0159] - transmitting, by the UE, the second SUCI to the network.

[0160] Section: Combined protection / key encapsulation in multi-target / multi-receipt settings

[0161] In some situations, it may be desirable if a data message (e.g., a long term identifier such as the 5G SUPI) can be securely shared with multiple parties that may use different encryption technologies or use different encapsulation keys. For instance, a first party may prefer / use a Classic McEliece public key system and another party may prefer FIPS 203 (i.e., ML-KEM). For instance, the first party may be the serving PLMN and the second party may be the home PLMN. The problem is that the encapsulation key depends on the public key of each of those cryptosystems, independently i.e.:

[0162] For ML-KEM (FIPS 203):

[0163] ML-KEM. Encaps(ek_ML) chose random byte string s_ML

[0164] K_ML = SHA3-512(s_ML II SHA3-256(ek_ML) ) And for Classic McEliece:

[0165] ClassicMcEliece.Encaps(ek_CME) chose random weight-t column vector s_CME

[0166] C = Encode(s_CME, ek_CME)

[0167] K_CME = SHAKE256(1 , s_CME, C)

[0168] The dependence of K on the secret and the encapsulation key is useful for several reasons. A reason is to protect against precomputation attacks that attempt to break one out of many keys (see Clause 4.5.3 in Kyber submission of the 3rdRound of NIST PQC). An additional advantage of including the public key in the computation of K is that it protects against misuse because this feature turns a noncontributory KEM in a contributory KEM (K depends on the inputs of both parties) (see clause 4.5.4 3 in Kyber submission of the 3rdRound of NIST PQC).

[0169] For instance, the first party may be the serving network (VPLMN) and the second party may be the home network (HPLMN). The only way of using both public key schemes (in general, two or more) sending a secure message to both parties is to have a 3 layer solution in which: each of the public key schemes is used to encapsulate a different key, the encapsulation keys are used to share a message, the message being a cryptographic key, and the symmetric key is used to protect the data message.

[0170] However, this adds overhead, and it is an aim of some embodiments to reduce this overhead.

[0171] Thus, in an embodiment of the invention that may be combined with other embodiments or used independently, a combined key may be derived from one or more of the keys of the public key schemes used and a common root secret. In such a multi-target scheme illustrated by means of Classic McEliece and ML-KEM, a common root secret root_s is obtained (e.g., by generating a byte string at random), and from it, both s_CME and s_ML, the secrets in Classic McEliece and ML-KEM (FIPS 203), can be obtained. The usage of root_s just indicates that it is possible to transform a first secret s_CME into s_ML, and viceversa. The actual multi-target key used should depend on both K_ML and K_CME, the keys derived from the individual schemes (in this example, Classic McEliece and ML-KEM)), thus, the ciphertext will also include both a function of the keys, e.g., a one-way function such as a hash function, e.g., hash(K_ML) and hash(K_CME), so that the entity using one of the schemes (e.g., Classic McEliece), also has access to the key derived from the other scheme (e.g., ML-KEM). The final key used for encryption is then computed as a cryptographic function (e.g., hash function) of root_S and the one-way functions of the keys of each of the schemes. choose random byte string root_s ML-KEM.Encaps(ek_ML) determine random byte string s_ML from root_s

[0172] K_ML = SHA3-512( root_s II SHA3-256(ek_ML) ) and

[0173] ClassicMcEliece.Encaps(ek_CME) chose random weight-t column vector s_CME from root_s

[0174] C = Encode(root_s, ek_CME)

[0175] K_CME = SHAKE256(1 , s_CME, C) and

[0176] K = G(root_s | H(K_ML) | H(K_CME))

[0177] This approach leaves the encapsulation logic of the key encapsulation schemes mostly untouched, and relies on (1) using a randomness source that is common in both the different public-key encryption schemes and (2) deriving a K as a function G() (e.g., G() may be a one-way function) of (2a) this common source of randomness and (2b) a function H() (e.g., H(K_ML) and H(K_CME)) of the keys derived by each of the key encapsulation schemes. Note that this requires transmitting next to the ciphertexts also the function of the keys derived by each of the key encapsulation schemes (e.g., H(K_ML) and H(K_CME)).

[0178] It is to be noted that in this embodiment applied to the protection of the cellular long-term identifier, the long-term identifier is protected simultaneously with the keys of serving PLMN and home PLMN. This may be desirable when the UE trusts said serving PLMN and desires to reduce the signalling overhead / latency. In this case, such a protected long-term identifier may be sent in an initial message (e.g., registration request message). The serving PLMN may decrypt it using its decryption key / preferred key encapsulation scheme (e.g., Classic McEliecee) obtaining the long-term identifier, and the serving PLMN may forward both the decrypted long-term identifier and the protected long-term identifier to the home PLMN. The home PLMN may decrypt it using its own secret key and / preferred key encapsulation scheme (e.g., ML-KEM), and may check that the received long term identifier from the serving PLMN matches the long-term identifier that has been locally decrypted.

[0179] Section: Resolving SUCI computation error due to wrong configuration parameters

[0180] The 3GPP document CR-C6-240155 identifies the issue of SUPI (Subscription Permanent Identifier) calculation errors due to misconfiguration in the USIM (Universal Subscriber Identity Module). This can occur if necessary parameters such as "SUPI Type", "HN ID", or "RID" are incorrectly configured or missing from the USIM, resulting in an error status word being returned to the Mobile Equipment (ME). Such errors can have significant consequences: - The User Equipment (UE) and user may be unable to access any services.

[0181] - Operators might experience revenue loss.

[0182] -The authentication process might fail due to the UE's inability to generate a SUCI, preventing network connection and error reporting.

[0183] These errors can arise in multiple scenarios:

[0184] 1. The UE is registered and authenticated in the 5GC (5G Core), with security contexts in non-access stratum (NAS) and access stratum (AS). If the home network updates SUCI-related configurations, the SUCI calculation might fail when the AMF (Access and Mobility Management Function) requests it.

[0185] 2. The UE moves to an unregistered state with no security contexts after the home network updates SUCI-related configurations. The UE attempts to trigger a registration request to the 5GC but fails due to SUCI calculation issues.

[0186] 3. The UE transitions to EPC / 4G after the home network updates SUCI-related configurations. Upon returning to the 5GC, the SUCI calculation failure prevents registration, although EPC services remain available.

[0187] These scenarios may be further aggravated when using a hybrid SUCI scheme as described in some embodiments of this invention. For instance, when a UE moves to a network requiring quantum resistant SUPI protection that may trigger certain USIM / ME re-configurations. It may become highly relevant for the UE to exit the error state and inform the 4G / 5G network about the specific error or missing parameter. It is therefore the object of some embodiments in this invention to address this problem:

[0188] It is to be noted that TS 31.102, Clause 4.4.11.8, defines a protection scheme identifier list data object that includes protection schemes, with different identifiers from highest to lowest priority, each of them linked to a key index identifier. In this invention, a protection scheme may be understood as a standalone scheme, e.g., using ECIES, or a hybrid scheme, e.g., using ECIES and some PQ schemes.

[0189] In an embodiment that may be combined with other embodiments or used independently, a UE, upon receiving an update associated with SUCI parameters, may evaluate whether there are missing / wrong parameters and / or perform computations to determine whether SUCI could be computed, or whether an error occurs. In the case that the UE can obtain the SUCI, the UE may inform the network in a response whether the updates were OK (e.g., send ACK), otherwise, if missing parameters are detected and / or wrong parameters are detected and / or SUCI cannot be computed, the response may contain an error code, which may be indicative of the failure cause. For instance, the error code could be enriched by other details, e.g., UE may be configured to further include in the response message an indication e.g., indicating which parameter may be missing / corrupt, and / or which scheme(s) is / are failing, and / or a timestamp, and / or a timestamp of the first occurrence of SUCI computation failure (which the UE may be configured to store, upon failure), and / or whether the failure cause is unknown. The home network (HPLMN) may upon updating the UE / USIM parameters (i.e., send a configuration update related to the SUCI computation) wait for an ACK and / or NACK, before it considers the update successful or failed. Additionally or alternatively, the UE may not send anything if the SUCI computation fails, and the network may determine that the configuration failed if no confirmation / ACK message was received in a time window. Additionally or alternatively, the UE may only send a message if the SUCI computation fails, and the network may determine that the configuration succeeded if no NACK message was received in a time window. The UE may keep the old configuration until it can confirm that the new configuration is valid. The home network (HPLMN) may also keep the old configuration until it has been confirmed by the UE that the new configuration is valid. The ACK (acknowledge) message may include a SUCI so that the network can verify that the SUCI is properly computed and can be properly decrypted.

[0190] In an embodiment that may be combined with other embodiments or used independently, UE may use a previous identifier, e.g., the 5G-GUTI or SUCI that was last used, to regain access, e.g., by informing about its current state. This may require the UE to store the last used GUTI or SUCI. This may require the AMF to communicate the last GUTI or SUCI to the home PLMN. The UE may then send the request for an updated configuration for the computation of SUCI to the HPLMN using said previously used identifier. In particular, if the last used SUCI is reused by the UE / ME / USIM, that SUCI may be kept in the AUSF / UDM / UDR (or equivalent data base in future network generations). A UE may send a registration request message including this old SUCI optionally including a flag indicating that it is being reused that may also indicate the cause of reuse. The AUSF / UDM / UDR may have a policy allowing the usage of a reused SUCI if the flag is enabled. The AUSF / UDM / UDR may also check whether the SUCI computation configuration has been updated since the last usage of the SUCI. The flag maybe implicit to the reuse of the SUCI / GUTI. For instance, when this happens, the receiving entity (e.g., AUSF / UDM / UDR) may check whether the UE was (recently) updated, and this may serve as a check. The receiving entity may also contact the UE to verify whether its configuration is correct or not.

[0191] In an embodiment that may be combined with other embodiments or used independently, UE may use a previous identifier, e.g., the 5G-GUTI or SUCI that was last used, to regain access. If the Access management function (AMF) is unable of associating the 5G-GUTI with the UE SUPI, it will send an Identity Request to the UE. Upon UE's SUCI calculation failure, an error code may be sent in the Identity response message, which may also include the 5G-GUTI, to the AMF, which would then forward it to the UE's home PLMN (e.g., provided the error does not stem from a missing / corrupt HN identifier, or Routing indicator); the AMF may also include the 5G-GUTI received in the registration request, if it was not included by the UE. Additionally or alternatively, the last used SUCI may also be used in the protocol as identification means; for instance, the UE (and optionally the home network) may be configured to maintain the last computed SUCI, even after de-registration from the network (e.g., due to UE turning off), such that in the event of computing a fresh SUCI, the last used SUCI may be used as identification means. Additionally or alternatively, the UE may include the error code associated with failure to compute a SUCI in the Registration Request message, thus prompting the AMF to forward the message directly to its home PLMN. HPLMN (UDM / UDR) may keep in store the last used 5G-GUTI (as in previous embodiment, this requires that an AMF communicates GUTI to the UDM / UDR when used correctly). The Home PLMN, based on the received 5G-GUTI may identify the UE, determine whether UE received an update associated to SUCI parameters, and based on the error message (and potential enrichment data), prepare another remediating update, and send it (e.g., OTA) to the UE.

[0192] In an embodiment that may be combined with other embodiments or used independently, in case of failed SUCI computation, UE may default to using null scheme to register to the network, then indicate the error to the home PLMN. Alternatively, UE may use EPC services, and indicate to the network, the error associated with SUCI computation. UE may then receive updated parameters through the 4G network. Alternatively, the UE may initiate an emergency registration, wherein it includes its permanent equipment identifier (PEI) in addition to the error code associated with SUCI computation failure and the additional enrichment information (as described in previous embodiments), which may then be used by the home network to identify the SUPI and parameters that may be / have been misconfigured. Alternatively, the UE uses its PEI in a normal registration procedure.

[0193] In an embodiment that may be combined with other embodiments or used independently, in case of failed SUCI computation, UE may make use an "emergency identifier" that may have been configured for this purpose. The UE may store (e.g., in the USIM) an "emergency identifier" for the case that the UE cannot compute the SUCI. In this event, the UE may use the "emergency identifier" to contact the core network, e.g., HPLMN, indicating its situation. The "emergency identifier" may (implicitly / explicitly) indicate the situation and may be linked / connected to the SUPI. Upon reception, the core network may contact the UE / USIM, e.g., to update its parameters. In an embodiment that may be combined with other embodiments or used independently, in case of failed SUCI computation because of a misconfiguration of a given cryptographic algorithm (e.g., a quantum resistant algorithm or a hybrid scheme), the UE or USIM may be configured to use a different (default) cryptographic algorithm (e.g., based on a non-quantum resistant scheme) to protect the SUPI, perform primary authentication, and request a suitable configuration.

[0194] In an embodiment that may be combined with other embodiments or used independently, in case of failed SUCI computation because a necessary parameter, such as "SUPI Type", is missing, the UE may use a default configuration requiring the highest possible security level, and (re-)attempt the computation based on it, and (re-)attempt the network registration by using it.

[0195] In an embodiment that may be combined with other embodiments or used independently, in case of failed SUCI computation because one or more necessary parameters such as "HN ID" or "RID" are missing, the UE may perform the encryption of the SUPI with the latest known key, and may send the registration request to the AMF (of the serving network) using it forindicating the missing identifiers. The AMF may then try to route the message, e.g., by using the key identifier to identify the home PLMN and / or by routing it to the most likely home PLMNs. In this and other embodiments, the responsible NF in the core network may limit the number of requests per time unit to prevent, e.g., potential DoS attacks.

[0196] It is described in clause 4.4.11.8 of TS 31.102, the subscription concealed identifier calculation information EF which, according to the first table within the same clause contains a Protection Scheme Identifier List data object and a Home Network Public Key List data object, where the first data object entries are ordered from the highest priority Protection Scheme identifier to the lowest, and where each Protection Scheme identifier is associated with a Key Index indicating the position of the Home Network Public Key in the Home Network Public Key List, that is applicable to the Protection Scheme. Furthermore, Annex C.l of 33.501 specifies the protection schemes currently supported by the 5G system, namely null-scheme, and two Elliptic Curve Integrated Encryption Schemes (ECIES): ECIES Profile and ECIES profile . With the migration towards post-quantum cryptography (PQC)-based protection schemes, more protection schemes (profiles) are likely to be supported, and where SUCI failure may occur using one protection scheme, it is better privacypreserving to fall-back to an alternative protection scheme which provides some form of privacy protection than using a null-scheme. Hence, it is the object of some of the embodiments below to describe this approach.

[0197] In an embodiment that may be combined with other embodiments or used independently, if the USIM supports more than one protection scheme and the protection scheme identifier list data object contains more than one protection scheme identifier entry(-ies), in the event of SUCI calculation failure (e.g., due to missing or corrupt public key identifier and / or index), the USIM may attempt to use another protection scheme with a lower priority, together with the home network public key associated with it, instead of using the null protection scheme, which, if supported by the home network, may be the protection scheme with the least priority.

[0198] In some scenarios, the usage of a (hybrid) (protection) scheme relying on one or more public key (schemes) may fail because of a wrong configuration of any of the public key / protection (schemes), thus, in an embodiment that may be combined with other embodiments or used independently, in the case of failure of a public key scheme, the UE may attempt to protect the SU PI with another public key scheme, e.g., another hybrid public key scheme. For instance, and in reference to above embodiment describing multiple hybrid schemes (Hybrid scheme #1 to Hybrid scheme #7), if Hybrid scheme #7 fails because of a failure of the configuration of Classic McEliecee, the UE should not revert to using the null security scheme to protect the SUPI, but may select Hybrid scheme #4 that is still a hybrid scheme, but without using (the wrongly configured) Classic McEliecee.

[0199] In some scenarios, the usage of a (hybrid) (protection) scheme relying on one or more public key (schemes) may fail because of a wrong configuration of any of the public key / protection (schemes), thus, the core network may configure a wireless device with two sets of parameters per protection scheme so that if one fails, the other set of parameters can still be used. Additionally or alternatively, if two protection schemes (e.g., used in different hybrid schemes) are associated with the same (home network) public key, the UE / USIM may try using the highest priority (or a lower priority) protection scheme with another (second) home network public key identifier (e.g., from the Home network public key list data object) which is different from the one (first) associated with / indexed by the chosen protection scheme identifier. For instance, a UE / USIM may be configured with a first and a second public key (identifier) per protection scheme so that in the case that one of them fails, the other one is still usable. This has the advantage of circumventing a SUCI calculation error when e.g., the same (first) home network public key is associated with both (or more) protection schemes and provides an alternative which provides privacy protection for the SUPI, instead of using the null protection scheme.

[0200] In an embodiment that may be combined with other embodiments or used independently, , the use of a (second) valid home network public key identifier other than the one (first) associated with / indexed by the protection scheme identifier may implicitly indicate to the network that the UE / USIM may have run into a SUCI calculation error, and thus prompt the network to re-provision the USIM with a new (first) home network public key to be associated with the protection scheme identifier indicated in the received SUCI, or, alternatively, request the USIM to update the protection scheme identifier list data object such that the key index associated with the protection scheme identifier used is replaced by the key index indicating the (second) home network public key that the UE had used for SUCI calculation.

[0201] In an embodiment that may be combined with other embodiments or used independently, in those cases in which a UE / USIM supports multiple schemes, e.g., multiple PQC- based protection schemes (profiles), UEs may autonomously select a different protection scheme / profile, which is also supported by the home network (and thus, UE / USIM), upon SUCI calculation failure with the default protection scheme set by the operator. Additionally, or alternatively, the UE may be provisioned with at least one more home network public key (e.g., per PQC-based protection scheme), such that UE is enabled to select the second home network public key to be used with the chosen protection scheme, as described in the previous embodiment.

[0202] In an embodiment that may be combined with other embodiments or used independently, if a UE (e.g., USIM and / or ME) determines that the SUCI cannot be computed due to a wrong configuration, the UE may rely on a pre-configuration / policy to determine the action to take. For instance, the ME may consider that the USIM is in an unconfigured status until the status is resolved, and the ME may reuse an old parameter locally stored (in the USIM or ME) for the recovery of the USIM.

[0203] The USIM may allow the computation of the SUCI by the ME. the USIM may have a configuration determining that in case that the SUCI cannot be computed, the SUPI and / or an old SUCI and / or the last GUTI should / is allowed to be exchanged in the clear when registering in the network. the USIM may have a configuration determining that in case that the SUCI cannot be computed, parameters (that may identify the USIM) may be sent when attempting to register with the network to resolve the situation. Such parameters may indicate the last networks the USIM was connected to, the timestamps of the last successful registration requests / primary authentication procedures, etc. Such parameters can be kept at the AUSF / UDM / UDR and can be used to verify that the USIM is trustworthy (as a kind of two factor authentication since it provides proof of information that is only known to the actual USIM and / or as a parameters for reply protection). For instance, the UE / USIM may send: last_used_SUCI, parameters[last_three_used_networks, last_N_timestamps]

[0204] The AUSF / UDM / UDR can use the last_used_SUCI to retrieve the SUPI and then use parameters[last_three_used_networks, last_N_timestamps] to verify that it is not a replay attack. the ME may have a configuration to store the last exchanged SUCIs for each given USIM including the parameters that were used (e.g., HN identifier or routing indicator). In the case that a USIM after configuration is missing certain parameters, the USIM may accept (missing) parameters from the ME (e.g., HN identifier, or Routing indicator) to attempt to compute / construct the SUCI. Additionally or alternatively, the ME may construct the SUCI given that available parameters.

[0205] In an embodiment that may be combined with other embodiments or used independently, certain UEs may have more than a single USIM, e.g., a DualSteer UE. A DualSteer UE is a UE that contains two or more USIMs, each of them with its corresponding SUPI and keying materials. In case that one of the USIMs fails to perform some actions, e.g., computing the SUCI, the failing USIM may rely on one of the other operational USIMs to, e.g., inform the core network about the failed actions and / or get an update of the parameters. In some cases, the failing USIM may use the keying materials of the other USIM to protect its SUPI and compute the SUCI.

[0206] In an embodiment that may be combined with other embodiments or used independently, a UE may report an error failure cause (SUCI cannot be computed) and / or SUCI computed using logged data (e.g., as in the previous embodiment) and / or metadata when attempting to register with the network. The network (e.g., serving network) may allow a communication to be performed, even if the policy of the network (serving or home network) is, e.g., to only allow communication using a protected SUPI to be established. The network (e.g., serving network) may use this information to become aware that the exchanged SUCI may not be correct or may not be completely / correctly computed. This may give the network a hint that additional processing may be required. For instance, if the home network identifier is missing and the ME / USIM logged two different home network identifiers as used by the ME, the metadata may include such parameters. The serving network may then contact both networks indicating the situation. Each of those (potentially home) networks, may check whether the SUCI may belong to them, e.g., by attempting to decrypt the SUCI and checking whether the integrity succeeds or fails. If succeeds, it may indicate this to the (serving) network and may proceed to perform / finish the primary authentication procedure, and once performed, it may reconfigure the USIM with suitable configuration parameters.

[0207] In general, it is described a method for updating parameters associated with the computation of a Subscriber Concealed Identifier (SUCI), wherein the method comprises:

[0208] - an apparatus receiving a configuration update from a first network, the configuration update comprising parameters associated with the protection of the subscriber permanent identifier.

[0209] - the apparatus performing, based on the configuration update, the security procedure to conceal the subscriber permanent identifier; - the apparatus determining whether the computation of the subscriber concealed identifier was successful, or has failed; and

[0210] - the apparatus sending a response message to the first network, containing an acknowledgment of receipt in case of success, or failure message in case of failure.

[0211] The method described above, wherein the method further comprises the apparatus being configured to provide additional information in the response message following an update, indicating the failure cause and / or timing, including one or more of the following:

[0212] - potential missing or corrupt parameters;

[0213] - scheme(s) that are subject of failure;

[0214] - failure conditions;

[0215] - timestamp of the first occurrence of SUCI computation failure; and

[0216] - whether the failure cause is unknown or an indication of the failure cause.

[0217] It is described a method for requesting parameters update from the network, wherein, in case of failing to compute a subscriber concealed identifier, an apparatus may be configured to include the error code associated with the subscriber concealed identifier computation failure and a last used identifier, wherein the last used identifier is one of the globally unique temporary identifier and SUCI, in the registration request and / or in the identity response message, sent to the access management function.

[0218] It is described a method for updating parameters associated with the computation of a subscriber concealed identifier, wherein the method comprises an apparatus configured to perform, upon failing to compute the subscriber concealed identifier, the following:

[0219] - search and select an access device associated with a network generation which does not require concealing the subscriber identifier using the scheme or method subject to failure;

[0220] - attach to the network and send a message, indicating the error code associated with SUCI computation failure and / or parameters for replay protection, to request a parameters update;

[0221] - receive updated parameters associated with SUCI computation.

[0222] It is describer another method for network access, wherein the method comprises an apparatus configured to perform, upon failing to compute the subscriber concealed identifier, a registration procedure, wherein the UE identifier is set to one of the following:

[0223] - subscriber concealed identifier computed using a null protection scheme; or

[0224] - subscriber permanent identifier protected using a different cryptographic algorithm / scheme; or

[0225] - the last used globally unique temporary identifier; or

[0226] - the last used SUCI; or

[0227] - the permanent equipment identifier. Background on wireless local area network technologies

[0228] Wi-Fi is a wireless technology that allows devices to connect to the Internet or to each other without using cables. Wi-Fi is based on radio waves that are transmitted and received by a device called a wireless access point (AP). The AP acts as a hub that connects Wi-Fi enabled devices, such as laptops, smartphones, tablets, smart TVs, etc., to a wired network, such as a local area network (LAN) or the Internet.

[0229] The term Wi-Fi is a trademark of the Wi-Fi Alliance, an industry association that certifies products that comply with the IEEE 802.11 standards for wireless local area networks (WLANs). These standards define the physical and data link layers of the communication protocol, such as the frequency bands, modulation schemes, encryption methods, authentication mechanisms, and data rates used by Wi-Fi devices. The most common Wi-Fi standards are based on IEEE 802.11a, 802.11b, 802.11g, 802. lln, 802.11ac, and 802.11ax, which operate in different frequency bands (2.4 GHz, 5 GHz, or both) and offer different levels of performance and compatibility.

[0230] To use Wi-Fi, a device needs to have a wireless network interface card (NIC) that can send and receive radio signals. The NIC scans the available wireless channels and detects the presence of nearby APs. The device then selects an AP to connect to, based on factors such as signal strength, security settings, and network name (SSID). The device and the AP exchange information, such as the MAC address, IP address, encryption key, and password, to establish a connection. This process is called association. After the connection is established, the device can communicate with the AP and other devices on the same network, or access the Internet through the AP.

[0231] IEEE 802. lln (Wi-Fi 4) provided new features such as MIMO and frame aggregation to increase throughput. IEEE 802.11ac (Wi-Fi 5) introduced wider bandwidth and MU-MIMO. IEEE 802.11 ax (WIFI-6) included OFDMA and BSS color or spatial reuse to use spectrum resources more efficiently. IEEE 802.11 ah introduced target wake time (TWT) to support low power loT applications by allowing STAs to go into sleep when not in a wake period after negotiation with AP. IEEE 802.11be (Wi-Fi 7) aims at improving throughput and latency operating in unlicensed bands between 1GHz and 7.125 GHz. Wi-Fi 7. Increases bandwidths up to 320 MHz, 4096 QAM modulation, and supporting up to 16 spatial streams in MU-MIMO with an improved sounding procedure. Wi-Fi 7 also enables multiple resource units to be assigned to a single device. Furthermore, it includes an enhanced preamble with a universal SIG filed indicating the PHY version. It also extends the negotiated ack buffer size to 1024 bits. It also enables multilink operation (MLO) enabling multiple links between a station and an access point, for instance an AP can have two radios 2.4 and 5 GHz and use both of them for simultaneous transmission and / or reception with a multi-link capable device (MLD) capable station. Wi-Fi 7 also includes a restricted TWT providing predictable latency by assigning STAs to different rTWT types and making sure that other ST As do not transmit if they do not belong to a given rTWT type. Wi-Fi 7 also include multi-AP coordination performing, e.g., coordinated transmission, beamforming, or joint transmission.

[0232] For instance, in references to Fig. 1, devices 100, 101 and 102 can be Wi-FI access points and device 106 can be a wireless station. Station 106 and access point 101 are MLD and communicate with two links 126. Device 102 is a cellular capable residential gateway.

[0233] Application to cellular technologies

[0234] The ideas presented in this invention may be applicable to a wide range of wireless technologies used in wide or local area networks and using different types of radio access technologies, in particular, the ideas may apply to cellular technologies. Even if some embodiments have been described in terms of certain technologies, e.g., 5G, 4G or WiFi, they may also be applicable to other wireless technologies.

[0235] A cellular system is a wireless communication system that consists of three main components: user equipment (UE), radio access network (RAN), and core network (CN). These components work together to provide voice and data services to mobile users over a large geographic area.

[0236] User equipment (UE) is the device that a user uses to access the cellular system, such as a smartphone, a tablet, a laptop, loT device, or a wearable device. A UE typically may contain the following components:

[0237] - A universal integrated circuit card (UICC), which stores the user's identification and authentication information, such as the subscription permanent identifier (SUPI) or credentials.

[0238] - A transceiver, which converts the digital signals from the processor into analog signals for transmission and reception over the air interface. The transceiver also performs modulation, demodulation, coding, decoding, and other signal processing functions.

[0239] - A processor, which controls the operation of the UE and executes the applications and services that the user requests. The processor also communicates with the RAN and the CN using various protocols.

[0240] - A display, which shows the user the information and feedback from the UE, such as the signal strength, the battery level, the call status, the messages, the contacts, the menu, etc.

[0241] - A microphone and a speaker, which enable the user to make and receive voice calls, as well as use other audio features, such as voice mail, voice recognition, etc.

[0242] - A keyboard and / or a touch screen, which allow the user to enter and select commands, text, numbers, etc. - A camera and / or a video recorder, which enable the user to capture and send images and videos, as well as use other multimedia features, such as video calling, video streaming, etc.

[0243] - A memory, which stores the data and programs that the user needs, such as the phone book, the messages, the photos, the videos, the applications, etc.

[0244] - A battery, which provides the power supply for the UE.

[0245] A UE access the cellular network via the radio access network, as described below. Certain UEs may communicate with each other by using device-to-device communication, also known as sidelink communication using the PC5 interface that may rely on physical sidelink (PS) broadcast channel, PS shared channel, PS control, etc.

[0246] A UE may receive / transmit / trigger a configuration by means of different procedures:

[0247] Downlink control information (DCI) is a type of control information that is sent from the BS to the UE on the physical downlink control channel (PDCCH). DCI contains various parameters that instruct the UE how / when to decode and transmit data on the physical downlink shared channel (PDSCH) and the physical uplink shared channel (PUSCH), such as the resource allocation, the modulation and coding scheme. The UE needs to monitor the PDCCH in each subframe to detect and decode the DCI that is addressed to it.

[0248] Uplink control information (UCI) is a type of control information that is sent from the UE to the BS on the physical uplink control channel (PUCCH) or the physical uplink shared channel (PUSCH). UCI contains various feedback signals that inform the BS about the status and quality of the downlink transmission, such as the HARQ. acknowledgments (ACKs), the channel state information (CSI), and the scheduling requests (SRs). The UE needs to encode and transmit the UCI according to the configuration and timing indicated by the BS.

[0249] Sidelink control information (SCI) is a type of control information that is sent from the UE to another UE on the physical sidelink control channel (PSCCH) in device-to-device (D2D) communication scenarios. The main functions of SCI include resource allocation, synchronization, channel quality reporting, .

[0250] Medium access control (MAC) control element (MAC CE) is a type of control information that is sent from the BS to the UE or vice versa on the MAC layer. MAC CE contains various commands or indications that regulate the MAC layer functions, such as the buffer status report (BSR), the timing advance command (TAC), the discontinuous reception (DRX) command, etc. The UE needs to process the MAC CE according to the MAC protocol and the configuration provided by the BS.

[0251] Radio resource control (RRC) command is a type of control information that is exchanged between the BS and the UE on the RRC layer. RRC Command contains various messages that modify / configure RRC parameters and / or initiate, modify, or release the RRC connection or the radio bearers between the UE and the BS, such as the RRC connection setup, the RRC connection reconfiguration, the RRC connection release, the security mode command, the mobility from E-UTRA command, the handover from E-UTRA preparation request, etc. The UE needs to respond to the RRC Command according to the RRC protocol and the configuration provided by the BS.

[0252] Non-access stratum (NAS) messages are used for signalling between UE and core network (CN) on the non-access stratum (NAS) layer. NAS messages enable functionality such as registration, session establishment, security, and mobility management. The UE needs to respond to the NAS Command according to the NAS protocol and the configuration provided by the CN.

[0253] UE parameter update (UPU) is a procedure between the UE and the home network that enables the home network to update configuration parameters in mobile phones and / or USIM using tthe UDM control plane procedure (TS 23.502). The UE can receive Parameters Update Data from the UDM after the UE has registered in the 5G network.

[0254] Steering of Roaming (SoR) enables the home network to guide the user equipment (UE) when registering on a visited network. For detailed information about the interfaces and registration in the 5G System, refer to 3GPP TS.23.501 (Release 15)

[0017] and 3GPP TS 24.501 (Release 15)

[0018] , The 5G CP-SOR is activated during or after registration to update the UE's "Operator Controlled PLMN Selector with Access Technology" list via secure NAS messages, as directed by the home PLMN based on specific operator policies, such as preferred networks or UE location.

[0255] UE configuration update (UCU) is used to update configuration parameters as per TS 23.502 that may include Access and Mobility Management related parameters decided and provided by the AMF, UE Policy provided by the PCF. When AMF wants to change the UE configuration for access and mobility management related parameters the AMF initiates the procedure defined in clause 4.2.4.2. When the PCF wants to change or provide new UE Policies in the UE, the PCF initiates the procedure defined in clause 4.2.4.3. If the UE Configuration Update procedure requires the UE to initiate a Registration procedure, the AMF indicates this to the UE explicitly. The procedure in clause 4.2.4.2 may be triggered also when the AAA Server that performed Network Slice-Specific Authentication and Authorization for an S-NSSAI revokes the authorization.

[0256] Radio access network (RAN) is the part of the cellular system that connects the UEs to the CN via the air interface. The RAN consists of base stations (BSs). A base station (BS) is a fixed or mobile transceiver that covers a certain geographic area, called a cell. In 5G, a BS is also called a gNB (next generation node B). A BS can serve multiple UEs simultaneously within its cell, by using different frequencies, time slots, codes, or beams. A BS also performs functions such as power control, handover control, channel allocation, interference management, etc. A base station can be divided into two units: a central unit (CU) and a distributed unit (DU). The CU performs the higher layer functions, such as RLC, PDCP, RRC, etc. The DU performs the lower layer functions, such as PHY and MAC. The CU and the DU can be co-located or separated, depending on the network architecture and deployment. In cellular systems, a base station may be denoted, based on context, as a cell, or gNB.

[0257] The cell may also refer to the coverage area of a base station. A BS may have different coverage areas such as a macro cell (e.g. several kilometres wide), a pico cell (e.g., for a given location such as a stadium) or a femto cell for a small location (e.g., a home or part of it).

[0258] A base station may communicate with the core network. Since there can be base stations for different cellular systems, different interfaces are required. For instance, a base station, eNB, in a 4G Long Term Evolution (LTE) system (also known as Evolved Universal Mobile Telecommunications Systems (UMTS) Terrestrial Radio Access Network (E-UTRAN)) may interface with the 4G CN known as EPC through the corresponding interface. For instance, a base station, gNB, in a 5G system (i.e., 5G New Radio or Next Generation RAN) may communicate with the 5GC through a different interface. 4G and 5G base stations may communicate with each other directly or through their corresponding core networks.

[0259] The main protocols used between the UEs and the RAN are:

[0260] - The physical layer (PHY), which defines the characteristics of the air interface, such as the frequency bands, the modulation schemes, the coding rates, the frame structure, the synchronization, etc.

[0261] - The medium access control (MAC) layer, which regulates the access of the UEs to the shared radio channel, by using techniques such as orthogonal frequency division multiple access (OFDMA), time division duplex (TDD), frequency division duplex (FDD), etc.

[0262] - The radio link control (RLC) layer, which provides reliable data transmission over the radio channel, by using techniques such as segmentation, reassembly, error detection, error correction, retransmission, etc.

[0263] - The packet data convergence protocol (PDCP) layer, which compresses and decompresses the headers of the data packets, encrypts and decrypts the data, and performs data integrity protection.

[0264] - The radio resource control (RRC) layer, which establishes, maintains, and releases the radio bearers between the UEs and the RAN, as well as exchanges the signaling messages for functions such as connection setup, handover, measurement reporting, security activation, etc.

[0265] A transmission / reception communication unit or transceiver may be used by BS and UE to transmit / receive data. Control data may be required for a physical broadcast channel, physical downlink control channel, etc. Data may be for the physical downlink shared channel. Data may be encoded by the UE and / or BS to obtain data symbols and / or control symbols that may be exchanged over the wireless interface. The conversion from digital data into analog symbols may be done by the transmission / reception communication unit

[0266] A medium access control control-element (MAC-CE) is a MAC layer communication element that is used to control the communication between wireless devices. A MAC-CE may be exchanged in a shared channel, e.g., the physical downlink / uplink / sidelink shared channel.

[0267] The communication between a UE and a base station or the communication between UEs (when sidelink is used) may involve the exchange of reference signals. Reference signals may include primary synchronization signal (PSS), a secondary synchronization signal (SSS), a physical broadcast channel demodulation reference signal (DMRS), a channel state information reference signal (CSI-RS). Core network (CN) is the part of the cellular system that connects the RAN to other networks, such as the Internet, or other cellular systems. The CN consists of two main (control / user) domains. The control domain is responsible for providing signalling and control functions for the UEs, such as authentication, authorization, mobility management, session management, etc. The control plane consists of several network functions (NFs), such as the access and mobility management function (AMF), the session management function (SMF), the unified data management (UDM), the policy control function (PCF), the network exposure function (NEF), and the authentication server function (AUSF). The access and mobility management function (AMF) is a NF that handles the registration, deregistration, connection management, and mobility management for the UEs. The session management function (SMF) is a NF that handles the establishment, modification, and release of the sessions for the UEs. The SMF also communicates with the user plane devices to perform functions such as IP address allocation, tunneling, QoS, etc. The unified data management (UDM) is a NF that stores and manages the user data, such as the SUPI, the service profile, the subscription status, etc. The policy control function (PCF) is a NF that provides the policy rules and charging information for the UEs, such as the access type, the service level, the data rate, the quota, etc. The network exposure function (NEF) is a NF that exposes the network capabilities and services to external applications and devices, such as the IMS, the Internet of Things (loT), etc. The authentication server function (AUSF) is a NF that performs the primary authentication with the by using credentials and the SUPI. The user domain is responsible for providing data and multimedia services to the UEs, by using packets and IP addresses. The user plane consists of two main functions: the user plane function (UPF) and the data network (DN). The user plane function (UPF) is a device that forwards the data packets between the UEs and the DNs, as well as performs functions such as tunneling, firewall, QoS, charging, etc. The data network (DN) is a network that provides access to the services and applications that the UEs request, such as the Internet, the IMS, etc. A residential gateway (RG) is a device that connects a home network to an external network, such as the Internet or a cellular system. An RG typically provides functions such as routing, switching, firewall, NAT, DHCP, DNS, VPN, etc. An RG can also support various types of interfaces, such as Ethernet, Wi-Fi, Bluetooth, USB, etc. A cellular-capable RG is an RG that has a cellular interface, such as a UICC slot, a cellular modem, or an antenna, that enables it to access the cellular system as a backup or an alternative to the wired or wireless broadband connection. A cellular-capable RG can provide benefits such as: (1) Enhanced reliability, by switching to the cellular connection in case of a failure or a degradation of the broadband connection; (2) Increased bandwidth, by aggregating the cellular connection and the broadband connection to achieve higher data rates or QoS.

[0268] A multi-SIM subscription is a subscription that allows a user to have multiple SIMs (or eSIMs) that are linked to the same account and service profile. A user can use the multi-SIM subscription to access the cellular system from different devices, such as a smartphone, a tablet, a laptop, or a wearable device, without having to switch the SIM card or the device.

[0269] In reference to Fig. 1, devices 100, 102, and 128 can play the role of UEs. Device 102 is part of a cellular-capable RG providing connectivity to a home network 129 e.g., by means of a local area network and / or wireless local area network. Device 102 is served by base station 104.

[0270] The RAN 127 comprises base station 103 and serves UE 128. UE 128 may also be a UE to Network relay given access to remote UE 136 that is out of coverage of base station 103. UEs 134 and 136 also communicate with each other via a UE-to-UE relay 135. Within the RAN, the range of base station 103 is extended via smart repeater 137 and reflective intelligent surface (RIS) 138. Smart repeater 137 and RIS 138 give access to UE 142.

[0271] The RAN 143 includes base station 104 tand serves as wireless access infrastructure for the home network. Base station 104 also serves a mobile access device and / or UE as a UAV 139. UAV 139 may provide connectivity to remote UE 136.

[0272] Furthermore, a satellite gateway 141 is shown that connects to satellite 140 and may provide connectivity services to remote UE 136 or UE 100.

[0273] In Fig. 1, the 5G core network 133 may include one or more an AMF 121, SMF 123, UPF 122, AUSF 124, UDM 125, PCF 131, NEF 132 and allows the connection to a data network 130.

[0274] In Fig. 1, a second core network 142, e.g., a legacy core network as a 4G core network, is also shown that may interface with the 5G core network 133, interface with base stations, and provide a connection to the data network 130. The legacy 4G core network is denoted EPC and may include one or more mobility management entities (MME), a serving gateway, a multimedia broadcast multicast service gateway, a broadcast multicast service center, a packet data network gateway, etc. The mobility management entity may handle the signalling between UE and the 4G CN and may interact with the home subscriber server (HSS). The MME may provide connection management, similar to the AMF in 5G. The serving gateway may be used to exchange user internet protocol messages whereby the serving gateway may interact with the packet data network gateway that is connected to IP services.

[0275] A UE may connect to a serving network or serving Public Land Mobile Network (PLMN). A UE may have a subscription with a home PLMN, and during the registration procedure, the (AMF of the) serving PLMN may forward the registration request to the (AUSF of the) home PLMN that may perform an initial authentication procedure between home PLMN and UE. If the authentication procedure is successful, keys are derived and the home PLMN may share derived credentials with the serving PLMN, including K_SEAF, that may be used to derive K_AMF, from which NAS keys and AS keys are derived. The registration request sent by the UE includes an identifier that can be used by the home PLMN to identify the UE. To prevent privacy vulnerabilities, the long-term subscriber's identifier known as Subscriber Permanent Identifier (SUPI) may not be exchanged in the clear, but instead, either a Subscription Concealed Identifier (SUCI) or a pseudonym known as GUTI are exchanged with the AMF of the serving PLMN. The AMF of the PLMN may then forward the SUCI to the home PLMN so that the home PLMN decrypts / verifies it.

[0276] A UE may connect to a serving network or serving Public Land Mobile Network (PLMN). A UE may have a subscription with a home PLMN, and during the registration procedure, the (AMF of the) serving PLMN may forward the registration request to the (AUSF of the) home PLMN that may perform an initial authentication procedure between home PLMN and UE. If the authentication procedure is successful, keys are derived and the home PLMN may share derived credentials with the serving PLMN, including K_SEAF, that may be used to derive K_AMF, from which NAS keys and AS keys are derived. The registration request sent by the UE includes an identifier that can be used by the home PLMN to identify the UE. To prevent privacy vulnerabilities, the long-term subscriber's identifier known as Subscriber Permanent Identifier (SUPI) may not be exchanged in the clear, but instead, either a Subscription Concealed Identifier (SUCI) or a pseudonym known as GUTI are exchanged with the AMF of the serving PLMN. The AMF of the PLMN may then forward the SUCI to the home PLMN so that the home PLMN decrypts / verifies it.

[0277] Furthermore, this invention can be applied to various types of UEs or terminal devices, such as mobile phone, vital signs monitoring / telemetry devices, smartwatches, detectors, vehicles (for vehicle-to-vehicle (V2V) communication or more general vehicle-to-everything (V2X) communication), V2X devices, Internet of Things (loT) hubs, loT devices, including low-power medical sensors for health monitoring, medical (emergency) diagnosis and treatment devices, for hospital use or first-responder use, virtual reality (VR) headsets, etc. Other variations to the disclosed embodiments can be understood and effected by those skilled in the art in practicing the claimed invention, from a study of the drawings, the disclosure and the appended claims. In the claims, the word "comprising" does not exclude other elements or steps, and the indefinite article "a" or "an" does not exclude a plurality. A single processor or other unit may fulfil the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage. The foregoing de-scription details certain embodiments of the invention. It will be appreciated, however, that no matter how detailed the foregoing appears in the text, the invention may be practiced in many ways, and is therefore not limited to the embodiments disclosed. It should be noted that the use of particular terminology when describing certain features or aspects of the invention should not be taken to imply that the terminology is being re-defined herein to be restricted to include any specific characteristics of the features or aspects of the invention with which that terminology is associated. Additionally, the expression "at least one of A, B, and C" is to be understood as disjunctive, i.e., as "A and / or B and / or C". The same applies to the expressions "A or B" and "at least one of A or B", i.e., they may indicate all possible combinations of the listed items.

[0278] A single unit or device may fulfil the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.

[0279] The described operations like those indicated in the above embodiments may be implemented as program code means of a computer program and / or as dedicated hardware of the related network device or function, respectively. The computer program may be stored and / or distributed on a suitable medium, such as an optical storage medium or a solid-state medium, supplied together with or as part of other hardware, but may also be distributed in other forms, such as via the Internet or other wired or wireless telecommunication systems.

Claims

Claims1. A method for protecting a long-term subscriber's identifier implemented in a user equipment (UE) wherein the UE comprises a Universal Subscriber Identity Module, USIM, and the method comprises: storing, in the USIM, a first value enabling verifying a first quantum-resistant public-key, obtaining, by the UE, at least part of the first quantum-resistant public-key, performing, by the UE, a legitimacy check of the obtained part of the first quantumresistant public-key, and if the legitimacy check is successful, performing by the UE: o obtaining a first quantum-resistant encapsulation key and o protecting the long-term subscriber's identifier using the first quantum-resistant encapsulation key, resulting in a protected long-term subscriber's identifier.

2. The method of claim 1, wherein the first value comprises multiple components, each component obtained as a function of a part of the first quantum-resistant public-key.

3. The method of claim 1, wherein the first value is a public key for digital signature verification.

4. The method of claim 1, 2 or 3, wherein the method comprises storing, by the UE, in the USIM a URL wherein the URL indicates where the first quantum-resistant public-key can be retrieved from.

5. The method of claim 2, wherein the performing the legitimacy check includes computing by the UE a function of the obtained part of the first quantum-resistant public key and comparing it with the stored first value.

6. The method of claim 3, wherein the performing of the legitimacy check includes verifying by the UE a digital signature attached to the obtained part of the first quantum-resistant public key.

7. The method of any of the previous claims, comprising:combining, by the UE, the first quantum-resistant encapsulation key with one or more second keys by means of a key derivation function to obtain an encryption key Ke and an integrity key Ki, using the encryption key Ke to encrypt the long-term subscriber's identifier by means of a symmetric encryption algorithm obtaining an encrypted long-term subscriber's identifier, using the integrity key Ki to obtain a message authentication code of the encrypted longterm subscriber's identifier.

8. The method of claims 1, 2, 3, 4, or 5, comprising: using, by the UE, the first quantum-resistant encapsulation key to protect the long-term subscriber's identifier, thereby obtaining a first subscriber's concealed identifier, using, by the UE, a second key to protect the first subscriber's concealed identifier, thereby obtaining a second subscriber's concealed identifier.

9. The method of claims 1, 2, 3, 4, or 5, comprising: using, by the UE, a second key to protect the long-term subscriber's identifier, thereby obtaining a first subscriber's concealed identifier, and using, by the UE, the first quantum-resistant encapsulation key to protect the first subscriber's concealed identifier, thereby obtaining a second subscriber's concealed identifier.

10. The method of claims 7, 8, or 9, wherein the protected long-term subscriber's identifier is derived from the encrypted long-term subscriber's identifier or the second subscriber's concealed identifier and, wherein the method comprises transmitting, by the UE, the protected long-term subscriber's identifier including the identities of the public-keys used in the encryption and / or a protection profile identifier.

11. The method of any previous claims, comprising indicating, by the UE, quantum resistant capabilities and / or protection profiles of the UE and / or a mobile equipment, ME associated with the UE and / or the USIM in an initial registration request message.

12. The method of any previous claims, comprising a mobile equipment, ME, in the UE indicating its quantum resistant capabilities to the USIM.

13. The method of any of claims 1-11, comprising the USIM indicating its quantum resistant capabilities to a mobile equipment, ME.

14. The method of any previous claims, comprising storing, by the UE, a configuration / policy determining the context / circumstances to protect the long-term subscriber's identifier by means of a QR algorithm and / or a non-QR algorithm.

15. The method of any previous claims, comprising downgrading, by the UE, the security level to protect the long-term subscriber's identifier by means of a non-quantum-resistant public key or protection scheme in case of emergency services.

16. The method of any of the previous claims, comprising downgrading, by the UE, the security level to encrypt the long-term subscriber's identifier by means of a non-quantum-resistant public key in case of interworking with a legacy network technology.

17. The method of any of the previous claim, wherein the first quantum-resistant public-key is associated with metadata, the metadata comprising one or more of:- a lifetime of the first quantum-resistant public-key;- an allowed or disallowed usage in hybrid mode or standalone mode;- an allowed or disallowed usage in protection scheme identifiers; and- a public key type.

18. The method of any of the previous claims, wherein the protecting, by the UE, the long-term subscriber's identifier using the first quantum-resistant public key comprises applying a domain separator field.

19. The method of claim 18, comprising transmitting, by the UE, the protected long-term subscriber's identifier with one or more fields of the domain separator field .

20. The method of claim 18 or 19, wherein the domain separator field includes one or more of:- Device specific identifiers,- User-specific identifiers,- Environmental context,- Session specific parameters, and- Application level metadata.

21. The method of claim 7 in combination with any of claims 18, 19 or 20, comprising signalling, by the UE, the order in which the first quantum-resistant encapsulation key and the one or more second keys are combined and / or used.

22. The method of any of claims 7 to 21, wherein the UE is configured with a policy determining the usage of a protection scheme based on a UE's context, wherein the protection scheme is one of a hybrid quantum-resistant and non-quantum resistant protection scheme, a hybrid quantum-resistant and quantum resistant protection scheme, a quantum-resistant protection scheme, a non-quantum resistant protection scheme; and the UE's context comprises one or more of a roaming status and a serving network identifier.

23. The method of claim 1, wherein the first quantum-resistant public-key is associated with a first network, and wherein the protecting the long-term subscriber's identifier by means of the first quantum-resistant public key is performed according to the policy of the first network.

24. The method of claim 10 and 23, wherein the protecting, by the UE, the long-term subscriber's identifier comprises protecting an unprotected home network identifier, such as a mobile network code and / or a mobile country code, and the long-term subscriber's identifier protected with a second network public key associated to a second network.

25. The method of claims 23 and 24, comprising indicating, by the UE, the protection by means of a protection scheme identifier.

26. The method of claim 1, wherein the protecting the long-term subscriber's using the first quantum-resistant public key comprises a. obtaining a multi-target encryption key as the result of applying a cryptographic function to a first input derived from a first quantum-resistant encapsulation key and a second input derived from a second encryption key, wherein the first quantumresistant encapsulation key is associated with a first network and wherein the second encryption key is associated with a second network; b. protecting the long-term subscriber's identifier using the multi-target encryption key.

27. The method of any of claims 23, 24, 25, and 26, wherein the first network is a serving PLMN and the second network is a home PLMN.

28. The method of any of the previous claims, further comprising receiving, by the UE, a configuration update from a network, the configuration update comprising parameters associated with the protection of the long-term subscriber's identifier, performing, by the UE, based on the configuration update, the security procedure to protect the long-term subscriber's identifier, resulting in a protected long-term subscriber's identifier; determining, by the UE, whether the computation of the protected long-term subscriber's identifier was successful; and sending, by the UE, a response message to the first network, containing an acknowledgment of receipt in case of success, or failure message in case of failure.

29. The method of any of the previous claims, wherein the method further comprises, in case of failing to protect the long-term subscriber's identifier, including, by the UE, an error code associated with the protected long term subscriber's identifier computation failure and a last used identifier in the registration request and / or in the identity response message, sent to the access management function, wherein the last used identifier is one of a globally unique temporary identifier and a Subscription Concealed Identifier, SUCL30. The method of any of the previous claims, wherein in case of failing to protect the long-term subscriber's identifier, the method comprises the following:search and select, by the UE, an access device associated with a network generation which does not require concealing the long term subscriber's identifier using the scheme or method subject to failure; attach or register, by the UE, to the network and send a message, indicating the error code associated with concealed long term identifier computation failure and / or parameters for replay protection, to request a parameters update; and receive updated parameters associated with concealed long term identifier computation.

31. The method of any of the previous claims, wherein the method comprises a UE configured to perform, in case of failing to protect the long-term subscriber's identifier, a registration procedure, wherein the UE identifier is set to one of the following: subscriber concealed identifier computed using a null protection scheme; or subscriber permanent identifier protected using a different cryptographic algorithm / scheme; or the last used globally unique temporary identifier; or the last used subscription concealed identifier, SUCI; or the permanent equipment identifier.

32. An apparatus configured for protection of a long-term subscriber's identifier, wherein the apparatus comprises a Universal Subscriber Identity Module, USIM, a transmitter, a receiver, a controller, a storage unit including instructions, which when executed, cause the apparatus to: store, in the USIM, a first value enabling verifying a first quantum-resistant public-key, obtain at least part of the first quantum-resistant public-key, perform a legitimacy check of the obtained part of the first quantum-resistant publickey, and upon determination that the legitimacy check is successful, the apparatus is configured to: obtain a first quantum-resistant encapsulation key andprotect the long-term subscriber's identifier using the first quantum-resistant encapsulation key, resulting in a protected long-term subscriber's identifier.

33. A computer program comprising instructions which, when executed, cause a processor to implement the method of any of Claims 1 to 31.

Citation Information

Patent Citations

  • Methods and apparatus for selecting a security profile in a wireless communication systems

    WO2024136262A1