Disaggregated Cryptographic Software Architecture for Post-Quantum Agility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

3GPP inventory management Integration Reference Point (IRP) lacks functionality for handling cryptographic information, necessitating cryptography agility to enhance security and post-quantum proof capability against quantum computing threats.

Innovation Solution

A centralized cryptographic inventory management (CIM) framework that supports a mixture of algorithm types, including classical, lattice-based, and isogeny-based cryptography, enabling efficient switching between cryptographic algorithms and ensuring compliance with post-quantum cryptography standards through automated discovery and management tools.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptographic algorithms are used in 3GPP IRP, then current security standards are maintained, but vulnerability to quantum computing attacks increases

Engineering Contradiction:
ImprovesecurityVSAvoidquantum computing threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a dynamic cryptographic algorithm selection mechanism that allows the system to switch between different cryptographic algorithms (classical and post-quantum) based on the security requirements and quantum threat level. The framework enables flexible adaptation of cryptographic functions to respond to evolving security challenges, resolving the contradiction between maintaining current security standards and preparing for quantum threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the cryptographic parameter landscape by supporting multiple algorithm types with different mathematical foundations (lattice-based, isogeny-based, code-based) alongside traditional algorithms. This parameter diversity allows the system to maintain compatibility with existing infrastructure while introducing quantum-resistance, thereby addressing both current security needs and future quantum threats.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple cryptographic algorithms are integrated to support post-quantum cryptography, then cryptographic flexibility and security resilience are improved, but system complexity increases

Engineering Contradiction:
Improvecryptography agilityVSAvoidcryptographic system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal cryptographic framework that handles multiple algorithm types through a single integrated architecture. The framework provides unified interfaces for key management, certificate handling, and cryptographic operations that work across different algorithms (RSA, ECC, lattice-based, isogeny-based), eliminating the need for separate implementation layers and reducing overall system complexity despite supporting diverse algorithms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces intermediary layers including a cryptographic inventory management system and standardized interfaces that mediate between different cryptographic algorithms and the rest of the 3GPP network functions. These intermediaries abstract the complexity of algorithm diversity, providing a simplified view to network functions while maintaining the flexibility to switch between algorithms as needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If automated discovery and management tools are deployed to manage cryptographic inventory, then compliance with evolving standards is improved, but implementation complexity increases

Engineering Contradiction:
ImprovecomplianceVSAvoidmanagement system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the cryptographic inventory management system automatically discovers, inventories, and manages cryptographic algorithms, keys, and certificates without requiring manual intervention. The system autonomously tracks cryptographic usage across network functions, monitors compliance status, and facilitates algorithm switching, thereby achieving high compliance with minimal operational complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The framework incorporates feedback loops that continuously monitor the cryptographic landscape, evolving standards, and system usage patterns. Based on this feedback, the automated management system dynamically adjusts its operations to maintain compliance with latest standards while optimizing the cryptographic inventory, reducing the need for complex manual management processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250310118A1Systems and methods for disaggregated cryptographic software architecture
Publication Date: 2025.10.02 VERIZON PATENT & LICENSING INC
  • US20250310118A1 patent drawing
  • US20250310118A1 patent drawing
  • US20250310118A1 patent drawing

AI summary

Disclosed are systems and methods for a cryptographic inventory management (CIM) framework that enables cryptography agility with regards to network security requirements regarding threats from/of quantum computing and artificial intelligence (AI). The disclosed CIM framework can support a mixture of algorithm types, such as, but not limited to, classical, lattice based, code based, isogeny based and the like, which makes switching between cryptographic algorithms efficient, secure and smooth. The disclosed framework can provide a centralized cryptography inventory system (e.g., keys, algorithms, protocols, libraries, crypto-accelerators) that can be compiled, updated and maintained, and can include all the cryptography assets of network functions and support network functions regardless whether they are physical or virtual, quantum vulnerable or not, and the like. The CIM framework can be compiled and implemented as a centralized cryptography system that is built and maintained via automated cryptography assets discovery tools.