Quantum-resistant security system between radio access network and core network for next-generation mobile networks

A system with QKD and PQC technologies secures communication protocols between radio access and core networks, addressing post-quantum threats by managing security functions, ensuring confidentiality and integrity, and maintaining network resilience.

WO2026089681A1PCT designated stage Publication Date: 2026-04-30TURKCELL TEKNOLOJI ARASTIRMA & GELISTIRME AS +1
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2026-04-30

AI Technical Summary

Technical Problem

Existing communication protocols between radio access network and core network in next-generation mobile networks are vulnerable to post-quantum threats due to the potential of quantum computers to breach traditional encryption methods, necessitating the development of new security architectures to ensure network integrity and resilience.

Method used

A system comprising a security management server, data protection server, network configuration server, monitoring and reporting server, secure session establishment server, and redundancy and load balancing server, utilizing quantum key distribution (QKD) and post-quantum cryptography (PQC) to manage and secure communication protocols, ensuring confidentiality, integrity, and continuous monitoring against post-quantum threats.

Benefits of technology

The system provides robust protection against post-quantum threats by enabling secure communication, continuous monitoring, and efficient network operation, ensuring data confidentiality, integrity, and resilience through dynamic key management and load balancing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure TR2024051684_30042026_PF_FP_ABST
    Figure TR2024051684_30042026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a system (1) for protecting communication protocols between the radio access network (R) and the core network (C) in next generation mobile networks against post-quantum threats.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] QUANTUM-RESISTANT SECURITY SYSTEM BETWEEN RADIO ACCESS NETWORK AND CORE NETWORK FOR NEXTGENERATION MOBIEE NETWORKS

[0002] Technical Field

[0003] The present invention relates to a system for protecting communication protocols between radio access network and core network in next generation mobile networks against post-quantum threats.

[0004] Background of the Invention

[0005] Today, in next generation mobile networks, the protection of communication protocols between radio access network (RAN) and core network against postquantum threats has become an important security issue. Since the development of quantum computers has the potential to breach traditional encryption methods, existing protocols need to be updated. In this context, it is important to study alternative methods in order to increase the quantum resilience of encryption algorithms, especially those used during data transmission. Furthermore, it has become a critical need to develop new security architectures in order to ensure the integrity of the network and to increase resilience against possible attacks.

[0006] For this reason, it is understood that there is a need for a system for protecting communication protocols between radio access network and core network in next generation mobile networks against post-quantum threats.

[0007] The Chinese patent document no. CN112600627, an application included in the state of the art, discloses a quantum secret communication network system based on an SDN space division multiplexing optical network. The said invention provides a quantum secret communication network system based on an SDN (Software-defined networking) space division multiplexing optical network. The system comprises an SDN controller, a space division multiplexing optical switching network and a QKD security gateway. The SDN controller is connected with the space division multiplexing optical switching network and the QKD security gateway, and the optical network transmission link is constructed by adopting the multi-core / few-mode optical fiber, in this way, the number of available channels which is several times or even dozens of times that of traditional singlemode optical fibers is provided, and the network transmission capacity is effectively improved. Based on an SDN management and control framework, a logic centralized management and control mechanism is adopted, a network global view is constructed, the real-time performance of network management and control is improved, and the use efficiency of network resources is improved. The QKD system is deployed in the network, and reliable and safe secret communication service can be provided for the terminal.

[0008] Summary of the Invention

[0009] An object of the present invention is to realize a system developed with the aim of protecting communication protocols between the radio access network and the core network in next generation mobile networks against post-quantum threats.

[0010] Detailed Description of the Invention

[0011] The “Quantum-Resistant Security System Between Radio Access Network and Core Network for Next- Generation Mobile Networks” realized to fulfd the objective of the present invention is shown in the figure attached, in which:

[0012] Figure 1 is a schematic view of the inventive system. The components illustrated in the figure are individually numbered, where the numbers refer to the following:

[0013] 1. System

[0014] 2. Security Management Server

[0015] 3. Data Protection Server

[0016] 4. Network Configuration Server

[0017] 5. Monitoring and Reporting Server

[0018] 6. Secure Session Establishment Server

[0019] 7. Redundancy and Load Balancing Server

[0020] R. Radio Access Network

[0021] C. Core Network

[0022] The inventive system (1) developed with the aim of protecting communication protocols between the radio access network (R) and the core network (C) in next generation mobile networks against post-quantum threats comprises

[0023] at least one security management server (2) which is configured to provide the secure communication between radio access and core networks in next generation mobile networks by managing critical security functions; and at least one data protection server (3) which is configured to enable the confidentiality and integrity of data transmitted through the network by using encryption and integrity verification techniques to be protected; at least one network configuration server (4) which is configured to provide secure and efficient network operation by managing the physical and logical configuration of the network;

[0024] at least one monitoring and reporting server (5) which is configured to enable the performance and security of the network to be continuously monitored, analyzed and reported;

[0025] at least one secure session establishment server (6) which is configured to enable secure session keys to be created and managed for users and devices, and a secure connection to be established; and at least one redundancy and load balancing server (7) which is configured to enable the continuous service robustness and high performance to be guaranteed by managing the redundancy and load balance of the network.

[0026] The security management server (2) included in the inventive system (1) is configured to enable suitable authorization levels to be determined by verifying the identity of devices and users wanting to connect to network, and access to network resources to be controlled according to these authorization levels. The security management server (2) is configured to provide secure communication by managing the distribution, renewal and revocation of the required encryption keys. The security management server (2) is configured to enable post-quantum secure key exchange to be supported by using quantum key distribution (QKD) and postquantum cryptography (PQC) algorithms. The security management server (2) is configured to enable the management of dynamically generated session keys by operating in integration with the secure session establishment server (6). The security management server (2) is configured to enable data to be accessible only by authorized users. The security management server (2) is configured to enable the encryption keys required by the data protection server (3) to be distributed. The security management server (2) is configured to provide the authentication and authorization policies required by the network configuration server (4) in order to protect the integrity of the network and prevent unauthorized access. The security management server (2) is configured to provide the necessary information used in the monitoring and reporting of security-related events and alarms that the monitoring and reporting server (5) utilizes. The security management server (2) is configured to enable users and devices to securely connect to the network by working with the secure session establishment server (6), and the process to include the distribution and management of generated QKD and PQC-based secure session keys. The security management server (2) is configured to enable the redundancy and load balance policies of the network to be securely applied with the redundancy and load balancing server (7), and to help the continuity and performance of the system be maintained, especially in safety-critical systems and components. The data protection server (3) included in the inventive system (1) is configured to enable data to be transmitted and stored securely by using encryption and integrity verification techniques that are resistant to post-quantum security threats. The data protection server (3) is configured to enable data encryption methods suitable for the algorithms determined by the security management server (2) to be selected, and data to be made suitable for the encryption method that will be used. The data protection server (3) is configured to ensure the confidentiality of the data as it is transmitted between the radio access network (R) and the core network (C) by encrypting the data with strong encryption algorithms. The data protection server (3) is configured to enable suitable dynamic encryption operations to be performed by taking the determined security keys as reference. The data protection server (3) is configured to ensure that data sent with specific signature algorithms reaches the recipient without being changed, and to send alerts to the relevant parties if any changes are made on the data by detecting this change. The data protection server (3) is configured to enable data integrity and signing operations to be performed by using keys provided by the security management server (2).

[0027] The network configuration server (4) included in the inventive system (1) is configured to enable the connections between the radio access network (R) and the core network (C) in next generation mobile networks to be managed and configured. The network configuration server (4) is configured to enable the network to operate efficiently and securely by carrying out the necessary configuration and management functions. The network configuration server (4) is configured to enable the physical and logical structure of the network to be identified and managed. The network configuration server (4) is configured to enable the connections, paths and gateways between network devices to be configured and the network topology to be optimized in accordance with redundancy and load balance requirements. The network configuration server (4) is configured to enable network protocols (in the form of IP, MPLS) to be configured and managed. The network configuration server (4) is configured to enable the integration of security protocols (such as IPsec, SSL / TLS) and QKD / PQC mechanisms into the network to be managed and the protocols used for network traffic and data transmission to be updated. The network configuration server (4) is configured to enable network devices and users to be managed in accordance with the authentication and authorization policies provided by the security management server (2). The network configuration server (4) is configured to ensure the security of network protocols by using encryption keys provided by the security management server (2). The network configuration server (4) is configured to enable network performance and security to be continuously monitored by working with the monitoring and reporting server and to provide information about network configuration changes, performance decreases and security breaches. The network configuration server (4) is configured to support the establishment of secure connections and sessions by working in integration with the secure session establishment server (6). The network configuration server (4) is configured to enable the topology of the network to be configured appropriately in order to meet redundancy and load balance requirements by working in integration with the redundancy and load balancing module.

[0028] The monitoring and reporting server (5) included in the inventive system (1) is configured to enable the performance and security of the network to be continuously monitored, analyzed and information about the state of the network to be reported to network administrators. The monitoring and reporting server (5) is configured to enable the overall performance and health of the network in the form of data transmission rates, latency and packet loss to be monitored, and early warnings that determine performance decrease and enable rapid intervention to be realized. The monitoring and reporting server (5) is configured to enable load imbalances to be detected and reported by working in integration with the redundancy and load balancing server (7). The monitoring and reporting server (5) is configured to enable configuration changes to be monitored and evaluated in terms of their impact on performance and security with the information provided by the network configuration server (4). The monitoring and reporting server (5) is configured to enable security breaches, suspicious activities and potential threats to be monitored and recorded, security-related events to be analyzed and recommendations that will enable appropriate security measures to be taken to be made. The monitoring and reporting server (5) is configured to enable the effectiveness of security policies and protocols to be evaluated and improvement recommendations to be provided to the security management server (2). The monitoring and reporting server (5) is configured to enable any security or performance issues that emerge during and after secure session establishment to be monitored by the monitoring and reporting server (5) through information received from the secure session establishment server.

[0029] The secure session establishment server (6) included in the inventive system (1) is configured to provide security against post-quantum threats by using QKD and PQC technologies, especially in next generation mobile networks. The secure session establishment server (6) is configured to enable secure session keys to be generated by using QKD and PQC techniques, and the generated keys to be unique and unpredictable. The secure session establishment server (6) is configured to enable users and devices to authenticate and authorize their identity during the login process; session keys to be shared only with authorized users and devices; and to provide access control in accordance with security policies and protocols. The secure session establishment server (6) is configured to enable authentication information and keys required for secure session establishment to be managed by working in integration with the security management server (2). The secure session setup server (6) is configured to enable secure connections between network devices and protocols to be established by working in integration with the network configuration server (4). The secure session setup server (6) is configured to provide configurations required for secure session establishment.

[0030] The redundancy and load balancing server (7) included in the inventive system (1) is configured to enable failures to be tolerated and resources to be used efficiently. The redundancy and load balancing server (7) is configured to enable system resources to be optimally used by balancing network traffic and workload, and continuity of redundancy mechanisms to be guaranteed in the event of failure of any system component. The redundancy and load balancing server (7) is configured to enable redundant configurations to be created and managed in devices and connection paths, and protection against system outages to be offered by providing redundancy between data centers, servers and network devices with automatic fail-over mechanisms in the event of failure of any component. The redundancy and load balancing server (7) is configured to enable overload on a single server or network connection to be avoided by dynamic distribution of network traffic and workloads. The redundancy and load balancing server (7) is configured to enable existing resources to be used in the best possible way by distribution of user requests and network traffic among multiple servers or gateways; performance to be optimized and resources to be used efficiently. The redundancy and load balancing server (7) is configured to provide security redundancy and contingency planning by working in integration with the security management server (2). The redundancy and load balancing server (7) is configured to enable backup systems to be activated in accordance with security measures in the event of security breaches or system failures. The redundancy and load balancing server (7) is configured to enable redundancy and load balancing strategies to be compatible with the network topology and protocols identified by the network configuration server (4) and network configurations to be adjusted so as to meet redundancy and load balancing requirements. The redundancy and load balancing server (7) is configured to provide regular information about system performance and redundancy status to the monitoring and reporting server.

[0031] Industrial Application of the Invention

[0032] By means of the inventive system (1), protection of communication protocols between the radio access network (R) and the core network (C) in next generation mobile networks against post-quantum threats is ensured. Within these basic concepts; it is possible to develop various embodiments of the inventive “Quantum-Resistant Security System (1) Between Radio Access Network and Core Network for Next- Generation Mobile Networks”; the invention cannot be limited to examples disclosed herein and it is essentially according to claims.

Claims

CLAIMS1. A system (1) which enables communication protocols between the radio access network (R) and the core network (C) in next generation mobile networks against post-quantum threats to be protected; comprisingat least one security management server (2) which is configured to provide the secure communication between radio access and core networks in next generation mobile networks by managing critical security functions; andcharacterized byat least one data protection server (3) which is configured to enable the confidentiality and integrity of data transmitted through the network by using encryption and integrity verification techniques to be protected; at least one network configuration server (4) which is configured to provide secure and efficient network operation by managing the physical and logical configuration of the network;at least one monitoring and reporting server (5) which is configured to enable the performance and security of the network to be continuously monitored, analyzed and reported;at least one secure session establishment server (6) which is configured to enable secure session keys to be created and managed for users and devices, and a secure connection to be established; andat least one redundancy and load balancing server (7) which is configured to enable the continuous service robustness and high performance to be guaranteed by managing the redundancy and load balance of the network.

2. A system (1) according to Claim 1; characterized by the security management server (2) which is configured to enable suitable authorization levels to be determined by verifying the identity of devices and users wanting to connect to network, and access to network resources to be controlled according to these authorization levels.

3. A system (1) according to Claim 1 or 2; characterized by the security management server (2) which is configured to provide secure communication by managing the distribution, renewal and revocation of the required encryption keys.

4. A system (1) according to any one of the preceding claims; characterized by the security management server (2) which is configured to enable post-quantum secure key exchange to be supported by using quantum key distribution (QKD) and post-quantum cryptography (PQC) algorithms.

5. A system (1) according to any one of the preceding claims; characterized by the security management server (2) which is configured to enable the management of dynamically generated session keys by operating in integration with the secure session establishment server (6).

6. A system (1) according to any one of the preceding claims; characterized by the security management server (2) which is configured to enable data to be accessible only by authorized users.

7. A system (1) according to any one of the preceding claims; characterized by the security management server (2) which is configured to enable the encryption keys required by the data protection server (3) to be distributed.

8. A system (1) according to any one of the preceding claims; characterized by the security management server (2) which is configured to provide the authentication and authorization policies required by the network configuration server (4) in order to protect the integrity of the network and prevent unauthorized access.

9. A system (1) according to any one of the preceding claims; characterized by the security management server (2) which is configured to provide the necessaryinformation used in the monitoring and reporting of security -related events and alarms that the monitoring and reporting server (5) utilizes.

10. A system (1) according to any one of the preceding claims; characterized by the security management server (2) which is configured to enable users and devices to securely connect to the network by working with the secure session establishment server (6), and the process to include the distribution and management of generated QKD and PQC -based secure session keys.

11. A system (1) according to any one of the preceding claims; characterized by the security management server (2) which is configured to enable the redundancy and load balance policies of the network to be securely applied with the redundancy and load balancing server (7), and to help the continuity and performance of the system be maintained, especially in safety-critical systems and components.

12. A system (1) according to any one of the preceding claims; characterized by the data protection server (3) which is configured to enable data to be transmitted and stored securely by using encryption and integrity verification techniques that are resistant to post-quantum security threats.

13. A system (1) according to any one of the preceding claims; characterized by the data protection server (3) which is configured to enable data encryption methods suitable for the algorithms determined by the security management server (2) to be selected, and data to be made suitable for the encryption method that will be used.

14. A system (1) according to any one of the preceding claims; characterized by the data protection server (3) which is configured to ensure the confidentiality of the data as it is transmitted between the radio access network (R) and the core network (C) by encrypting the data with strong encryption algorithms.

15. A system (1) according to any one of the preceding claims; characterized by the data protection server (3) which is configured to enable suitable dynamic encryption operations to be performed by taking the determined security keys as reference.

16. A system (1) according to any one of the preceding claims; characterized by the data protection server (3) which is configured to ensure that data sent with specific signature algorithms reaches the recipient without being changed, and to send alerts to the relevant parties if any changes are made on the data by detecting this change.

17. A system (1) according to any one of the preceding claims; characterized by the data protection server (3) which is configured to enable data integrity and signing operations to be performed by using keys provided by the security management server (2).

18. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to enable the connections between the radio access network (R) and the core network (C) in next generation mobile networks to be managed and configured.

19. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to enable the network to operate efficiently and securely by carrying out the necessary configuration and management functions.

20. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to enable the physical and logical structure of the network to be identified and managed.

21. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to enable the connections, paths and gateways between network devices to be configured and the network topology to be optimized in accordance with redundancy and load balance requirements.

22. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to enable network protocols (in the form of IP, MPLS) to be configured and managed.

23. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to enable the integration of security protocols (such as IPsec, SSL / TLS) and QKD / PQC mechanisms into the network to be managed and the protocols used for network traffic and data transmission to be updated.

24. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to enable network devices and users to be managed in accordance with the authentication and authorization policies provided by the security management server (2).

25. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to ensure the security of network protocols by using encryption keys provided by the security management server (2).

26. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to enable network performance and security to be continuously monitored by working with the monitoring and reporting server and to provide information about network configuration changes, performance decreases and security breaches.

27. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to support the establishment of secure connections and sessions by working in integration with the secure session establishment server (6).

28. A system (1) according to any one of the preceding claims; characterized by the network configuration server (4) which is configured to enable the topology of the network to be configured appropriately in order to meet redundancy and load balance requirements by working in integration with the redundancy and load balancing module.

29. A system (1) according to any one of the preceding claims; characterized by the monitoring and reporting server (5) which is configured to enable the performance and security of the network to be continuously monitored, analyzed and information about the state of the network to be reported to network administrators.

30. A system (1) according to any one of the preceding claims; characterized by the monitoring and reporting server (5) which is configured to enable the overall performance and health of the network in the form of data transmission rates, latency and packet loss to be monitored, and early warnings that determine performance decrease and enable rapid intervention to be realized.

31. A system (1) according to any one of the preceding claims; characterized by the monitoring and reporting server (5) which is configured to enable load imbalances to be detected and reported by working in integration with the redundancy and load balancing server (7).

32. A system (1) according to any one of the preceding claims; characterized by the monitoring and reporting server (5) which is configured to enableconfiguration changes to be monitored and evaluated in terms of their impact on performance and security with the information provided by the network configuration server (4).

33. A system (1) according to any one of the preceding claims; characterized by the monitoring and reporting server (5) which is configured to enable security breaches, suspicious activities and potential threats to be monitored and recorded, security-related events to be analyzed and recommendations that will enable appropriate security measures to be taken to be made.

34. A system (1) according to any one of the preceding claims; characterized by the monitoring and reporting server (5) which is configured to enable the effectiveness of security policies and protocols to be evaluated and improvement recommendations to be provided to the security management server (2).

35. A system (1) according to any one of the preceding claims; characterized by the monitoring and reporting server (5) which is configured to enable any security or performance issues that emerge during and after secure session establishment to be monitored by the monitoring and reporting server (5) through information received from the secure session establishment server.

36. A system (1) according to any one of the preceding claims; characterized by the secure session establishment server (6) which is configured to provide security against post-quantum threats by using QKD and PQC technologies, especially in next generation mobile networks.

37. A system (1) according to any one of the preceding claims; characterized by the secure session establishment server (6) which is configured to enable secure session keys to be generated by using QKD and PQC techniques, and the generated keys to be unique and unpredictable.

38. A system (1) according to any one of the preceding claims; characterized by the secure session establishment server (6) which is configured to enable users and devices to authenticate and authorize their identity during the login process; session keys to be shared only with authorized users and devices; and to provide access control in accordance with security policies and protocols.

39. A system (1) according to any one of the preceding claims; characterized by the secure session establishment server (6) which is configured to enable authentication information and keys required for secure session establishment to be managed by working in integration with the security management server (2).

40. A system (1) according to any one of the preceding claims; characterized by the secure session establishment server (6) which is configured to enable secure connections between network devices and protocols to be established by working in integration with the network configuration server (4).

41. A system (1) according to any one of the preceding claims; characterized by the secure session establishment server (6) which is configured to provide configurations required for secure session establishment.

42. A system (1) according to any one of the preceding claims; characterized by the redundancy and load balancing server (7) which is configured to enable failures to be tolerated and resources to be used efficiently.

43. A system (1) according to any one of the preceding claims; characterized by the redundancy and load balancing server (7) which is configured to enable system resources to be optimally used by balancing network traffic and workload, and continuity of redundancy mechanisms to be guaranteed in the event of failure of any system component.

44. A system (1) according to any one of the preceding claims; characterized by the redundancy and load balancing server (7) which is configured to enable redundant configurations to be created and managed in devices and connection paths, and protection against system outages to be offered by providing redundancy between data centers, servers and network devices with automatic fail-over mechanisms in the event of failure of any component.

45. A system (1) according to any one of the preceding claims; characterized by the redundancy and load balancing server (7) which is configured to enable overload on a single server or network connection to be avoided by dynamic distribution of network traffic and workloads.

46. A system (1) according to any one of the preceding claims; characterized by the redundancy and load balancing server (7) which is configured to enable existing resources to be used in the best possible way by distribution of user requests and network traffic among multiple servers or gateways; performance to be optimized and resources to be used efficiently.

47. A system (1) according to any one of the preceding claims; characterized by the redundancy and load balancing server (7) which is configured to provide security redundancy and contingency planning by working in integration with the security management server (2).

48. A system (1) according to any one of the preceding claims; characterized by the redundancy and load balancing server (7) which is configured to enable backup systems to be activated in accordance with security measures in the event of security breaches or system failures.

49. A system (1) according to any one of the preceding claims; characterized by the redundancy and load balancing server (7) which is configured to enable redundancy and load balancing strategies to be compatible with the networktopology and protocols identified by the network configuration server (4) and network configurations to be adjusted so as to meet redundancy and load balancing requirements.

50. A system (1) according to any one of the preceding claims; characterized by the redundancy and load balancing server (7) which is configured to provide regular information about system performance and redundancy status to the monitoring and reporting server.

Citation Information

Patent Citations

  • Quantum data link security terminal and security communication network

    CN110289952A

  • Security protocol agility migration method and system realized based on SDN (Software Defined Network)

    CN118381667A

  • Post-quantum cryptographic communication protocol

    US10581604B2

  • Systems and methods for post-quantum cryptography communications channels

    US11218300B1

  • Systems and methods for device grouping based on quantum resistant encryption capability

    US20230254133A1