Method and device for selectively protecting network slice identifier on basis of quantum security
PQC-based encryption and decryption methods secure network slice identifiers, addressing quantum attacks and improving AMF/SMF relocation efficiency in 5G wireless communication systems.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- SAMSUNG ELECTRONICS CO LTD
- Filing Date
- 2025-09-22
- Publication Date
- 2026-05-07
AI Technical Summary
Existing 5G wireless communication systems lack effective methods to protect network slice identifiers from quantum computer-based attacks and efficiently relocate or reselect AMF or SMF for a specific network slice identifier after a security context is established between a terminal and a network entity.
Implementing Post Quantum Cryptography (PQC) based encryption and decryption methods to secure network slice identifiers, including generating shared keys and encrypting/decrypting network slice identifiers using PQC algorithms, ensuring protection and efficient relocation of AMF or SMF as needed.
Effectively protects network slice identifiers from quantum computer-based attacks and improves the inefficiency of relocating or reselecting AMF or SMF, enhancing security and efficiency in network slice management.
Smart Images

Figure KR2025095597_07052026_PF_FP_ABST
Abstract
Description
Method and device for protecting selective network slice identifiers based on quantum security
[0001] The present disclosure relates to a wireless communication system, and more specifically, to a method and apparatus for selectively protecting a network slice identifier based on quantum security.
[0002] 5G wireless communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in frequency bands below 6 GHz ('Sub 6 GHz'), such as 3.5 gigahertz (3.5 GHz), but also in ultra-high frequency bands called millimeter waves (mmWave), such as 28 GHz and 39 GHz ('Above 6 GHz'). In addition, for 6G wireless communication technology, which is referred to as a system beyond 5G communication, implementation in the terahertz band (e.g., the 3 terahertz (3 THz) band at 95 GHz) is being considered to achieve transmission speeds 50 times faster and ultra-low latency reduced to one-tenth compared to 5G wireless communication technology.
[0003] In the early stages of 5G wireless communication technology, aiming to satisfy service support and performance requirements for enhanced Mobile BroadBand (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), technologies such as beamforming and Massive MIMO to mitigate path loss and increase transmission distance in ultra-high frequency bands, support for various numerologies (such as the operation of multiple subcarrier spacing) and dynamic operation of slot formats for the efficient utilization of ultra-high frequency resources, initial access technologies to support multi-beam transmission and broadband, definition and operation of Band-Width Parts (BWP), Low Density Parity Check (LDPC) codes for high-volume data transmission, new channel coding methods such as Polar Codes for the reliable transmission of control information, and L2 pre-processing (L2 Standardization has been carried out for pre-processing, network slicing which provides a dedicated network specialized for specific services, and other methods.
[0004] Currently, discussions are underway to improve and enhance the performance of the initial 5G wireless communication technology, taking into account the services that the 5G wireless communication technology was intended to support. Additionally, standardization of the physical layer is in progress for technologies such as V2X (Vehicle-to-Everything), which helps autonomous vehicles make driving decisions and enhance user convenience based on their own location and status information transmitted by the vehicle; NR-U (New Radio Unlicensed), which aims for system operation in unlicensed bands that meets various regulatory requirements; NR terminal low power consumption technology (UE Power Saving); Non-Terrestrial Network (NTN), which is direct terminal-satellite communication for securing coverage in areas where communication with the terrestrial network is impossible; and positioning.
[0005] In addition, standardization is underway in the field of wireless interface architecture / protocols for technologies such as the Industrial Internet of Things (IIoT) for supporting new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) which provides nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement including Conditional Handover and Dual Active Protocol Stack (DAPS) Handover, and 2-step Random Access (2-step RACH for NR) which simplifies random access procedures. Standardization is also underway in the field of system architecture / services for 5G baseline architectures (e.g., Service based Architecture, Service based Interface) for incorporating Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC), which provides services based on the location of the terminal.
[0006] When such 5G wireless communication systems are commercialized, connected devices, which are increasing explosively, will be connected to communication networks. Accordingly, it is expected that there will be a need to enhance the functionality and performance of 5G wireless communication systems and to integrate the operation of connected devices. To this end, new research is planned to be conducted on 5G performance improvement and complexity reduction, support for AI services, support for metaverse services, and drone communication using eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).
[0007] Furthermore, the advancement of these 5G wireless communication systems encompasses multi-antenna transmission technologies such as new waveforms, Full Dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas to guarantee coverage in the terahertz band of 6G wireless communication technology; metamaterial-based lenses and antennas; high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM); and Reconfigurable Intelligent Surface (RIS) technology to improve terahertz band signal coverage; as well as full-duplex technology for enhancing frequency efficiency and system networks; AI-based communication technologies that realize system optimization by utilizing satellites and Artificial Intelligence (AI) from the design stage and internalizing end-to-end AI support functions; and the realization of services of complexity exceeding the limits of terminal computing capabilities by utilizing ultra-high-performance communication and computing resources. It could serve as a foundation for the development of next-generation distributed computing technologies.
[0008] The technical problem of the present disclosure is to provide a method and apparatus capable of effectively protecting network slice identifiers from quantum computer-based attacks.
[0009] Furthermore, the technical problem of the present disclosure is to provide a method and apparatus capable of improving the inefficiency of the prior art that occurs by relocating or reselecting an AMF or SMF for a specific network slice identifier after a security context is established between a terminal and a network entity.
[0010] The technical problems to be solved in the various embodiments of the present disclosure are not limited to those mentioned above, and other technical problems not mentioned may be considered by those skilled in the art from the various embodiments of the present disclosure described below.
[0011] In one embodiment of the present disclosure, a method performed by a User Equipment (UE) in a wireless communication system is provided, the method may include: identifying whether a network slice identifier contains first information indicating that Post Quantum Cryptography (PQC) based encryption is performed on the network slice identifier; if the network slice identifier contains the first information, performing the PQC based encryption on the network slice identifier to obtain a protected network slice identifier; and transmitting a message containing the protected network slice identifier to a network entity.
[0012] In one embodiment of the present disclosure, a user equipment (UE) for a wireless communication system is provided, the UE comprises a transceiver; and a processor connected to the transceiver, the processor being configured to identify whether a network slice identifier includes first information indicating that Post Quantum Cryptography (PQC) based encryption is performed on the network slice identifier, and if the network slice identifier includes the first information, to perform the PQC based encryption on the network slice identifier to obtain a protected network slice identifier, and to control the transceiver to transmit a message containing the protected network slice identifier to a network entity.
[0013] In one embodiment of the present disclosure, the message may further include second information indicating a profile of an algorithm for PQC-based encryption and third information indicating a shared key generation method and an encryption method for PQC-based encryption.
[0014] In one embodiment of the present disclosure, the message may further include fourth information indicating the profile of the algorithm for the PQC-based encryption and the shared key generation method and encryption method for the PQC-based encryption.
[0015] In one embodiment of the present disclosure, the PQC-based encryption may include generating a first shared key based on the public key of the network entity and the private key of the UE, generating a second shared key based on the PQC-based public key of the network entity, generating a third shared key based on the first shared key and the second shared key, and encrypting the network slice identifier based on the third shared key.
[0016] In one embodiment of the present disclosure, generating the first shared key includes generating the first shared key using asymmetric key consensus based on the public key of the network entity and the private key of the UE, generating the second shared key includes generating the second shared key using PQC key encapsulation based on the PQC-based public key of the network entity, and generating the third shared key may include generating the third shared key by performing an XOR (Exclusive OR) operation on the first shared key and the second shared key.
[0017] In one embodiment of the present disclosure, the PQC-based encryption may include generating a ciphertext by performing encryption on the network slice identifier based on the public key of the network entity, and performing a PQC algorithm on the ciphertext based on the PQC-based public key of the network entity.
[0018] In one embodiment of the present disclosure, generating the ciphertext may include generating a key pair of the public key and private key of the UE, generating a shared key based on the public key of the network entity and the private key of the UE, and generating the ciphertext by encrypting the network slice identifier based on the shared key.
[0019] In one embodiment of the present disclosure, the message is an initial registration request message, and the method may further include the step of receiving a registration acceptance message from the network entity, which includes an allowed network slice identifier, in response to the initial registration request message.
[0020] In one embodiment of the present disclosure, the network slice identifier is S-NSSAI (Single Network Slice Assistance Information), and the S-NSSAI may include the first information, information regarding SST (Slice / Service Type), and information regarding SD (Service Differentiator).
[0021] In one embodiment of the present disclosure, a method performed by a network entity in a wireless communication system is provided, the method may include the step of receiving a message containing an encrypted network slice identifier from a user device (User Equipment, UE), wherein the encrypted network slice identifier includes information regarding a protected network slice identifier and a protection method for said protected network slice identifier; and the step of obtaining a network slice identifier by performing Post Quantum Cryptography (PQC) based decryption on said protected network slice identifier based on the information regarding said protection method.
[0022] In one embodiment of the present disclosure, a network entity for a wireless communication system is provided, the network entity comprises a transceiver; and a processor connected to the transceiver, the processor receiving a message containing an encrypted network slice identifier from a User Equipment (UE), the encrypted network slice identifier comprising information regarding a protected network slice identifier and a protection method for the protected network slice identifier, and may be configured to obtain a network slice identifier by performing Post Quantum Cryptography (PQC) based decryption on the protected network slice identifier based on the information regarding the protection method.
[0023] In one embodiment of the present disclosure, the PQC-based decoding may include obtaining a first shared key based on the public key of the UE and the private key of the network entity, generating a second shared key based on the PQC-based public key of the network entity, generating a third shared key based on the first shared key and the second shared key, and decoding the protected network slice identifier based on the third shared key.
[0024] In one embodiment of the present disclosure, generating the first shared key includes generating the first shared key using asymmetric key consensus based on the public key of the UE and the private key of the network entity, generating the second shared key includes generating the second shared key using PQC key encapsulation based on the PQC-based public key of the network entity, and generating the third shared key may include generating the third shared key by performing an XOR (Exclusive OR) operation on the first shared key and the second shared key.
[0025] In one embodiment of the present disclosure, the PQC-based decryption may include generating an intermediate ciphertext by performing a PQC algorithm on the protected network slice identifier based on the PQC-based private key of the network entity, and performing decryption on the intermediate ciphertext based on the private key of the network entity.
[0026] In one embodiment of the present disclosure, performing decryption on the intermediate ciphertext may include generating a shared key based on the public key of the UE and the private key of the network entity, and performing decryption on the intermediate ciphertext based on the shared key.
[0027] In one embodiment of the present disclosure, the message is an initial registration request message, and the method may further include the steps of: selecting an Access and Mobility Management Function (AMF) or a Session Management Function (SMF) based on the network slice identifier; and transmitting the registration request message to the selected AMF or SMF.
[0028] According to the present disclosure, network slice identifiers can be effectively protected from quantum computer-based attacks.
[0029] In addition, according to the present disclosure, the inefficiency of the prior art can be effectively improved because the AMF or SMF for a specific network slice identifier can be immediately relocated or reselected even before a security context is established between the terminal and the network entity.
[0030] The effects obtainable in the present disclosure are not limited to those mentioned in the various embodiments, and other unmentioned effects will be clearly understood by those skilled in the art to which the present disclosure pertains from the description below.
[0031] Figure 1 illustrates a structure in which a wireless communication system provides a network slice according to an SLA received in the form of GSMA's GST / NEST.
[0032] Figure 2 illustrates the format of S-NSSAI.
[0033] Figure 3 illustrates NSSAI.
[0034] Figure 4 illustrates a procedure for using NSSAI.
[0035] Figure 5 illustrates the procedure for setting an allowed NSSAI through an initial registration procedure.
[0036] FIG. 6 illustrates a network slice identifier according to one embodiment of the present disclosure.
[0037] FIG. 7 illustrates a network slice identifier according to one embodiment of the present disclosure.
[0038] FIG. 8 illustrates a method for encrypting a network slice identifier according to the proposed method 2 of the present disclosure.
[0039] FIG. 9 illustrates an embodiment of an encryption method according to the present disclosure.
[0040] FIG. 10 illustrates an embodiment of an encryption method according to the proposed method 2 of the present disclosure.
[0041] FIG. 11 illustrates the operation procedure of a UE and a network entity according to the proposed method 2 of the present disclosure.
[0042] FIG. 12 illustrates a method for encrypting a network slice identifier according to the proposed method 3 of the present disclosure.
[0043] FIG. 13 illustrates an embodiment of an encryption method according to the proposed method 3 of the present disclosure.
[0044] FIG. 14 illustrates a registration procedure according to the proposed method 4 of the present disclosure.
[0045] FIG. 15 illustrates a fallback procedure 1 according to the proposed method 5 of the present disclosure.
[0046] FIG. 16 illustrates a fallback procedure 2 according to the proposed method 5 of the present disclosure.
[0047] FIG. 17 illustrates a flowchart of a method performed by a terminal according to the proposed method of the present disclosure.
[0048] FIG. 18 illustrates a flowchart of a method performed by a network entity according to the proposed method of the present disclosure.
[0049] FIG. 19 illustrates the structure of a terminal to which the proposed method of the present disclosure can be applied.
[0050] FIG. 20 illustrates the structure of a network entity to which the proposed method of the present disclosure can be applied.
[0051] FIG. 21 illustrates a communication system to which the proposed method of the present disclosure can be applied.
[0052] Embodiments of the present disclosure will be described in detail below with reference to the attached drawings.
[0053] In describing the embodiments, if a detailed description of a known function or configuration related to the present disclosure could unnecessarily obscure the essence of the present disclosure, such detailed description will be omitted.
[0054] For the same reason, some components in the attached drawings have been exaggerated, omitted, or schematically depicted. Additionally, the size of each component does not entirely reflect its actual dimensions. Identical or corresponding components in each drawing have been assigned the same reference number.
[0055] The advantages and features of the present disclosure and the methods for achieving them will become clear by referring to the embodiments described below in detail together with the accompanying drawings.
[0056] Furthermore, the present disclosure is not limited to the embodiments disclosed below but may be implemented in various different forms, and the embodiments provided merely to complete the configuration of the present disclosure and to fully inform those skilled in the art of the scope of the invention, and the present disclosure is defined only by the scope of the claims. Throughout the specification, the same reference numerals refer to the same components.
[0057] For the convenience of the following description, some terms and names defined in 3GPP (3rd generation partnership project) standards (specifications for 5G, NR, LTE, or similar systems) may be used. Additionally, terms and names newly defined in next-generation communication systems to which this disclosure applies (e.g., 6G, Beyond 5G systems) or used in existing communication systems may be used. The use of such terms is not limited by the terms and names of this disclosure and may be applied equally to systems conforming to other standards, and may be modified in other forms without departing from the technical spirit of this disclosure. Embodiments of this disclosure can be easily modified and applied to other communication systems.
[0058] Additionally, in one embodiment of the present disclosure, singular expressions such as "one" and "the above" unless otherwise explicitly indicated include plural expressions.
[0059] Additionally, in one embodiment of the present disclosure, the term "and / or" includes a combination of a plurality of related described items or any of a plurality of related described items.
[0060] Furthermore, the terms used in one embodiment of the present disclosure are used merely to describe specific embodiments and are not intended to limit the present disclosure. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this specification, terms such as “comprising” or “having” are intended to indicate the presence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0061] Additionally, the terms “associated with” and “associated therewith” and their derivatives used in one embodiment of the present disclosure may mean things such as include, be included within, interconnect with, contain, be contained within, connect to or with, couple to or with, be communicated with, cooperate with, interleave, juxtapose, be proximate to, be bound to or with, have, have a property of, etc.
[0062] Additionally, in this disclosure, expressions such as "greater than" or "less than" have been used to determine whether specific conditions are satisfied or fulfilled; however, this is merely for illustrative purposes and does not exclude descriptions of "greater than" or "less than." Conditions described as "greater than" may be replaced with "greater than," conditions described as "less than" with "less than," and conditions described as "greater than and less than" with "greater than and less than."
[0063] Prior to a detailed description of the present disclosure, examples of possible meanings for some terms used in this specification are provided. However, it should be noted that the interpretations provided below are not limited to these examples.
[0064] In the present disclosure, a terminal (or communication terminal) is a subject that communicates with a base station or another terminal and may be referred to as a node, UE (user equipment), NG UE (next generation UE), MS (mobile station), device, or terminal. Additionally, the terminal may include at least one of a smartphone, tablet PC, mobile phone, video phone, e-book reader, desktop PC, laptop PC, netbook computer, PDA, PMP (portable multimedia player), MP3 player, medical device, camera, or wearable device. Additionally, the terminal may include at least one of a television, DVD (digital video disk) player, audio, refrigerator, air conditioner, vacuum cleaner, oven, microwave, washing machine, air purifier, set-top box, home automation control panel, security control panel, media box, game console, electronic dictionary, electronic key, camcorder, or electronic photo frame.In addition, the terminal may include at least one of various medical devices (e.g., various portable medical measuring devices (blood glucose meter, heart rate monitor, blood pressure monitor, or body temperature monitor, etc.), MRA (magnetic resonance angiography), MRI (magnetic resonance imaging), CT (computed tomography), imaging device, or ultrasound device, etc.), navigation device, satellite navigation system (GNSS (global navigation satellite system)), EDR (event data recorder), FDR (flight data recorder), automotive infotainment device, marine electronic equipment (e.g., marine navigation device, gyrocompass, etc.), avionics, security device, vehicle head unit, industrial or household robot, drone, ATM of a financial institution, POS (point of sales) of a store, or Internet of Things device (e.g., light bulb, various sensor, sprinkler device, fire alarm, thermostat, street light, toaster, exercise equipment, hot water tank, heater, boiler, etc.). In addition, the terminal may include various types of multimedia systems capable of performing communication functions. Meanwhile, the present disclosure is not limited to what has been described above, and the terminal may be referred to by terms having the same or similar meaning.
[0065] In addition, in the present disclosure, the base station is an entity that communicates with a terminal and performs resource allocation for the terminal, and may have various forms and may be at least one of a gNode B, eNode B, Node B, BS (Base Station), wireless access unit, base station controller, or a node on a network. Alternatively, it may be referred to as a CU (central unit) or a DU (distributed unit) depending on the separation of functions. Meanwhile, the present disclosure is not limited thereto, and the base station may be referred to by a term having the same or similar meaning.
[0066] In addition, in this disclosure, embodiments may be described using terms used in some communication standards (e.g., 5G (NR (new radio)) or 5G (NR) systems defined by 3GPP (3rd generation partnership project)), but this is merely for illustrative purposes, and embodiments of this disclosure may be applied to other communication systems having similar technical backgrounds or channel types. Furthermore, this disclosure may be applied to other communication systems with some modifications made at the discretion of a person with technical knowledge, without departing significantly from the scope of this disclosure.
[0067] Additionally, in the present disclosure, the direction of data transmitted from a terminal may be referred to as an uplink, and the direction of data transmitted to a terminal may be referred to as a downlink. Accordingly, in the case of uplink transmission, the transmitter may refer to a terminal, and the receiver may refer to a specific network entity of a base station or communication system. Alternatively, in the case of downlink transmission, the transmitter may refer to a specific network entity of a base station or communication system, and the receiver may refer to a terminal.
[0068] Network Slicing
[0069] In wireless communication systems, network slicing technology can refer to a technology that enables the provision of hardware infrastructure resources tailored to the requirements of various services through virtualization technology. In 5G systems, the GSMA (GSM Association) and 3GPP (3 rd The Generation Partnership Project (3GPP) defines network slices such as eMBB, URLLC, and mMTC as standards, and is also standardized to allow the creation and provision of network slices by service according to operator requirements. Network slicing technology defined by 3GPP enables the provision of services for eMBB, URLLC, mMTC, and various verticals based on Service Level Agreement (SLA) requirements. It is designed so that wireless communication systems receive and apply requirements defined based on the Generic Network Slice Template (GST) and Network Slice Type (NEST) defined by the GSMA. The GST defines attributes for providing specific network slices required by eMBB, URLLC, mMTC, and various verticals. The NEST is a template form in which appropriate values are filled into the attributes defined in the GST to provide specific network slice services. GST / NEST can be used by a Network Slice Provider (NSP) to prepare a Network Slice Instance (NSI) that satisfies a specific SLA for a Network Slice Consumer (NSC).
[0070] FIG. 1 illustrates a structure in which a wireless communication system provides a network slice according to an SLA received in the form of GSMA's GST / NEST. FIG. 1 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 1.
[0071] Referring to Fig. 1, the Communications Service Management Function (CSMF) of the Communication Service Consumer (CSC) converts the GST / NEST defined by GSMA into a Service Profile defined by 3GPP and transmits it to the Network Slice Management Function (NSMF) of the Communication Service Provider (CSP). The NSMF converts the received Service Profile into a Top Slice Subnet Profile, which can then be converted into the Radio Access Network (RAN) Slice Subnet Profile, Core Network (CN) Slice Subnet Profile, and Transport Network (TN) Slice Subnet Profile, which are domain-specific profiles for each wireless communication system. According to each domain-specific profile, the Network Operator (NOP) can create network slices by setting the characteristics defined in the corresponding profile on the network components of each domain. Each domain-specific profile can be passed from the NOP to the domain-specific Network Slice Subnet Management Function (NSSMF). For example, a RAN slice subnet profile can be passed to the RAN NSSMF, a CN slice subnet profile can be passed to the CN NSSMF, and a TN slice subnet profile can be passed to the TN NSSMF. The domain-specific NSSMF can create and / or configure domain-specific slices based on the domain-specific profile.
[0072] Table 1 illustrates attributes corresponding to profiles defined by 3GPP that map to attributes defined by GSMA for GST / NEST. The attributes in Table 1 are merely examples to aid in understanding the present disclosure, and the present disclosure is not limited to the examples in Table 1. Additional attributes not exemplified in Table 1 may be included, and some of the attributes exemplified in Table 1 may be omitted.
[0073] [Table 1]
[0074]
[0075] The GST attributes exemplified in Table 1 are defined in the GSMA standard document NG.116, and the service profile attributes and RAN slice subnet profile attributes are 3GPP (3 rd The Generation Partnership Project is defined in TS (Technical Specification) 28.541, and the present disclosure incorporates the entirety of such documents by reference.
[0076] Network Slice Identifier
[0077] To use network slices created according to an SLA, 3GPP standards define Network Slice Selection Assistance Information (NSSAI), Single Network Slice Selection Assistance Information (S-NSSAI), Slice / Service Type (SST), and Service Differentiator (SD).
[0078] FIG. 2 illustrates the format of an S-NSSAI. FIG. 2 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 2. For example, in the example of FIG. 2, SST (212) and SD (214) are exemplified as 8 bits and 24 bits, respectively, but the number of bits may be changed.
[0079] A network slice can be identified using S-NSSAI (210), and S-NSSAI (210) may include SST (212) and / or SD (214). SST (212) is information indicating a network slice or service type and may have a standardized SST value or a non-standardized SST value. For example, in 3GPP standards, network slices or service types such as eMBB, URLLC, MioT (Massive Internet of Things), V2X (Vehicle to Everything), and HMTC (High Performance Machine Type Communications) are defined by standardized SST values. SD (214) is information distinguishing a network slice among multiple network slices having the same SST, and SD (214) may not be included in S-NSSAI (210) or may be omitted. Table 2 illustrates standardized SST values defined in 3GPP standards.
[0080] [Table 2]
[0081]
[0082] By distinguishing network slices and service types through SST values and differentiating network slices by various operators and service providers within the same network slice through SD values, various network slices can be distinguished by a combination of SST and SD values. Through S-NSSAI, which is a combination of SST and SD values, User Equipment (UE) can use network slices provided by the network (NW).
[0083] FIG. 3 illustrates an NSSAI. FIG. 3 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 3. For example, other types of NSSAI may be additionally defined in addition to the NSSAI types illustrated in FIG. 3, and the number of S-NSSAIs included in a single NSSAI may be any value of one or more.
[0084] NSSAI (310) may refer to a combination or set of S-NSSAIs. For example, NSSAI (310) may be a Configured NSSAI (312), a Requested NSSAI (314), an Allowed NSSAI (316), or a Subscribed NSSAI (not shown), but may be other types of NSSAI. A Configured NSSAI (312) may refer to an NSSAI configured on a UE, a Requested NSSAI (314) may refer to an NSSAI for a UE to check whether a network slice is available to a network (NW), an Allowed NSSAI (316) may refer to an NSSAI for a NW to inform a UE whether a specific network slice is available, and a Subscribed NSSAI (not shown) may refer to an NSSAI configured on a Unified Data Management (UDM).
[0085] Referring to FIG. 3, each NSSAI (312, 314, 316) may include at least one S-NSSAI, and a combination or set of S-NSSAI#1 (322), S-NSSAI#2 (324), ..., S-NSSAI#8 (326)) as exemplified in FIG. 3 may be defined as NSSAI (310). Each S-NSSAI (322, 324, 326) may have the format of an S-NSSAI as described with reference to FIG. 2.
[0086] FIG. 4 illustrates a procedure for using NSSAI. FIG. 4 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 4. For example, in the example of FIG. 4, the configured NSSAI and subscribed NSSAI are illustrated as having up to 16 S-NSSAIs, and the requested NSSAI and allowed NSSAI are illustrated as having up to 8 S-NSSAIs, but the maximum number of S-NSSAIs included in each NSSAI may change. Additionally, in the example of FIG. 4, the number of S-NSSAIs included in each NSSAI may change, and the values of SST and SD may also change.
[0087] Referring to FIG. 4, it is assumed that a configuration NSSAI (e.g., 312 in FIG. 3) including S-NSSAI#1 (e.g., 322 in FIG. 3) and S-NSSAI#2 (e.g., 324 in FIG. 3) is configured on the UE (410), and that S-NSSAI#1 has an SST value of 1 and an SD value of NULL, and S-NSSAI#2 has an SST value of 2 and an SD value of NULL. For example, according to the example in Table 2, S-NSSAI#1 may be associated with a network slice for eMBB, and S-NSSAI#2 may be associated with a network slice for URLLC. The UE (410) can send a request NSSAI (e.g., 314 in FIG. 3) containing S-NSSAI#1 and S-NSSAI#2 to the Access and Mobility Management Function (AMF) (420) (402) to use the network slice associated with S-NSSAI#1 and the network slice associated with S-NSSAI#2, and the AMF (420) can forward the request NSSAI to the UDM (430) (404).
[0088] In the example of FIG. 4, it is assumed that a subscription NSSAI containing default S-NSSAI#1 and S-NSSAI#3 is set in the UDM (430), and that default S-NSSAI#1 has an SST value of 1 and an SD value of NULL, and S-NSSAI#3 has an SST value of 3 and an SD value of NULL. The UDM (430) checks whether the S-NSSAI included in the request NSSAI is allowed to the corresponding UE (410), and transmits an allowable NSSAI containing the allowable S-NSSAI (e.g., see 316 in FIG. 3) to the AMF (420) (406), and if the AMF (420) needs to update the allowable NSSAI to the UE (410), it can transmit the allowable NSSAI to the UE (410) (408). If the allowed NSSAI does not need to be updated to the UE (410), the AMF (420) may not deliver the allowed NSSAI to the UE (410). For example, the UDM (430) may check if the S-NSSAI#1 included in the request NSSAI is included in the subscribed NSSAI and send S-NSSAI#1 to the AMF (420) by including it in the allowed NSSAI (406). For example, if none of the S-NSSAIs included in the request NSSAI are included in the subscribed NSSAI, the UDM (430) may send the default S-NSSAI (e.g., default S-NSSAI#1) to the AMF (420) by including it in the allowed NSSAI (406). The UE (410) may use the S-NSSAI#1 included in the allowed NSSAI to perform a procedure (e.g., establish a PDU session) to use the network slice associated with S-NSSAI#1.
[0089] UE Route Selection Policy (URSP)
[0090] To enable the UE to perform application-specific traffic classification using network slices created in the network according to the SLA, the network can set a URSP for the UE. Based on the set URSP, the UE can send traffic for a specific application to a specific network slice. Tables 3 and 4 provide examples of URSPs defined in 3GPP standards.
[0091] [Table 3]
[0092]
[0093] [Table 4]
[0094]
[0095] The information exemplified in Tables 3 and 4 is described in detail in 3GPP TS 23.503, and this disclosure incorporates the entire 3GPP TS 23.503 document by reference. Referring to Table 3, a URSP may include a Rule Precedence that specifies the priority of the policy, a Traffic Descriptor, and a List of Route Selection Descriptors. A UE may identify a specific application through Application Descriptors, which are sub-items of the Traffic Descriptor, and identify a specific network slice through Network Slice Selection, which is a sub-item of the List of Route Selection Descriptors. An OSAppId included in the Application Descriptors may be used to identify a specific application in the UE, and an S-NSSAI may be used to identify a specific network slice in the UE.
[0096] Initial Registration Procedure for Network Slicing
[0097] In the initial registration process, the UE can request the network to use a specific network slice through the S-NSSAI value included in the request NSSAI (e.g., see 402 and 404 in FIG. 4). The network can check the availability of the S-NSSAI value included in the request NSSAI requested by the UE and send it to the UE, including the S-NSSAI value, which is an identifier of the available network slices, in the allow NSSAI (e.g., see 406 and 408 in FIG. 4). The UE can perform procedures such as PDU Session Establishment for a specific network slice using the S-NSSAI value included in the allow NSSAI.
[0098] If a URSP is not configured on the UE, the UE cannot select an S-NSSAI value and may request the establishment of a PDU session with a NULL value. If S-NSSAI is NULL, the AMF can map the corresponding PDU session to the default network slice based on the default S-NSSAI value stored in the UDM. If a URSP is configured on the UE, the UE can request the establishment of a PDU session for the corresponding network slice by specifying an S-NSSAI value according to the policy configured in the URSP.
[0099] FIG. 5 illustrates a procedure for establishing an allowed NSSAI through an initial registration procedure. FIG. 5 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 5. For example, some configurations illustrated in FIG. 5 may be omitted, and configurations not illustrated in FIG. 5 may be added.
[0100] Referring to FIG. 5, the UE (410) may transmit a request NSSAI (e.g., see 314 in FIG. 3) containing an S-NSSAI associated with the network slice to be used among the configured NSSAIs (e.g., see 312 in FIG. 3) to the base station (or RAN) (440) via an initial registration request message (502). In addition to the request NSSAI, the initial registration request message may include additional information such as, for example, UE identification information (e.g., at least one of SUCI (Subscriber Concealed Identifier), GUTI (Globally Unique Temporary Identity), PEI (Permanent Equipment Identifier)), security parameter information.
[0101] A base station (or RAN) (440) can select an AMF (420) (504) and send a registration request message to the selected AMF (420) (506). For example, the AMF (420) may be an Initial AMF, and the base station (440) can send a registration request message (502) to the Initial AMF (420).
[0102] The AMF (420) can select the AUSF (Authentication Server Function) (450) and initiate an authentication process with the AUSF (450) (508). The authentication process (508) may include at least one of the following: the AMF (420) requesting the AUSF (450) to authenticate the UE (410); the AUSF (450) obtaining authentication data of the UE (410) from the UDM (430); and the AUSF (450) performing authentication with the UE (410) through the AMF (420).
[0103] After performing the authentication procedure (508), the AMF (420) can perform a NAS (Non-Access Stratum) security setup procedure with the UE (410) (510). Through the security setup procedure (510), the AMF (420) can obtain security context information for the UE (410) and provide the security context information of the UE (410) to the base station (or RAN) (440). The security context information can be used to protect messages transmitted or received between the UE (410) and the base station (440).
[0104] After the NAS security setup procedure (510) is completed, the AMF (420) determines an allowed NSSAI (e.g., see 316 in FIG. 3) (512) and can send the allowed NSSAI to the UE (410) via a registration acceptance message (514). The UE (410) can complete the initial registration procedure by sending a registration completion message to the AMF (420) (516). The allowed NSSAI received via the registration acceptance message (514) can be used by the UE (410) to identify network slices and establish connections.
[0105] However, if an NSSAI requiring protection, such as encryption, is included in the NAS signaling, the UE (410) may request it from the network after the NAS security setup procedure (510) is completed. For example, the NSSAI requiring protection may include an NSSAI associated with a network slice for security-sensitive services such as government services, military communications services, medical services, and financial services. Therefore, if an NSSAI requiring protection is included in the NAS signaling, the UE (410) may need to perform a procedure for updating the AMF (420) and the allowed NSSAI after establishing security context information (e.g., after 510 in FIG. 5).
[0106] If an NSSAI requiring protection is included in AS signaling, the AS signaling is not encrypted, which can lead to the leakage of sensitive information. Current 3GPP standards stipulate that S-NSSAIs should not be included in AS signaling by default. After the initial registration process, the network can configure S-NSSAIs that do not require protection and S-NSSAIs that require protection on the UE; in the case of S-NSSAIs that do not require protection, the UE can transmit them via AS signaling in plaintext without encryption, whereas in the case of S-NSSAIs that require protection, the UE cannot transmit them via AS signaling. For example, S-NSSAIs that do not require protection may include S-NSSAIs for SSTs defined in 3GPP standards (e.g., see Table 2 and related descriptions).
[0107] Network slicing security
[0108] 3GPP standards define Network Slice Specific Authentication and Authorization (NSSAA) procedures as security technologies for network slicing, as well as procedures for interoperability with devices, such as firewalls, that provide security functions at the N6 interface connecting network slices and data networks (DN). NSSAA procedures refer to additional authentication procedures for network slice services provided by third parties, in addition to network slices defined in 3GPP standards, such as URLLC, eMBB, and mMTC. Furthermore, it defines Network Slice Admission Control (NSAC) functions to prevent attacks, such as Distributed Denial of Service (DDoS), through access control for specific network slices. From an SLA perspective, the GSMA provides attributes that allow setting Availability and Isolation Levels to provide network slice security.
[0109] Post-Quantum Cryptography (PQC)
[0110] Modern security algorithms face the threat of being mathematically solved within polynomial time due to the advent of future quantum computers. To address security threats posed by quantum computers, the National Institute of Standards and Technology (NIST) is proceeding with the standardization of PQC algorithms. PQC can refer to a collection of algorithms that provide cryptographic methods capable of running efficiently on classical computing platforms while withstanding computational exploitation by quantum adversaries.
[0111] In order to protect against security vulnerabilities caused by the emergence of quantum computers in next-generation communication systems, relevant standards organizations, including 3GPP, are expected to consider NIST's recommendation regarding the use of PQC algorithms. The 3GPP Release 19 SA3 WG is discussing algorithm modifications to prevent quantum computer-based attacks by increasing the key length of existing symmetric key encryption algorithms.
[0112] Problems with conventional technology
[0113] In 6G systems, network slicing technology is expected to provide customized services based on the requirements of various applications; however, 5G systems (e.g., systems based on standards after 3GPP Release 15) and 5G-Advanced systems (e.g., systems based on standards after 3GPP Release 18) are primarily designed around requirements for throughput, delay, and admission control. SLAs defined by GSMA and 3GPP lack definitions for attributes that can provide security in specific network slices, and there is a lack of methods to provide enhanced security network slices to deliver various security services required when utilizing network slices, such as preventing security threats between slices when a UE uses multiple slices simultaneously, or providing network slices to protect against new security threats in the era of quantum computing.
[0114] In standards from 3GPP Release 15 onwards, S-NSSAIs may be used as identifiers for network slices (e.g., see "Network Slice Identifier" in this disclosure). If S-NSSAIs are transmitted over the air without protection, potential security risks may arise, such as an eavesdropper inferring sensitive information (e.g., network topology or information on specific user groups) from the S-NSSAIs. To mitigate these risks, the following security measures have been introduced in NAS signaling and AS signaling since 3GPP Release 15.
[0115] - NAS (Non-Access-Stratum) Signaling: By including S-NSSAI in NAS signaling, potential AMF redeployment can be prevented and system security performance can be improved. Specifically, existing 3GPP standards specify that S-NSSAI should be transmitted or received in NAS signaling only after NAS security is established to prevent the leakage of potentially sensitive information due to S-NSSAI (e.g., see Fig. 5 and related description). Since S-NSSAI can be transmitted with enabled confidentiality and integrity protection after NAS security is established, potential security risks can be mitigated.
[0116] - AS (Access-Stratum) Signaling: By including S-NSSAI in AS signaling, the base station can select the appropriate AMF and prevent the possibility of AMF redeployment. Specifically, existing 3GPP standards adopt a two-stage approach to mitigate the risk of sensitive information leakage while allowing S-NSSAI transmission even before AS security is established. In the first stage, or when a terminal first registers with the network, S-NSSAI is not transmitted by default in AS signaling. After this initial registration, the network can configure the UE with two sets of S-NSSAI: one considered incapable of inferring sensitive information, and the other capable of containing sensitive information. In the former case, the terminal can transmit it in plaintext in AS signaling, while the latter cannot be included in AS signaling.
[0117] Existing methods for protecting S-NSSAI in NAS and AS signaling have a vulnerability to attacks such as "Harvest Now, Decrypt Later," which allow attackers to collect encrypted data before the advent of quantum computers and decrypt it afterward to steal the information. By decrypting pre-collected, encrypted S-NSSAI data after the emergence of quantum computers, attackers can infer user information and network topology data regarding specific network slices requiring enhanced security (e.g., network slices specialized for government services, military communications, medical services, and financial services).
[0118] The proposed method of the present disclosure
[0119] The present disclosure proposes a method to selectively protect network slice identifiers through the PQC quantum security algorithm to address technical security issues related to quantum computers. Specifically, the present disclosure proposes a method to protect network slice identifiers to prevent new threats arising from the emergence of quantum computers when providing network slice services specialized for government services, military communication services, medical services, financial services, etc., in addition to the five SSTs defined in the standard for network slices.
[0120] Examples of network slice identifiers in this disclosure may be NSSAI or S-NSSAI, but the proposed method of this disclosure is not limited to NSSAI or S-NSSAI. The network slice identifiers to which the proposed method of this disclosure can be applied include not only NSSAI or S-NSSAI but also network slice identifiers to be used in 6G communication systems and next-generation communication systems after 6G. Therefore, in the description of this disclosure focusing on NSSAI or S-NSSAI, NSSAI and S-NSSAI can be generalized as network slice identifiers, respectively, and may be changed to other names. For example, Configuration NSSAI can be generalized as Configured Network Slice Identifier, Request NSSAI as Requested Network Slice Identifier, Allow NSSAI as Allowed Network Slice Identifier, and Subscribe NSSAI as Subscribed Network Slice Identifier.
[0121] In 5G systems, the Access and Mobility Management Function (AMF) and the Session Management Function (SMF) are separate, but in 6G systems, the AMF and SMF can be integrated into a single core network function or network entity. Accordingly, in this disclosure, the network management entity may be referred to as "AMF or SMF". In this disclosure, the network (NW) may refer to a RAN, a base station, or a core network.
[0122] In this disclosure, PQC may collectively refer to cryptographic technologies for responding to security threats arising from the emergence of quantum computers. Examples of PQC may include the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) according to FIPS 203 of the National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS), the Module-Lattice-Based Digital Signature (ML-DSA) according to FIPS 204, and the Stateless Hash-Based Digital Signature (SLH-DSA) according to FIPS 205. However, in this disclosure, PQC is not limited to PQC technologies according to NIST FIPS standards, and other PQC technologies may be used. For example, examples of PQC may include Code-Based Cryptography, Multivariate Polynomial Cryptography, Lattice-Based Cryptography not defined in NIST FIPS standards, and Hash-Based Cryptography. In this disclosure, PQC may be used interchangeably with other terms such as Quantum Resilient Cryptography.
[0123] The proposed methods of the present disclosure may each be implemented independently, but at least one of the proposed methods of the present disclosure may also be implemented in a combined form.
[0124] Proposed Method 1
[0125] In Method 1 of the present disclosure, it is proposed to add information to the network slice identifier indicating whether to perform PQC-based encryption on the network slice identifier or to perform PQC-based encryption. In the present disclosure, information indicating whether to perform PQC-based encryption on the network slice identifier or to perform PQC-based encryption may be briefly referred to as Quantum-Resilient (QR) information or Privacy information. QR information may be included in the network slice identifier that the network sets for the UE. For example, if the network slice identifier is an S-NSSAI, the QR information may be included in the S-NSSAI included in the set NSSAI (e.g., see 312 in FIG. 3). If the QR information indicates that PQC-based encryption is to be performed on the network slice identifier, the UE may perform PQC-based encryption on the network slice identifier (containing the QR information) and transmit it to the network. If the QR information indicates that PQC is not performed for the network slice identifier, the UE may treat the network slice identifier as a legacy network slice identifier (e.g., see 210 in FIG. 2) or transmit it to the network without PQC-based encryption for the network slice identifier (containing the QR information) (or without PQC-based encryption for the network slice identifier).
[0126] As an example that does not limit the present disclosure, QR information may be defined as a 1-bit field, but the number of bits may be changed to a value greater than 1. For example, if the value of QR information is 1, the QR information may indicate that PQC-based encryption is performed for a network slice containing said QR information, and the UE may perform PQC-based encryption on a network slice identifier (e.g., S-NSSAI) based on a PQC profile. For example, if the value of QR information is 0, said network slice identifier is identified as a legacy network slice identifier (e.g., see 210 in FIG. 2), or the QR information may indicate that PQC-based encryption is not performed for a network slice containing said QR information. In this case, the UE may not perform PQC-based encryption on the network slice identifier (e.g., S-NSSAI) (or may omit PQC-based encryption on the network slice identifier). Conversely, the value of QR information may be changed to the opposite or changed to another value.
[0127] In the present disclosure, a network slice identifier containing QR information or privacy information indicating that PQC-based encryption is performed may be referred to as a QR-tagged network slice identifier or a privacy-tagged network slice identifier. For example, an S-NSSAI containing QR information or privacy information indicating that PQC-based encryption is performed may be referred to as a QR-tagged S-NSSAI or a privacy-tagged S-NSSAI.
[0128] In Method 1 of the present disclosure, the encryption profile information (e.g., legacy profile, PQC profile) that the UE uses to protect the network slice identifier may be provisioned from the network to the UE, predefined between the UE and the network, configured via system information (e.g., System Information Block (SIB)), or configured via an RRC setup message (e.g., RRCSetup). According to the present disclosure, a PQC-based encrypted network slice identifier may be referred to as a Protected Network Slice Identifier. For example, an S-NSSAI encrypted according to Method 1 of the present disclosure may be referred to as a Protected S-NSSAI, and a combination or set of Protected S-NSSAIs may be referred to as a Protected NSSAI.
[0129] In the proposed method of the present disclosure, at least one encryption profile and at least one protection scheme may be used for the protection of a network slice identifier. If multiple encryption profiles and / or multiple protection schemes are used, the UE needs to signal to the network the encryption profile and protection scheme used for the protection of the network slice identifier so that the encrypted network slice identifier can be decrypted in the network. To this end, the proposed method 1 of the present disclosure proposes information indicating the encryption profile used for the protection of the network slice identifier and information indicating the protection scheme used for the protection of the network slice identifier. In the present disclosure, information indicating the profile of the encryption algorithm used for the protection of the network slice identifier may be briefly referred to as profile selection information, and information indicating the encryption scheme used for the protection of the network slice identifier may be briefly referred to as protection scheme information.
[0130] For example, profile selection information and protection mode information may be added as headers to an encrypted network slice identifier. When profile selection information and protection mode information are added as headers to an encrypted network slice identifier, the bit length of the encrypted network slice identifier may vary depending on the encryption profile used. Alternatively, for example, profile selection information and protection mode information may be included in a message transmitted over the network as information separate from the encrypted network slice identifier.
[0131] If there is no need to signal the encryption profile and protection method for the protection of the network slice identifier, the profile selection information and protection method information may not be added to the network slice identifier or signaled to the network.
[0132] FIG. 6 illustrates a network slice identifier according to one embodiment of the present disclosure. FIG. 6 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 6.
[0133] Referring to FIG. 6, a network slice identifier (210) of a 5G system and a network slice identifier (620) according to Method 1 of the present disclosure are illustrated. The network slice identifier (210) of the 5G system may be, for example, an S-NSSAI (e.g., "Network Slice Identifier" of the present disclosure or FIG. 2), and may be referred to as a legacy S-NSSAI. The network slice identifier (620) according to Method 1 of the present disclosure may be an S-NSSAI containing QR information or privacy information (e.g., "Method 1 of the present disclosure") and may be referred to as a proposed S-NSSAI. An S-NSSAI generated by encrypting the proposed S-NSSAI according to the present disclosure may be referred to as a protected S-NSSAI.
[0134] The legacy S-NSSAI (210) may include SST (212) and SD (214), where SST (212) is an 8-bit field and SD (214) is a 24-bit field. The proposed S-NSSAI (620) may include SST, SD, and QR information, where SST is an 8-bit field and SD is a 23-bit field, and QR information may be a 1-bit field by reusing 1 bit of the SD field. As described in the proposed method 1 of the present disclosure, the number of bits of QR information may have a value greater than 1.
[0135] Referring to FIG. 6, the UE can obtain a protected S-NSSAI (630) by encrypting the proposed S-NSSAI (620) according to the present disclosure. The length of the protected S-NSSAI (630) may vary depending on the encryption profile and protection method used to encrypt the protected S-NSSAI (630), and the protected S-NSSAI (630) may contain N bits. If the UE needs to signal the encryption profile and protection method used to encrypt the protected S-NSSAI (630) to a network, the UE may add profile selection information (632) and protection method information (634) in the form of a header to the protected S-NSSAI (630) or signal them as information separate from the protected S-NSSAI (630).
[0136] Profile selection information (632) may be information indicating the encryption profile used for encryption of the protected S-NSSAI (630). Profile selection information (632) may indicate at least one encryption profile, including legacy profile (642) and PQC profile (644). For example, legacy profile (642) may include Null profile, Profile A, and Profile B associated with the encryption algorithm used for SUCI (Subscription Concealed Identifier) defined in 3GPP TS 33.501 Annex C, but this is only for the benefit of understanding the present disclosure and may be defined as other encryption profiles or profiles of encryption algorithms other than those based on EICIES (Elliptic Curve Integrated Encryption Scheme). A PQC profile (644) may include a profile for the CRYSTALS-KYBER algorithm for key encapsulation according to the NIST FIPS 203 standard, a profile for the CRYSTALS-Dilithium algorithm for digital signatures defined in the FIPS 204 standard, and a profile for the SPHINCS+ algorithm for digital signatures defined in the FIPS 205 standard, but this is only for the sake of understanding the present disclosure and may also be defined as a profile for other PQC cryptographic algorithms not defined in the NIST FIPS standards. Tables 5 and 6 illustrate Profile A and Profile B defined in 3GPP TS 33.501 Annex C, respectively, and Table 7 illustrates a PQC profile configured to use the CRYSTAL-KYBER PQC algorithm. Descriptions of each profile are described in detail in 3GPP TS 33.501 and FIPS 203, and the present disclosure incorporates these documents in their entirety by reference.
[0137] [Table 5]
[0138]
[0139] [Table 6]
[0140]
[0141] [Table 7]
[0142]
[0143] Referring to FIG. 6, as an example that does not limit the present disclosure, when the value of the profile selection information (632) is 0, the profile selection information (632) may indicate a NULL profile as a legacy profile (642) and a NULL profile as a PQC profile (644). When the value of the profile selection information (632) is 1, the profile selection information (632) may indicate profile A as a legacy profile (642) and a PQC profile set for CRYSTAL-KYBER as a PQC profile (644). When the value of the profile selection information (632) is 2, the profile selection information (632) may indicate profile B as a legacy profile (642) and a PQC profile set for CRYSTAL-KYBER as a PQC profile (644).
[0144] The protection method information (634) may indicate a shared key generation method (652) used for generating a shared key between the UE and the network, and a method (654) for encrypting S-NSSAI using the generated shared key.
[0145] Referring to FIG. 6, as an example that does not limit the present disclosure, when the value of the protection method information (634) is 0, the protection method information (634) may indicate NULL as the shared key generation method (652) and NULL as the PQC encryption method (654). When the value of the protection method information (634) is 1, the protection method information (634) may indicate a legacy method using the UE's private key and the network's public key as the shared key generation method (652) and a PQC algorithm as the encryption method (654). When the value of the protection method information (634) is 2, the protection method information (634) may indicate a hybrid method combining a method using a PQC-based public key and a legacy method as the shared key generation method (652) and an AES (Advanced Encryption Standard)-based symmetric algorithm as the encryption method (654). When the value of the protection method information (634) is 3, the protection method information (634) may indicate a hybrid method that combines a method using a PQC-based public key and a legacy method as a shared key generation method (652), and a PQC algorithm as an encryption method (654).
[0146] In the proposed method 1 of the present disclosure, profile selection information and protection method information may be combined to represent both the encryption profile and the protection method as a single piece of information. In the present disclosure, information indicating both the encryption profile and the protection method used for encryption of a network slice identifier may be briefly referred to as protection method information. By defining the profile selection information by including it in the protection method information, the number of bits required to represent the encryption profile and the protection method can be reduced.
[0147] FIG. 7 illustrates a network slice identifier according to one embodiment of the present disclosure. FIG. 7 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 7.
[0148] Referring to FIG. 7, in contrast to the example of FIG. 6, instead of signaling the profile selection information (632) and the protection method information (634) as separate information, they can be integrated into one information (710) and added to the header of the protection S-NSSAI (630) or transmitted as information separate from the protection S-NSSAI (630). The protection method information (710) may together indicate an encryption profile (642) for legacy algorithms, an encryption profile (644) for PQC algorithms, a method (652) for shared key generation, and / or an encryption method (654).
[0149] Proposed Method 2
[0150] Method 2 of the present disclosure proposes a method for encrypting a network slice identifier using a PQC-based public key. In the present disclosure, a shared key generated based on the network's public key and the UE's private key according to an existing algorithm may be referred to as a first shared key, a legacy shared key, or S1; a shared key generated based on a PQC-based public key according to a PQC algorithm may be referred to as a second shared key, a PQC shared key, or S2; and a shared key generated based on the legacy shared key (S1) and the PQC shared key (S2) may be referred to as a third shared key, a hybrid shared key, or S. Specifically, Method 2 of the present disclosure proposes a method for generating a hybrid shared key (S) based on the legacy shared key (S1) and the PQC shared key (S2), and encrypting a network slice identifier using the hybrid shared key (S).
[0151] When the proposed method 2 of the present disclosure is used, by using the existing Elliptic Curve (EC)-based shared key generation algorithm and the PQC-based shared key generation algorithm together, it is possible to prevent an attacker from finding the shared key even if they use a quantum computer, so attacks using a quantum computer can be effectively defended.
[0152] FIG. 8 illustrates a method for encrypting a network slice identifier according to Method 2 proposed in the present disclosure. FIG. 8 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 8. For example, while FIG. 8 focuses on S-NSSAI for the sake of understanding, S-NSSAI in the example of FIG. 8 can be generalized to a network slice identifier. Furthermore, the algorithm for generating the legacy shared key (S1) and the algorithm for generating the PQC shared key (S2) are not limited to any specific algorithm, and various algorithms may be used. In the present disclosure, the term "shared key" may be used interchangeably with terms such as "symmetric key" or "secret key." The example of FIG. 8 can be performed by a UE.
[0153] Referring to FIG. 8, the UE can generate a legacy shared key (S1) by performing an Asymmetric Key Agreement (806) using the network (NW)'s public key (802) and the UE's private key (804). For example, the Asymmetric Key Agreement (806) can be performed using an Elliptic Curve (EC)-based algorithm, but other algorithms may also be used. Additionally, the UE can generate a PQC shared key (S2) by performing PQC key encapsulation (814) using the network's PQC-based public key (812). For example, PQC key encapsulation (814) can be performed using a modular grid-based key encapsulation algorithm defined in the NIST FIPS 203 standard, but other algorithms may also be used. The UE can generate a hybrid shared key by performing an operation (822) using the legacy shared key (S1) and the PQC shared key (S2). Although the operation (822) in FIG. 8 is illustrated as XOR (Exclusive OR), in the proposed method 2 of the present disclosure, XOR operation is not the only possible operation for hybrid shared key generation, and other operations may be used.
[0154] The UE can obtain an encrypted network slice identifier (844) by performing symmetric encryption (842) on a network slice identifier (832) using a hybrid shared key. For example, the network slice identifier (832) may be a privacy-tagged S-NSSAI included in the request NSSAI, and an example of a privacy-tagged S-NSSAI may be an S-NSSAI containing QR information or privacy information according to the proposed method 1 of the present disclosure. For example, the symmetric encryption (842) may be performed using the AES algorithm, but other algorithms may be used.
[0155] The encryption method of the network slice identifier exemplified in FIG. 8 may correspond to the protection method (634) exemplified in FIG. 6 or the protection method (710) exemplified in FIG. 7, which uses a shared key generation method (652) using a PQC-based public key and a legacy method and a legacy encryption method (654). For example, the encryption method of the network slice identifier exemplified in FIG. 8 may correspond to the case where the protection method (634) in FIG. 6 is protection method 2, or the case where the protection method (710) in FIG. 7 is protection method 3 or protection method 4.
[0156] In the method of FIG. 8, if a PQC-based algorithm is used instead of symmetric encryption (842), the encryption method of the network slice identifier exemplified in FIG. 8 may correspond to a protection method exemplified in FIG. 6 (634) or FIG. 7 (710) that uses a shared key generation method (652) using a PQC-based public key and a legacy method and a PQC encryption method (654). For example, in the method of FIG. 8, if a PQC-based algorithm is used instead of symmetric encryption (842), the encryption method of the network slice identifier exemplified in FIG. 8 may correspond to the case where the protection method (634) in FIG. 6 is protection method 3, or the case where the protection method (710) in FIG. 7 is protection method 5 or protection method 6. For example, the PQC-based algorithm may include lattice-based ciphers such as CRYSTALS-KYBER and CRYSTALS-Dilithium, but may also include code-based ciphers and multivariate-based ciphers that will be developed in the future.
[0157] FIG. 9 illustrates an embodiment of an encryption method according to the present disclosure. FIG. 9 is merely an example to aid in understanding the present disclosure and is not intended to limit the present disclosure. FIG. 9 can be performed by a UE.
[0158] Referring to FIG. 9, in operation 1, the UE can perform key pair generation (902) to generate the UE's public key (904) and the UE's private key (906). For example, key pair generation (902) can be performed using an elliptic curve (EC)-based ephemeral key pair generation algorithm, and the UE's public key (904) can be an ephemeral public key, and the UE's private key (906) can be an ephemeral private key. For example, the UE's private key (906) can correspond to the UE's private key (804) in the example of FIG. 8.
[0159] In operation 2, the UE can generate a shared key (912) by performing key consensus (910) using the network (NW)'s public key (908) and the UE's private key (906). For example, the key consensus (910) can be performed using an EC-based key consensus algorithm, and the shared key (912) can be a temporary shared key. For example, the network (NW)'s public key (908) can correspond to the network's public key (802) in the example of FIG. 8, and the shared key (912) can correspond to the legacy shared key (S1) in the example of FIG. 8.
[0160] In operation 3, the UE may perform key derivation (914) to generate a Message Authentication Code (MAC) key (924) and / or an encryption key and an Initial Counter Block (ICB) (916) for symmetric encryption. For example, an example of key derivation (914) may include a Key Derivation Function (KDF), but other algorithms may be used. For example, the MAC key (924) may be an ephemeral MAC key, and the encryption key (916) may be an ephemeral encryption key (Ephemeral Encryption Key or Eph. Enc. Key).
[0161] In operation 4, the UE can generate a cipher-text value (922) by performing symmetric encryption (920) on a plaintext block (918) using an encryption key and an ICB (916). For example, the symmetric encryption (920) may correspond to the symmetric encryption (842) in the example of FIG. 8, the plaintext block (918) may include a network slice identifier, and the cipher-text block (922) may include a protected network slice identifier.
[0162] In operation 5, the UE can generate a MAC tag value (928) by performing a MAC function (926) using the MAC key (924). Operation 5 may be omitted if necessary. For example, the MAC function (926) may include a hash-based MAC algorithm, but other algorithms may be used.
[0163] Through the embodiment illustrated in FIG. 9, the UE can generate at least one of a public key (904), a ciphertext (922), or a MAC tag value (928). In the embodiment of FIG. 9, the functions and information (902, 908, 910) indicated by hatching may be vulnerable to threats from quantum computers and may become a problem upon the emergence of quantum computers.
[0164] FIG. 10 illustrates an embodiment of an encryption method according to Method 2 proposed in the present disclosure. FIG. 10 is merely an example to aid in understanding the present disclosure and is not intended to limit the present disclosure. The embodiment of FIG. 10 can be performed by a UE.
[0165] For example, the embodiment of FIG. 10 may be an encryption method implemented according to the proposed method 2 of the present disclosure. Compared to the embodiment of FIG. 9, a PQC-based shared key generation algorithm may be used in conjunction by additionally utilizing functions and information (1010, 1012, 1014, 1016, 1018) indicated by dots. In the embodiment of FIG. 10, a hybrid shared key is generated using the shared key generated according to the method of FIG. 9 and the shared key generated based on the PQC algorithm, and since the generated hybrid shared key is used, the shared key cannot be found even if a quantum computer is used, so attacks using a quantum computer can be effectively defended.
[0166] Referring to FIG. 10, operation 1 may correspond to operation 1 (902) of FIG. 9, and the description of FIG. 9 is included herein by reference.
[0167] In operation 2.a, an elliptic curve (EC)-based network temporary public key (1008) may be used instead of the network's public key (908) for enhanced security. The UE may generate a shared key (912) by performing key consensus (910) using the network's (NW) elliptic curve (EC)-based network temporary public key (1008) and the UE's private key (906). For example, the key consensus (910) may be performed using an EC-based key consensus algorithm, and the shared key (912) may be a temporary shared key. For example, the elliptic curve (EC)-based network temporary public key (1008) may correspond to the network's public key (802) in the example of FIG. 8, and the shared key (912) may correspond to the legacy shared key (S1) in the example of FIG. 8.
[0168] In operation 2.b, the UE can generate a PQC shared key (1014) and / or an encrypted shared key (1020) by performing PQC key encapsulation (1012) using the network's PQC-based public key (1010). For example, the network's PQC-based public key (1010) may be a temporary public key of the network generated using a PQC algorithm, and the PQC shared key (1014) may be a temporary shared key. For example, PQC key encapsulation (1012) may correspond to PQC key encapsulation (814) in the example of FIG. 8, and PQC shared key (1014) may correspond to PQC shared key (S2) in the example of FIG. 8.
[0169] In operation 3, the UE can generate a shared key (1018) through hybrid key generation (1016) using the shared key (912) and the shared key (1014). For example, the hybrid key generation (1016) may correspond to the operation (822) in the example of FIG. 8, and the shared key (1018) may correspond to the hybrid shared key in the example of FIG. 8.
[0170] In operation 4, the UE may perform key derivation (914) on the shared key (1018) to generate a Message Authentication Code (MAC) key (924) and / or an encryption key and an Initial Counter Block (ICB) (916) for symmetric encryption. For example, the MAC key (924) may be a temporary MAC key, and the encryption key (916) may be a temporary encryption key (Eph. Enc. Key).
[0171] Operations 5 and 6 may correspond to operations 4 (920) and 5 (926) of FIG. 9, and the description of FIG. 9 is included herein by reference.
[0172] Through the embodiment illustrated in FIG. 10, the UE can generate at least one of a public key (904), an encrypted shared key (1020), a ciphertext (922), or a MAC tag value (928). The ciphertext (922) may be, for example, a protected network slice identifier (e.g., the protected S-NSSAI (630) of FIG. 6 and FIG. 7). Since the shared key (1018, 1020) generated using the embodiment of FIG. 10 cannot be found even if an attacker uses a quantum computer, attacks using a quantum computer can be effectively defended.
[0173] FIG. 11 illustrates the operation procedure of a UE and a network entity according to Method 2 proposed in the present disclosure. FIG. 11 is merely an example to aid in understanding the present disclosure and is not intended to limit the present disclosure. In the example of FIG. 11, some components may be omitted and components not illustrated may be added. Additionally, the order of operation in the example of FIG. 11 may be changed.
[0174] Referring to FIG. 11, it is assumed that a network entity has provisioned the network entity's public key to the UE. For example, the network entity's public key may be provisioned to the UE's SIM (Subscriber Identity Module). For example, the network entity's public key being provisioned may include the network entity's elliptic curve (EC)-based public key and the network entity's PQC-based public key.
[0175] In operation 1, the UE can generate a key pair of the UE's public key and private key. For example, operation 1 may correspond to operation 1 (902) of FIG. 10. For example, the UE's key pair may be generated using an EC-based key pair generation algorithm.
[0176] In operation 2, the UE can generate a shared key (S1) using the public key of the network entity and the private key of the UE. For example, in operation 2, the public key of the network entity may be the EC-based public key of the network entity, and the private key of the UE may be the EC-based private key of the UE generated in operation 1. For example, operation 2 may correspond to the key consensus (806) of FIG. 8 or the key consensus (910) of FIG. 10, and the shared key (S1) may be a legacy shared key and may be generated using the EC-based key consensus.
[0177] In operation 3, the UE can generate a shared key (S2) and a corresponding ciphertext using a PQC key encapsulation mechanism (KEM). For example, operation 3 may correspond to the PQC key encapsulation (814) of FIG. 8 and the PQC key encapsulation (1012) of FIG. 10, and the shared key (S2) may be a PQC shared key and may be generated using a PQC key encapsulation algorithm.
[0178] In operation 4, the UE can generate a final shared key (S) using the shared key (S1) and the shared key (S2). For example, operation 4 may correspond to the operation (822) of FIG. 8 and the hybrid key generation (1016) of FIG. 10, and the final shared key (S) may be a hybrid shared key and may be generated using operations such as XOR.
[0179] In operation 5, the UE can encrypt the network slice identifier using a shared key (S). For example, the network slice identifier may be a network slice identifier containing QR information according to method 1 proposed in the present disclosure. As a more specific example, the network slice identifier may be an S-NSSAI containing QR information according to method 1 proposed in the present disclosure. For example, operation 5 may correspond to the encryption (842) of FIG. 8 and the encryption (920) of FIG. 10, and the encryption may be symmetric encryption and may be performed using an AES algorithm, etc.
[0180] The encrypted network slice identifier may have the format of a network slice identifier according to Method 1 proposed in the present disclosure. For example, the encrypted network slice identifier may be an S-NSSAI in the form including profile selection information (632), protection mode information (634), and protection S-NSSAI (630) as exemplified in FIG. 6, or an S-NSSAI in the form including protection mode information (710) and protection S-NSSAI (630) as exemplified in FIG. 7. In the present disclosure, an S-NSSAI in the form including profile selection information, protection mode information, and protection S-NSSAI, or an S-NSSAI in the form including protection mode information and protection S-NSSAI, may be referred to as an encrypted S-NSSAI.
[0181] The UE may transmit an encrypted network slice identifier (e.g., an encrypted S-NSSAI) to the network entity. The UE may transmit the encrypted network slice identifier along with the ciphertext generated in Operation 3 and / or the UE's public key generated in Operation 1 (e.g., the UE's EC-based public key) to the network entity.
[0182] A network entity can identify information about a shared key generation method, information about an encryption method, and profile information of an algorithm used for encryption based on information received along with an encrypted network slice identifier or information included in the header of the encrypted network slice identifier (e.g., profile selection information and protection method information of FIG. 6, or protection method information of FIG. 7). The network entity can decrypt the encrypted network slice identifier based on the identified shared key generation method, encryption method, and encryption profile information.
[0183] If the shared key generation method is identified as a hybrid method combining the PQC public key and a legacy method (e.g., a method based on key consensus using the UE private key and the network entity's public key) and the encryption method is identified as a symmetric encryption method (e.g., if the protection method in FIG. 6 is 2, or the protection method in FIG. 7 is 3 or 4), the network entity can perform operations 6 through 9 to decrypt the encrypted network slice identifier.
[0184] In operation 6, the network entity can generate a shared key (S1) using the UE's public key and the network entity's private key. For example, the UE's public key may be one received from the UE, and the network entity's private key may be the network entity's EC-based private key.
[0185] In operation 7, the network entity can generate a shared key (S2) and a corresponding ciphertext using a PQC key encapsulation mechanism (KEM). For example, operation 7 may correspond to operation 3 of the UE.
[0186] In operation 8, the network entity can generate a final shared key (S) using the shared key (S1) and the shared key (S2). For example, operation 8 may correspond to operation 4 of the UE, and the shared key (S) may be a hybrid shared key and may be generated using operations such as XOR.
[0187] In operation 9, the network entity can decrypt the network slice identifier using a shared key (S). For example, the decrypted network slice identifier may be a network slice identifier containing QR information according to method 1 proposed in the present disclosure. As a more specific example, the decrypted network slice identifier may be an S-NSSAI containing QR information according to method 1 proposed in the present disclosure. For example, operation 5 may correspond to the encryption (842) of FIG. 8 and the encryption (920) of FIG. 10, and the encryption may be symmetric encryption and may use an AES algorithm, etc.
[0188] If the network entity successfully decrypts the network slice identifier, it may perform an operation to select an AMF or an SMF using the decrypted network slice identifier (e.g., see proposed method 4 of the present disclosure and related description). If the network entity cannot decrypt the network slice identifier, the UE may perform an operation such as a fallback procedure (e.g., see proposed method 5 of the present disclosure and related description).
[0189] Proposed Method 3
[0190] Method 3 of the present disclosure proposes another method for encrypting a network slice identifier using a PQC-based public key. Specifically, Method 3 of the present disclosure proposes a method for first encrypting a network slice identifier based on a network public key and additionally encrypting the encrypted network slice identifier based on a PQC-based network public key.
[0191] When the proposed method 3 of the present disclosure is used, the network slice identifier encrypted according to the prior art is additionally encrypted based on PQC, so that even if an attacker uses a quantum computer, the network slice identifier cannot be decrypted, and thus attacks using a quantum computer can be effectively defended.
[0192] FIG. 12 illustrates a method for encrypting a network slice identifier according to Method 3 proposed in the present disclosure. FIG. 12 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 12. For example, while FIG. 12 focuses on S-NSSAI for illustrative purposes, S-NSSAI in the example of FIG. 12 can be generalized to a network slice identifier. Furthermore, the encryption method according to the conventional method and the encryption method based on PQC are not limited to any specific algorithm, and various algorithms may be used. The example of FIG. 12 can be performed by a UE.
[0193] Referring to FIG. 12, the UE can first encrypt a network slice identifier (832) using the public key of the network (NW) (1202). For example, the network slice identifier (832) may be a privacy-tagged S-NSSAI included in the request NSSAI, and an example of a privacy-tagged S-NSSAI may be an S-NSSAI containing QR information or privacy information according to the proposed method 1 of the present disclosure. For example, encryption (1202) may include generating a shared key (e.g., S1) by performing asymmetric key consensus (e.g., 806 in FIG. 8) using the network's public key (e.g., 802 in FIG. 8) and the UE's private key (e.g., 804 in FIG. 8), and generating an encrypted network slice identifier (1204) (e.g., 844 in FIG. 8) by performing symmetric encryption (e.g., 842 in FIG. 8) using the shared key. The entire description of 802, 804, 806, 842, and 844 of FIG. 8 is included herein by reference. The encrypted network slice identifier (1204), which is the result of the first encryption (1202), can be used as an intermediate ciphertext for the PQC-based second encryption (1206).
[0194] A UE can generate a final encrypted network slice identifier (1208) by performing PQC-based encryption (1206) on an intermediate ciphertext or a primary encrypted network slice identifier (1204) using the network's PQC-based public key (812). For example, the final encrypted network slice identifier (1208) may be an encrypted privacy-tagged S-NSSAI and may be included in the request NSSAI. For example, an example of a privacy-tagged S-NSSAI may be an S-NSSAI containing QR information according to the proposed method 1 of the present disclosure. PQC-based encryption (1206) may be performed using a PQC-based algorithm, and the PQC-based algorithm may include, for example, lattice-based ciphers such as CRYSTALS-KYBER and CRYSTALS-Dilithium, but may also include code-based ciphers and multivariate-based ciphers developed in the future.
[0195] The encryption method of the network slice identifier exemplified in FIG. 12 may correspond to a protection method using a shared key generation method (652) and a PQC-based encryption method (654) that use a legacy method among the protection method (634) exemplified in FIG. 6 or the protection method (710) exemplified in FIG. 7. For example, the encryption method of the network slice identifier exemplified in FIG. 12 may correspond to the case where the protection method (634) in FIG. 6 is protection method 1, or the case where the protection method (710) in FIG. 7 is protection method 1 or protection method 2.
[0196] FIG. 13 illustrates an embodiment of an encryption method according to Method 3 proposed in the present disclosure. FIG. 13 is merely an example to aid in understanding the present disclosure and is not intended to limit the present disclosure. The embodiment of FIG. 13 can be performed by a UE.
[0197] For example, the embodiment of FIG. 13 may be an encryption method implemented according to the proposed method 3 of the present disclosure. Compared to the embodiment of FIG. 9, PQC-based encryption may be additionally performed by adding functions and information (1010, 1302, 1304, 1306) indicated by dots. In the embodiment of FIG. 13, by additionally encrypting the network slice identifier, which is first encrypted according to the method of FIG. 9, based on PQC, attacks using a quantum computer can be effectively defended because the network slice identifier cannot be decrypted even if an attacker uses a quantum computer.
[0198] Referring to FIG. 13, operations 1 through 4 may correspond to operations 1 (902) through 4 (920) of FIG. 9, and the description of FIG. 9 is included herein by reference. As in the example of FIG. 10, for enhanced security, an elliptic curve (EC)-based network temporary public key (1008) may be used instead of the network public key (908) in operation 2.
[0199] In operation 5, the UE may use the ciphertext value (922) as an intermediate ciphertext (1302) by symmetric encryption (920), and generate a ciphertext value (1306) by performing PQC-based encryption (1304) on the intermediate ciphertext (1302) using the network's PQC-based public key (1010). For example, the network's PQC-based public key (1010) may be a temporary public key of the network generated using a PQC algorithm and may correspond to the PQC-based network public key (812) in the example of FIG. 12. For example, the PQC-based encryption (1304) may correspond to the PQC-based encryption (1206) in the example of FIG. 12. For example, the ciphertext value (1306) may correspond to an encrypted network slice identifier (1208).
[0200] In operation 6, the UE may generate a MAC tag value (928) by performing a MAC function (926) on a ciphertext value (1306) using a MAC key (924). Operation 6 may be omitted if necessary. For example, the MAC function (926) may include a hash-based MAC algorithm, but other algorithms may be used.
[0201] Through the embodiment illustrated in FIG. 13, the UE can generate at least one of a public key (904), a ciphertext (1306), or a MAC tag value (928). Since the ciphertext (1306) generated using the embodiment of FIG. 13 cannot be decrypted even if an attacker uses a quantum computer, attacks using a quantum computer can be effectively defended.
[0202] Proposed Method 4
[0203] In the proposed method 4 of the present disclosure, a method is proposed to perform an initial registration procedure using a network slice identifier according to the proposed method 1 of the present disclosure. In the proposed method 4 of the present disclosure, when a UE receives a network slice identifier containing QR information, the UE encrypts the network slice identifier based on PQC during the initial access procedure and transmits it to a RAN node; if the RAN node has a PQC profile, it decrypts the PQC-encrypted network slice identifier and uses the decrypted network slice identifier to immediately perform a registration request to a target AMF or SMF other than the initial AMF or SMF.
[0204] FIG. 14 illustrates a registration procedure according to Method 4 proposed in the present disclosure. FIG. 14 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 14. For example, some configurations exemplified in FIG. 14 may be omitted, and configurations not exemplified in FIG. 14 may be added. Although FIG. 14 focuses on NSSAI and S-NSSAI, NSSAI and S-NSSAI can be generalized to network slice identifiers.
[0205] Referring to FIG. 14, it is assumed that the UE (410) is not yet registered with the network and possesses a configuration NSSAI and a PQC-based public key of the RAN (440). Additionally, in the example of FIG. 14, it is assumed that the configuration NSSAI includes an S-NSSAI for an SST defined in a 3GPP standard (e.g., see Table 2 and related description) and / or at least one S-NSSAI tagged with QR information. In the present disclosure, the S-NSSAI for an SST defined in a 3GPP standard may be referred to as the Public S-NSSAI, and the S-NSSAI containing QR information indicating that PQC-based encryption according to the present disclosure is performed may be referred to as the QR-tagged S-NSSAI or the Privacy-tagged S-NSSAI.
[0206] The UE (410) may transmit an initial registration request message to the RAN (440) through an initial access procedure (1402). For example, the initial registration request message may be transmitted to the RAN (440) through a Radio Resource Control (RRC) setup completion message (e.g., RRCSetupComplete message) of the initial access procedure. Although the NAS security setup is not yet complete, the initial registration request message may include a request NSSAI containing a PQC-based encrypted S-NSSAI. For example, the PQC-based encrypted S-NSSAI may have a format according to the proposed method 1 of the present disclosure (e.g., see FIG. 6, FIG. 7 and related description) and may be encrypted using the PQC-based encryption method described in the proposed method 2 or proposed method 3 of the present disclosure.
[0207] RAN (440) can obtain an S-NSSAI by performing decryption on the protected S-NSSAI based on the protection scheme and / or profile indicated by the encrypted S-NSSAI (1404). Additionally, RAN (440) can directly select a target AMF or SMF (1430) rather than an initial AMF or SMF (1420) based on the decrypted S-NSSAI (1404).
[0208] After selecting the target AMF or SMF (1430), the RAN (440) can send a registration request message directly to the target AMF or SMF (1430) instead of the initial AMF or SMF (1420). Accordingly, according to the proposed method 4 of the present disclosure, the relocation or reselection of the AMF or SMF for the QR-tagged S-NSSAI can be performed immediately even before the NAS security setup procedure is completed, so the relocation or reselection of the AMF or SMF for the QR-tagged S-NSSAI can be performed more quickly than in the prior art, and the technical effect of reducing the signaling overhead until the relocation or reselection of the AMF or SMF can be expected.
[0209] A target AMF or SMF (1430) may select an AUSF (450) and initiate an authentication procedure with the AUSF (450) (1408). The authentication procedure (1408) may include at least one of the target AMF or SMF (1430) requesting authentication of the UE (410) from the AUSF (450), the AUSF (450) obtaining authentication data of the UE (410) from the UDM (430), and the AUSF (450) performing authentication with the UE (410) through the target AMF or SMF (1430).
[0210] After performing the authentication procedure (1408), the target AMF or SMF (1430) can perform the NAS security setup procedure with the UE (410) (1410). Through the security setup procedure (1410), the target AMF or SMF (1430) can obtain security context information for the UE (410) and provide the security context information of the UE (410) to the RAN (440). The security context information can be used to protect messages transmitted or received between the UE (410) and the RAN (440).
[0211] After the NAS security setup procedure (1410) is completed, the target AMF or SMF (1430) can determine the allowed NSSAI (1412) and send the allowed NSSAI to the UE (410) via a registration acceptance message (1414). The UE (410) can complete the initial registration procedure by sending a registration completion message to the target AMF or SMF (1430) (1416). The allowed NSSAI received via the registration acceptance message (1414) can be used by the UE (410) to identify network slices and establish connections.
[0212] According to the proposed method 4 of the present disclosure, the UE (410) can request the NSSAI requiring protection from the network even before the NAS security setup procedure (1410) is completed, so that the redeployment of the AMF or SMF for the NSSAI requiring protection can be performed more quickly and effectively. For example, the NSSAI requiring protection may include an NSSAI associated with a network slice for security-sensitive services such as government services, military communications services, medical services, and financial services.
[0213] Proposed Method 5
[0214] Method 5 of the present disclosure proposes two fallback procedures for cases where the RAN cannot decode a PQC-based protected network slice identifier. For example, cases where the RAN cannot decode a PQC-based protected network slice identifier may include cases where a PQC profile is not set on the RAN, cases where the RAN does not support PQC, etc.
[0215] Fallback procedure 1 according to method 5 of the present disclosure may include the UE transmitting only the S-NSSAI for the five SSTs defined in the 3GPP standard to the network via the requested NSSAI through the initial access procedure, and transmitting the NSSAI requiring protection to the initial AMF or SMF by PQC-based encryption through the update registration procedure after the NAS security setup procedure is completed, and decrypting the PQC-based encrypted NSSAI in the initial AMF or SMF to perform the redeployment of the AMF or SMF.
[0216] Fallback procedure 2 according to method 5 of the present disclosure may include the UE performing an existing standard procedure based on a default S-NSSAI without sending any S-NSSAI through an initial access procedure, encrypting the NSSAI requiring protection based on PQC after the NAS security setup procedure is completed and transmitting it to an initial AMF or SMF, and decrypting the PQC-encrypted NSSAI from the initial AMF or SMF to perform relocation of the AMF or SMF.
[0217] FIG. 15 illustrates a fallback procedure 1 according to method 5 proposed in the present disclosure. FIG. 15 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 15. For example, some configurations illustrated in FIG. 15 may be omitted, and configurations not illustrated in FIG. 15 may be added. FIG. 15 focuses on NSSAI and S-NSSAI, but NSSAI and S-NSSAI can be generalized to network slice identifiers.
[0218] Referring to FIG. 15, it is assumed that the UE (410) is not yet registered with the network and has a configured NSSAI and a PQC-based public key of the RAN (440). Additionally, in the example of FIG. 15, it is assumed that the configured NSSAI includes at least one public S-NSSAI and at least one S-NSSAI tagged with QR information. In the present disclosure, an S-NSSAI for an SST defined in a 3GPP standard may be referred to as a public S-NSSAI, and an S-NSSAI containing QR information indicating that PQC-based protection according to the present disclosure is configured may be referred to as a QR-tagged S-NSSAI.
[0219] The UE (410) can send an initial registration request message to the RAN (440) through an initial access procedure (1502). For example, the initial registration request message can be sent to the RAN (440) through a Radio Resource Control (RRC) setup completion message (e.g., RRCSetupComplete message) of the initial access procedure. In fallback procedure 1, only the public S-NSSAI or the S-NSSAI for the five SSTs defined in the 3GPP standard can be sent to the RAN (440) through the request NSSAI.
[0220] RAN (440) can select an initial AMF or SMF (1420) (1504) and send a registration request message to the initial AMF or SMF (1420) (1506).
[0221] An initial AMF or SMF (1420) may select an AUSF (450) and initiate an authentication procedure with the AUSF (450) (1508). The authentication procedure (1508) may include at least one of the initial AMF or SMF (1420) requesting authentication of the UE (410) from the AUSF (450), the AUSF (450) obtaining authentication data of the UE (410) from the UDM (430), and the AUSF (450) performing authentication with the UE (410) through the initial AMF or SMF (1420).
[0222] After performing the authentication procedure (1508), the initial AMF or SMF (1420) may perform a NAS security setup procedure with the UE (410) (1510). In the proposed method 5 of the present disclosure, the NAS security setup procedure may be performed based on PQC. The initial AMF or SMF (1420) may obtain PQC-based security context information for the UE (410) through the security setup procedure (1510) and provide the PQC-based security context information of the UE (410) to the RAN (440). The PQC-based security context information may be used to protect messages transmitted or received between the UE (410) and the RAN (440).
[0223] After the NAS security setup procedure (1510) is completed, the initial AMF or SMF (1420) determines the initial allowed NSSAI (1512) and can send the allowed NSSAI to the UE (410) via an initial registration acceptance message (1514). The UE (410) can complete the initial registration procedure by sending an initial registration completion message to the initial AMF or SMF (1420) (1516).
[0224] The UE can transmit a request NSSAI containing a QR-tagged S-NSSAI to an initial AMF or SMF (1420) via an update registration request message (1518). The initial AMF or SMF (1420) can determine a protection scheme and an encryption profile based on protection scheme information and / or profile selection information included in the S-NSSAI or in the header of the S-NSSAI, and can perform PQC-based decryption on the request NSSAI (1518) (1520). The initial AMF or SMF (1420) can also determine a target AMF or SMF (1430) and determine an allowable NSSAI for the request NSSAI (1518) (1520).
[0225] Through the relocation (1522) of the AMF or SMF, the allowed NSSAI can be provided from the initial AMF or SMF (1420) to the target AMF or SMF (1430), and the target AMF or SMF (1430) can transmit the allowed NSSAI to the UE (410) through an update registration acceptance message.
[0226] FIG. 16 illustrates fallback procedure 2 according to method 5 proposed in the present disclosure. FIG. 16 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 16. For example, some configurations illustrated in FIG. 16 may be omitted, and configurations not illustrated in FIG. 16 may be added. FIG. 16 focuses on NSSAI and S-NSSAI, but NSSAI and S-NSSAI can be generalized to network slice identifiers.
[0227] Referring to FIG. 16, it is assumed that the UE (410) is not yet registered with the network and has a configured NSSAI and a PQC-based public key of the RAN (440). Additionally, in the example of FIG. 16, it is assumed that the configured NSSAI includes at least one public S-NSSAI and at least one S-NSSAI tagged with QR information. In the present disclosure, an S-NSSAI for an SST defined in a 3GPP standard may be referred to as a public S-NSSAI, and an S-NSSAI containing QR information indicating that PQC-based protection according to the present disclosure is configured may be referred to as a QR-tagged S-NSSAI.
[0228] The UE (410) can send an initial registration request message to the RAN (440) through an initial access procedure (1602). For example, the initial registration request message can be sent to the RAN (440) through a Radio Resource Control (RRC) setup completion message (e.g., RRCSetupComplete message) of the initial access procedure. In fallback procedure 2, the UE does not send any S-NSSAI to the RAN (440) through the initial registration message.
[0229] RAN (440) can select an initial AMF or SMF (1420) (1604) and send a registration request message to the initial AMF or SMF (1420) (1606).
[0230] An initial AMF or SMF (1420) may select an AUSF (450) and initiate an authentication procedure with the AUSF (450) (1608). The authentication procedure (1608) may include at least one of the initial AMF or SMF (1420) requesting authentication of the UE (410) from the AUSF (450), the AUSF (450) obtaining authentication data of the UE (410) from the UDM (430), and the AUSF (450) performing authentication with the UE (410) through the initial AMF or SMF (1420).
[0231] After performing the authentication procedure (1608), the initial AMF or SMF (1420) may perform a NAS security setup procedure with the UE (410) (1610). In the proposed method 5 of the present disclosure, the NAS security setup procedure may be performed based on PQC. The initial AMF or SMF (1420) may obtain PQC-based security context information for the UE (410) through the security setup procedure (1610) and provide the PQC-based security context information of the UE (410) to the RAN (440). The PQC-based security context information may be used to protect messages transmitted or received between the UE (410) and the RAN (440).
[0232] After the NAS security setup procedure (1610) is completed, the initial AMF or SMF (1420) receives a request NSSAI containing an encrypted QR-tagged S-NSSAI from the UE (410) (not shown), determines a protection scheme and encryption profile based on protection scheme information and / or profile selection information included with or in the header of the S-NSSAI, and can perform PQC-based decryption on the request NSSAI (1612). The initial AMF or SMF (1420) can also determine a target AMF or SMF (1430) and determine an allowable NSSAI for the request NSSAI (1612).
[0233] Through the relocation (1614) of the AMF or SMF, the accepted NSSAI can be provided from the initial AMF or SMF (1420) to the target AMF or SMF (1430), and the target AMF or SMF (1430) can transmit the accepted NSSAI to the UE (410) through a registration acceptance message (1616). The UE (410) can complete the initial registration procedure by transmitting a registration completion message to the target AMF or SMF (1430) (1618).
[0234] FIG. 17 illustrates a flowchart of a method performed by a terminal according to the proposed method of the present disclosure. FIG. 17 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 17. For example, some components illustrated in FIG. 17 may be omitted, and components not illustrated in FIG. 17 may be added.
[0235] Referring to FIG. 17, the terminal can identify whether the network slice identifier includes first information indicating that Post Quantum Cryptography (PQC)-based encryption is performed on the network slice identifier (1702). For example, the first information may be QR information or privacy information according to Method 1 of the present disclosure, and the network slice identifier may be a network slice identifier including QR information or privacy information according to Method 1 of the present disclosure (e.g., see 620 in FIG. 6 and 7). As a more specific example, the network slice identifier may be an S-NSSAI included in a set NSSAI, and the S-NSSAI may include the first information, information regarding SST (Slice / Service Type) (e.g., see 622 in FIG. 6 and 7), and information regarding SD (Service Differentiator) (e.g., see 624 in FIG. 6 and 7). For example, the first information may have a value of 1, but the value may be changed (e.g., see Method 1 proposed in the present disclosure). Alternatively, the network slice identifier may be a legacy network slice identifier (e.g., see 210 in FIG. 2, FIG. 6 and FIG. 7) and may not include the first information.
[0236] If the network slice identifier includes first information (e.g., QR information), the terminal can obtain a protected network slice identifier by performing PQC-based encryption on the network slice identifier (1704). For example, PQC-based encryption may include encryption according to the proposed method 2 of the present disclosure or the proposed method 3 of the present disclosure.
[0237] For example, when encryption according to the proposed method 2 of the present disclosure is applied in 1704, the PQC-based encryption may include generating a first shared key (e.g., S1 in FIG. 8) based on the public key of a network entity (e.g., 802 in FIG. 8) and the private key of a terminal (e.g., 804 in FIG. 8), generating a second shared key (e.g., S2 in FIG. 8) based on the PQC-based public key of the network entity (e.g., 812 in FIG. 8), generating a third shared key (e.g., hybrid shared key in FIG. 8) based on the first shared key and the second shared key, and encrypting a network slice identifier (e.g., 832 in FIG. 8) based on the third shared key (e.g., 842 in FIG. 8). For example, the private key of the terminal may be obtained through the generation of a key pair of the terminal's public key and private key (e.g., 902 in FIG. 10). For example, generating a first shared key may include generating a first shared key using asymmetric key consensus (e.g., 806 in FIG. 8) based on the public key of a network entity and the private key of a terminal, generating a second shared key may include generating a second shared key using PQC key encapsulation (e.g., 814 in FIG. 8) based on the PQC-based public key of a network entity, and generating a third shared key may include generating a third shared key by performing an XOR (Exclusive OR) operation (e.g., 822 in FIG. 8) on the first shared key and the second shared key.
[0238] For example, when encryption according to the proposed method 3 of the present disclosure is applied in 1704, the PQC-based encryption may include generating a ciphertext (e.g., 1204 in FIG. 12) by performing encryption on a network slice identifier based on the public key of a network entity (e.g., 1202 in FIG. 12), and performing a PQC algorithm on the ciphertext based on the PQC-based public key of a network entity (e.g., 812 in FIG. 12) (e.g., 1206 in FIG. 12). For example, generating a ciphertext may include generating a key pair of the terminal's public key and private key (e.g., 902 in FIG. 13), generating a shared key based on the network entity's public key (e.g., 1008 in FIG. 13) and the terminal's private key (e.g., 906 in FIG. 13) (e.g., 912 in FIG. 13), and generating a ciphertext by encrypting a network slice identifier based on the shared key (e.g., 920 in FIG. 13).
[0239] The terminal may transmit a message containing a protected network slice identifier to a network entity (1706). For example, the message (1706) may further include second information (e.g., profile selection information, 632 in FIG. 6) indicating a profile of an algorithm for PQC-based encryption, and third information (e.g., protection method information, 634 in FIG. 6) indicating a shared key generation method and an encryption method for PQC-based encryption. For example, the second information and the third information may be included as headers of the protected network slice identifier (e.g., 630 in FIG. 6) to form encrypted network slice identifiers (e.g., 632, 634, 630 in FIG. 6), or they may be included in the message separately from the protected network slice identifier. Alternatively, for example, the message (1706) may further include a fourth piece of information (e.g., protection method information, 710 in FIG. 7) that indicates the profile of the algorithm for PQC-based encryption, the shared key generation method for PQC-based encryption, and the encryption method together. For example, the fourth piece of information may be included as a header of a protected network slice identifier (e.g., 630 in FIG. 7) to form an encrypted network slice identifier (710, 630 in FIG. 7), or it may be included in the message separately from the protected network slice identifier.
[0240] For example, the message (1706) may be an initial registration request message (e.g., 1402 in FIG. 14), in which case the terminal may perform an initial registration procedure according to the proposed method 4 of the present disclosure. In response to the initial registration request message, the terminal may receive a registration acceptance message (e.g., 1414 in FIG. 14) containing an allowed network slice identifier from a network entity. For example, the network entity may be a base station or RAN (440), or an AMF or SMF (1420 or 1430).
[0241] If the network entity is unable to decrypt the encrypted network slice identifier, the terminal may transmit the PQC-based encrypted network slice identifier to the network entity in accordance with fallback procedure 1 or fallback procedure 2 of the proposed method 5 of the present disclosure (e.g., see proposed method 5 of the present disclosure).
[0242] FIG. 18 illustrates a flowchart of a method performed by a network entity according to the proposed method of the present disclosure. FIG. 18 is merely an example to aid in understanding the present disclosure, and the present disclosure is not limited to the example of FIG. 18. For example, some configurations illustrated in FIG. 18 may be omitted, and configurations not illustrated in FIG. 18 may be added. The network entity may be a base station or a RAN (440), or an AMF or an SMF (1420 or 1430).
[0243] Referring to FIG. 18, a network entity may receive a message containing an encrypted network slice identifier from a User Equipment (UE) (1802). For example, the encrypted network slice identifier may have a format according to the proposed method 1 of the present disclosure (e.g., 632, 634, 630 of FIG. 6 or 710, 630 of FIG. 7), and the encrypted network slice identifier may include a protected network slice identifier (e.g., 630 of FIG. 6 and 7) and information regarding a protection method for the protected network slice identifier (e.g., 634 of FIG. 6 or 710 of FIG. 7).
[0244] A network entity can obtain a network slice identifier by performing Post Quantum Cryptography (PQC)-based decryption on a protected network slice identifier based on information regarding the protection method (1804). For example, the PQC-based decryption may be performed to correspond to PQC-based encryption according to Method 2 proposed in the present disclosure or Method 3 proposed in the present disclosure.
[0245] For example, when PQC-based encryption according to the proposed method 2 of the present disclosure is applied to a protected network slice identifier, PQC-based decryption in 1804 may include obtaining a first shared key (e.g., S1) based on the terminal's public key and the network entity's private key (e.g., operation 6 of FIG. 11), generating a second shared key (e.g., S2) based on the network entity's PQC-based public key (e.g., operation 7 of FIG. 11), generating a third shared key (e.g., S) based on the first shared key and the second shared key (e.g., operation 8 of FIG. 11), and decrypting the protected network slice identifier based on the third shared key (e.g., operation 9 of FIG. 11). For example, generating a first shared key may include generating a first shared key using asymmetric key consensus (e.g., 806 in FIG. 8) based on the public key of a terminal and the private key of a network entity, generating a second shared key may include generating a second shared key using PQC key encapsulation (e.g., 814 in FIG. 8) based on the PQC-based public key of a network entity, and generating a third shared key may include generating a third shared key by performing an Exclusive OR (XOR) operation (e.g., 822 in FIG. 8) on the first shared key and the second shared key.
[0246] For example, when PQC-based encryption according to the proposed method 3 of the present disclosure is applied to a protected network slice identifier, PQC-based decryption may be performed to correspond to the encryption exemplified in FIG. 12. More specifically, PQC-based decryption may include generating an intermediate ciphertext by performing a PQC algorithm on the protected network slice identifier based on the PQC-based private key of the network entity, and performing decryption on the intermediate ciphertext based on the private key of the network entity. For example, performing decryption on the intermediate ciphertext may include generating a shared key based on the public key of the terminal and the private key of the network entity, and performing decryption on the intermediate ciphertext based on the shared key.
[0247] For example, message (1802) may be an initial registration request message, in which case the network entity may perform an initial registration procedure according to method 4 of the present disclosure. The network entity may select an Access and Mobility Management Function (AMF) or a Session Management Function (SMF) based on a network slice identifier and transmit a registration request message to the selected AMF or SMF (e.g., see FIG. 14 and related description).
[0248] Device and System Structure
[0249] FIG. 19 illustrates the structure of a terminal to which the proposed method of the present disclosure may be applied. FIG. 19 is for illustrative purposes only, and the present disclosure is not limited to the example of FIG. 19. Some components in FIG. 19 may be omitted, and components not shown in FIG. 19 may be added.
[0250] Referring to FIG. 19, the terminal (1900) may include a transceiver (1920) comprising a receiver and a transmitter, a memory (1930), and a processor (1910). The transceiver (1920), memory (1930), and processor (1910) of the terminal may be configured to implement the proposed method of the present disclosure. The transceiver (1920), memory (1930), and processor (1910) may be implemented in the form of one or more semiconductor chips.
[0251] The transceiver (1920) may be configured to transmit and receive signals with a network entity. The signals may include, for example, control information and data. The transceiver may be composed of an RF (radio frequency) transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies a received signal and down-converts the frequency. However, this is merely one embodiment of the transceiver, and the components of the transceiver are not limited to an RF transmitter and an RF receiver. Additionally, the transceiver may receive a signal via a wireless channel and output it to a processor, and transmit the signal output from the processor via a wireless channel.
[0252] The memory (1930) can store programs and data necessary for the operation of the terminal. Additionally, the memory can store control information or data included in signals transmitted and received by the terminal. The memory can be composed of a storage medium or a combination of storage media such as ROM, RAM, hard disk, CD-ROM, and DVD. Additionally, there may be multiple memories.
[0253] A processor (1910) can control a series of processes so that a terminal can operate according to the proposed method of the present disclosure. For example, the processor can control the components of the terminal to perform the proposed method 1 to the proposed method 5 of the present disclosure. There may be multiple processors, and the processors can perform the control operation of the terminal components by executing a program stored in memory.
[0254] FIG. 20 illustrates the structure of a network entity to which the proposed method of the present disclosure may be applied. The example in FIG. 20 is for illustrative purposes only, and the present disclosure is not limited to the example in FIG. 20. Some components in FIG. 20 may be omitted, and components not shown in FIG. 20 may be added.
[0255] Referring to FIG. 20, a network entity (2000) may include a transceiver (2020) including a receiver and a transmitter, a memory (2030), and a processor (2010). The transceiver (2020), memory (2030), and processor (2010) of the network entity (2000) may be configured to implement proposed methods 1 to 5 of the present disclosure. The transceiver (2020), memory (2030), and processor (2010) may be implemented in the form of one or more semiconductor chips.
[0256] The transceiver (2020) can transmit and receive signals with a terminal. The signals may include, for example, control information and data. The transceiver may be composed of an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies a received signal and down-converts the frequency. However, this is merely one embodiment of the transceiver, and the components of the transceiver are not limited to an RF transmitter and an RF receiver. Additionally, the transceiver may receive a signal through a wireless channel and output it to a processor, and transmit the signal output from the processor through a wireless channel.
[0257] The memory (2030) can store programs and data necessary for the operation of the network entity. Additionally, the memory can store control information or data included in signals transmitted and received by the network entity. The memory can be composed of a storage medium or a combination of storage media such as ROM, RAM, hard disk, CD-ROM, and DVD. Additionally, there may be multiple memories.
[0258] A processor (2010) can control a series of processes so that a network entity can operate according to the proposed method of the present disclosure. For example, the processor can control each component of the network entity to perform the proposed method 1 to the proposed method 5 of the present disclosure. There may be multiple processors, and the processors can perform control operations on the components of the network entity by executing a program stored in memory.
[0259] FIG. 21 illustrates a communication system to which the proposed method of the present disclosure may be applied. The example in FIG. 21 is for illustrative purposes only, and the present disclosure is not limited to the example in FIG. 21. Some components in FIG. 21 may be omitted, and components not shown in FIG. 21 may be added.
[0260] In next-generation wireless communication systems, it is expected that communication services for application fields requiring special security, such as government services, military communication services, medical services, and financial services, can be provided by utilizing quantum security algorithms to prevent security threats caused by the emergence of quantum computers. As illustrated in FIG. 21, it is expected that security for network slice services requiring enhanced security, such as government services, military communication services, medical services, and financial services, can be strengthened in preparation for the emergence of quantum computers through the protection of optional network slice identifiers with applied quantum security proposed in this disclosure.
[0261] Methods according to the embodiments described in the claims or specification of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.
[0262] When implemented in software, a computer-readable storage medium may be provided for storing one or more programs (software modules). One or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. One or more programs include instructions that cause the electronic device to execute methods according to the embodiments described in the claims or specification of this disclosure.
[0263] Such programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, ROM (Read Only Memory), Electrically Erasable Programmable Read Only Memory (EEPROM), magnetic disc storage devices, Compact Disc-ROM (CD-ROM), Digital Versatile Discs (DVDs), or other forms of optical storage devices, magnetic cassettes. Alternatively, they may be stored in memory composed of some or all of these. Additionally, each constituent memory may include multiple units.
[0264] Additionally, the program may be stored on an attachable storage device accessible via a communication network such as the Internet, Intranet, Local Area Network (LAN), Wide LAN (WLAN), or Storage Area Network (SAN), or a combination thereof. Such a storage device may be connected to the device performing the embodiment of the present disclosure through an external port. Additionally, a separate storage device on the communication network may be connected to the device performing the embodiment of the present disclosure.
[0265] In the specific embodiments of the present disclosure described above, the components included in the disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural form, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.
[0266] Meanwhile, although specific embodiments have been described in the detailed description of the present disclosure, it is understood that various modifications are possible within the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims set forth below as well as equivalents thereof.
[0267] The various embodiments of the present disclosure and the terms used therein are not intended to limit the technology described in the present disclosure to specific embodiments and should be understood to include various modifications, equivalents, and / or substitutions of said embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar components. A singular expression may include a plural expression unless the context clearly indicates otherwise. In the present disclosure, expressions such as "A or B," "at least one of A and / or B," "A, B or C," or "at least one of A, B and / or C" may include all possible combinations of items listed together. Expressions such as "first," "second," "first," or "second" may modify said components regardless of order or importance and are used only to distinguish one component from another and do not limit said components. When it is mentioned that a certain (e.g., 1st) component is "(functionally or telecommunicationally) connected" or "connected" to another (e.g., 2nd) component, said certain component may be directly connected to said other component or connected through another component (e.g., 3rd component).
[0268] As used in this disclosure, the term "module" includes a unit composed of hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be a component formed integrally, or a minimum unit or part thereof that performs one or more functions. For example, a module may be composed of an application-specific integrated circuit (ASIC).
[0269] Various embodiments of the present disclosure may be implemented as software (e.g., a program) comprising instructions stored in a machine-readable storage medium (e.g., internal memory or external memory) that is readable by a machine (e.g., a computer). The machine may include a terminal according to various embodiments, which is a device capable of calling instructions stored from the storage medium and operating according to the called instructions. When the instructions are executed by a processor, the processor may perform a function corresponding to the instructions directly or by using other components under the control of the processor. The instructions may include code generated or executed by a compiler or an interpreter.
[0270] A device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' means merely that the storage medium does not contain a signal and is tangible, without distinguishing whether data is stored semi-permanently or temporarily on the storage medium.
[0271] Methods according to the various embodiments disclosed herein may be provided as included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed online in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or through an application store (e.g., Play Store™). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created in a storage medium such as the memory of a manufacturer's server, an application store's server, or a relay server. Each component (e.g., a module or program) according to the various embodiments may be composed of a singular or multiple entities, and some of the aforementioned sub-components may be omitted, or other sub-components may be further included in the various embodiments. Generally or additionally, some components (e.g., a module or program) may be integrated into a single entity to perform the same or similar functions as those performed by each of the respective components prior to integration. Operations performed by a module, program, or other component according to various embodiments may be executed sequentially, in parallel, iteratively, or heuristically, or at least some operations may be executed in a different order, omitted, or other operations may be added.
Claims
1. A method performed by a User Equipment (UE) in a wireless communication system, A step of identifying whether a network slice identifier includes first information indicating that Post Quantum Cryptography (PQC)-based encryption is performed on the network slice identifier; If the network slice identifier includes the first information, the step of obtaining a protected network slice identifier by performing PQC-based encryption on the network slice identifier; and A method comprising the step of transmitting a message containing the above-mentioned protected network slice identifier to a network entity.
2. In Claim 1, A method in which the above message further includes second information indicating the profile of the algorithm for the PQC-based encryption and third information indicating the shared key generation method and the encryption method for the PQC-based encryption.
3. In Claim 1, A method in which the above message further includes fourth information indicating the profile of the algorithm for the PQC-based encryption and the shared key generation method and encryption method for the PQC-based encryption.
4. In Claim 1, The above PQC-based encryption is, Generating a first shared key based on the public key of the above network entity and the private key of the above UE, and Generating a second shared key based on the PQC-based public key of the above network entity, and Generating a third shared key based on the first shared key and the second shared key, and A method comprising encrypting the network slice identifier based on the third shared key.
5. In Claim 4, Generating the first shared key includes generating the first shared key using asymmetric key consensus based on the public key of the network entity and the private key of the UE, and Generating the second shared key includes generating the second shared key using PQC key encapsulation based on the PQC-based public key of the network entity, and A method for generating the third shared key, comprising generating the third shared key by performing an XOR (Exclusive OR) operation on the first shared key and the second shared key.
6. In Claim 1, The above PQC-based encryption is, Generating a ciphertext by performing encryption on the network slice identifier based on the public key of the network entity, and A method comprising performing a PQC algorithm on the ciphertext based on the PQC-based public key of the network entity.
7. In Claim 6, Generating the above ciphertext is, Generating a key pair of the public and private keys of the above UE, and Generating a shared key based on the public key of the above network entity and the private key of the above UE, and A method comprising generating the ciphertext by encrypting the network slice identifier based on the shared key.
8. In Claim 1, A method wherein the network slice identifier is S-NSSAI (Single Network Slice Assistance Information), and the S-NSSAI includes the first information, information regarding SST (Slice / Service Type), and information regarding SD (Service Differentiator).
9. In a method performed by a network entity in a wireless communication system, A step of receiving a message containing an encrypted network slice identifier from a User Equipment (UE), wherein the encrypted network slice identifier includes information regarding a protected network slice identifier and a protection method for the protected network slice identifier; and A method comprising the step of obtaining a network slice identifier by performing Post Quantum Cryptography (PQC)-based decryption on the protected network slice identifier based on information regarding the protection method.
10. In Claim 9, The above PQC-based decoding is, Obtaining a first shared key based on the public key of the above UE and the private key of the above network entity, and Generating a second shared key based on the PQC-based public key of the above network entity, and Generating a third shared key based on the first shared key and the second shared key, and A method comprising decrypting the protected network slice identifier based on the third shared key.
11. In Claim 10, Generating the first shared key includes generating the first shared key using asymmetric key consensus based on the public key of the UE and the private key of the network entity, and Generating the second shared key includes generating the second shared key using PQC key encapsulation based on the PQC-based public key of the network entity, and A method for generating the third shared key, comprising generating the third shared key by performing an XOR (Exclusive OR) operation on the first shared key and the second shared key.
12. In Claim 9, The above PQC-based decoding is, Generating an intermediate ciphertext by performing a PQC algorithm on the protected network slice identifier based on the PQC-based private key of the above network entity, and A method comprising performing decryption on the intermediate ciphertext based on the private key of the network entity.
13. In Claim 12, Performing decryption on the above intermediate ciphertext is, Generating a shared key based on the public key of the above UE and the private key of the above network entity, and A method comprising performing decryption on the intermediate ciphertext based on the shared key.
14. User Equipment (UE) for a wireless communication system, Transmitter / receiver; and It includes a processor connected to the above-mentioned transceiver, and the processor, Identifying whether the network slice identifier includes first information indicating that Post Quantum Cryptography (PQC)-based encryption is performed on the network slice identifier, and If the above network slice identifier includes the above first information, the above PQC-based encryption is performed on the above network slice identifier to obtain a protected network slice identifier, and A UE configured to control the above transceiver to transmit a message containing the above protected network slice identifier to a network entity.
15. In a network entity for a wireless communication system, Transmitter / receiver; and It includes a processor connected to the above-mentioned transceiver, and the processor, A message containing an encrypted network slice identifier is received from a User Equipment (UE), wherein the encrypted network slice identifier includes information regarding a protected network slice identifier and a protection method for the protected network slice identifier, and A network entity configured to obtain a network slice identifier by performing Post Quantum Cryptography (PQC)-based decryption on the protected network slice identifier based on information regarding the above protection method.
Citation Information
Patent Citations
Method and system for distributing network slices and electronic equipment
CN116761168A
Method and apparatus of network slicing by using dynamic network traffic analysis based on software defined networking
KR102053596B1
Inspection System and Method for Compact Camera Module Cover
KR102272745B1
Privacy key and message authentication code
US20220272534A1
Methods and systems for performing post quantum cryptography based asymmetric key encryption during primary authentication
WO2024162661A1