Post-Quantum SUCI Encryption for 5G Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G networks face security challenges due to the vulnerability of elliptic curve cryptography (ECC) algorithms to quantum computers, which can break long-term static ECC public keys, and the need for post-quantum cryptography to secure Subscriber Concealed Identifiers (SUCI) and shared secret keys against quantum computers, especially with the transition from 128-bit to 256-bit keys.

Innovation Solution

Implementing post-quantum cryptography algorithms, such as lattice-based or code-based key exchange mechanisms, to securely convert Subscriber Permanent Identifiers (SUPI) into SUCI and manage shared secret keys, ensuring secure encryption and authentication protocols resistant to quantum computer attacks, allowing devices to use either 128-bit or 256-bit keys seamlessly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If elliptic curve cryptography (ECC) algorithms are used for SUCI encryption, then current security standards are met, but security is compromised against quantum computer attacks

Engineering Contradiction:
Improvesecurity against quantum computersVSAvoidvulnerability to quantum attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transitions from ECC algorithms to post-quantum cryptography algorithms, fundamentally changing the cryptographic parameter体系和数学基础 to resist quantum computer attacks while maintaining SUCI encryption functionality

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent proactively implements post-quantum cryptography algorithms before quantum computers become widely capable, preparing the system in advance against future threats while maintaining compatibility with current network infrastructure

Inventive Principle:
Principle #10Preliminary action

2Reliability

If 128-bit keys are used, then current performance requirements are met, but security strength is insufficient for long-term protection

Engineering Contradiction:
Improvelong-term security protectionVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic key length selection, allowing the system to adaptively use either 128-bit or 256-bit keys based on security requirements and device capabilities, providing flexibility in balancing security strength and performance

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent designs a unified key management system that can handle both 128-bit and 256-bit keys through the same post-quantum cryptography framework, enabling devices to seamlessly support multiple key lengths without requiring separate management mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If post-quantum cryptography algorithms are implemented, then future security threats are mitigated, but computational overhead increases

Engineering Contradiction:
Improvequantum-resistant securityVSAvoidcomputational energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements post-quantum cryptography selectively for SUCI encryption operations that require quantum resistance, while using more efficient algorithms for other authentication processes, applying the stronger cryptography only where absolutely necessary

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240113878A1Subscription Concealed Identifier (SUCI) Supporting Post-Quantum Cryptography
Publication Date: 2024.04.04 ADEIA EMERGING TECHNOLOGIES INC
  • US20240113878A1 patent drawing
  • US20240113878A1 patent drawing
  • US20240113878A1 patent drawing

AI summary

A device and a network can authenticate using a subscription concealed identifier (SUCI). The device can store (i) a plaintext subscription permanent identifier (SUPI) for the device, (ii) a network static public key, and (iii) a key encapsulation mechanism (KEM) for encryption using the network static public key. The network can store (i) a device database with the SUPI, (ii) a network static private key, and (iii) the KEM for decryption using the network static private key. The device can (i) combine a random number with the SUPI as input into the KEM to generate a ciphertext as the SUCI, and (ii) transmit the ciphertext/SUCI to the network. The network can (i) decrypt the ciphertext using the KEM to read the SUPI, (iii) select a key K from the device database using the SUPI, and (iv) conduct an Authentication and Key Agreement (AKA) with the selected key K.