Hybrid SUCI Encryption with ECC and PQC

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional ECIES-based SUCI encryption is vulnerable to quantum cryptanalysis, posing a threat to communication security as it can be broken by a Cryptographically Relevant Quantum Computer using Shor's algorithm.

Innovation Solution

Implementing a hybrid SUCI encryption method that uses both elliptic curve cryptography (ECC) and post-quantum cryptography (PQC), where the SUCI comprises a SUPI type indicating the use of both ECC and PQC, ensuring security against quantum attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ECIES-based SUCI encryption is used, then communication security is provided, but it is vulnerable to quantum cryptanalysis

Engineering Contradiction:
Improvecommunication securityVSAvoidquantum cryptanalysis vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies composite cryptography by combining ECIES (elliptic curve integrated encryption scheme) with PQC (post-quantum cryptography) algorithms. The hybrid encryption scheme uses both traditional ECIES and post-quantum algorithms (such as Kyber or Dilithium) to create a composite encryption system that leverages the strengths of both approaches, providing security against both classical and quantum attacks.

Inventive Principle:
Principle #40Composite materials

Solution Approach 2:

The patent segments the encryption process into multiple independent cryptographic operations. Instead of relying on a single encryption algorithm, the SUCI generation is divided into ECIES-based encryption and PQC-based encryption steps, with each segment providing a layer of security. This segmentation allows the system to maintain security even if one cryptographic primitive is compromised.

Inventive Principle:
Principle #1Segmentation

2Reliability

If hybrid ECC and PQC encryption is implemented, then resistance against quantum attacks is achieved, but device complexity increases

Engineering Contradiction:
Improvequantum attack resistanceVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal SUCI generation framework that can handle multiple cryptographic schemes through a unified interface. The system is designed to support both traditional ECIES and post-quantum algorithms within the same architecture, allowing flexible configuration and selection of cryptographic primitives without requiring separate dedicated systems for each algorithm.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent utilizes parameter changes in the SUPI type field to indicate the cryptographic scheme being used. By modifying the SUPI type parameter, the system can signal whether ECIES, PQC, or hybrid encryption is employed, enabling the network to appropriately process SUCIs based on their encryption method without increasing structural complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250048113A1SUCI encryption
Publication Date: 2025.02.06 NOKIA TECHNOLOGIES OY
  • US20250048113A1 patent drawing
  • US20250048113A1 patent drawing
  • US20250048113A1 patent drawing

AI summary

Embodiments of the present disclosure relate to subscription concealed identifier (SUCI) encryption. In an aspect, a terminal device generates a SUCI of the terminal device based on a subscription permanent identifier (SUPI) of the terminal device. The SUCI comprises a SUPI type indicating that both elliptic curve cryptography (ECC) and post quantum cryptography (PQC) are used in the generating of the SUCI. The terminal device further transmits the SUCI to a network device. As such, a SUCI can be defined to comprise a SUPI type indicating that both the ECC and PQC are used in the generating of the SUCI. With the SUCI generated based on both the ECC and PQC, different kinds of cryptanalytic attacks can be avoided.