Post-Quantum Session Key Service for Enterprise 5G Roaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network communication systems are vulnerable to quantum computer attacks, particularly with the advent of quantum computers that can break existing public key cryptography methods like RSA and elliptic curve cryptography, compromising the security of encrypted data, especially in enterprise 5G deployments with co-located Private LTE and WiFi, and large-scale WAN deployments.

Innovation Solution

The implementation of a quantum-resistant Session Key Service (SKS) that uses post-quantum pre-shared keys (PQPSK) and post-quantum common secret seeds (PQSEED) for secure key generation and distribution across Wireless LAN Controllers (WLC), Access Points (AP), and User Equipment (UE), establishing secure tunnels and sessions resistant to quantum computer attacks through protocols like CAPWAP/DTLS, SXP, BGP, and DNSCrypt.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If quantum computers become available, then cryptanalytic attacks can break existing public key cryptography (RSA, elliptic curves), but this undermines the security of encrypted data stored and transmitted today

Engineering Contradiction:
Improvecryptographic securityVSAvoidquantum computer attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by implementing post-quantum cryptographic algorithms (such as lattice-based cryptography, code-based cryptography, or hash-based signatures) into network devices and protocols before quantum computers become operational. This allows systems to be upgraded to quantum-resistant cryptography in advance, protecting encrypted data from future quantum attacks without requiring immediate deployment of quantum technology.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If existing public key cryptography methods are used for secure communication, then current network protocols work efficiently, but they become vulnerable to quantum computer attacks

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidquantum resistance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies parameter changes by transitioning from traditional public key cryptographic parameters (RSA key sizes, elliptic curve parameters) to post-quantum cryptographic parameters (lattice dimensions, polynomial degrees, hash function parameters). This parameter transformation enables the same communication protocols to maintain efficiency while achieving quantum-resistant security levels.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent substitutes the mechanical/crypto-system of traditional public key infrastructure with post-quantum cryptographic mechanisms. This includes replacing RSA/ECDSA key exchange and signature algorithms with quantum-resistant alternatives such as CRYSTALS-Kyber for key encapsulation, CRYSTALS-Dilithium for digital signatures, or SPHINCS+ for stateless signatures, thereby eliminating vulnerability to quantum attacks while preserving protocol functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If quantum-resistant cryptography is implemented across enterprise deployments, then future security is ensured, but system complexity and implementation challenges increase

Engineering Contradiction:
Improvelong-term securityVSAvoidquantum-resistant implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing post-quantum cryptographic solutions that can be integrated into multiple existing network protocols and enterprise systems simultaneously. The implementation provides quantum-resistant security across diverse applications including secure email, file transfer, virtual private networks, and cloud services using a unified cryptographic framework, reducing the need for separate implementations for each system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces intermediary components such as quantum-resistant certificate authorities, key management services, and protocol translation layers that facilitate the transition to post-quantum cryptography. These intermediaries handle the complexity of key generation, distribution, and validation, allowing legacy systems to communicate securely with quantum-resistant infrastructure without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12052350B2Quantum resistant secure key distribution in various protocols and technologies
Publication Date: 2024.07.30 CISCO TECHNOLOGY INC
  • US12052350B2 patent drawing
  • US12052350B2 patent drawing
  • US12052350B2 patent drawing

AI summary

A quantum resistant method is provided for supporting user equipment (UE) roaming across APs/eNBs/gNBs belonging to various Wireless LAN Controllers (WLCs) in enterprise 5G and WiFi co-located deployments. The method may include initializing a SKS server in an electrical communication with a master WLC with a random post-quantum common secret seed (PQSEED) to generate a post-quantum pre-shared key (PQPSK) and a respective PQPSK-ID. The method may also include sending an encrypted PQSEED along with a PQPSK-ID to a second WLC. The method may further include joining AP (WiFi) to the master WLC using a CAPWAP/DTLS protocol. The method may further include sending the PQPSK-ID from the master WLC to the UE in an EAP success packet when the UE is associated with the AP (WiFi).