Post-Quantum Session Key Service for Enterprise 5G Roaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network communication systems are vulnerable to quantum computer attacks, particularly with the advent of quantum computers that can break existing public key cryptography methods like RSA and elliptic curve cryptography, compromising the security of encrypted data, especially in enterprise 5G deployments with co-located Private LTE and WiFi, and large-scale WAN deployments.
Innovation Solution
The implementation of a quantum-resistant Session Key Service (SKS) that uses post-quantum pre-shared keys (PQPSK) and post-quantum common secret seeds (PQSEED) for secure key generation and distribution across Wireless LAN Controllers (WLC), Access Points (AP), and User Equipment (UE), establishing secure tunnels and sessions resistant to quantum computer attacks through protocols like CAPWAP/DTLS, SXP, BGP, and DNSCrypt.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If quantum computers become available, then cryptanalytic attacks can break existing public key cryptography (RSA, elliptic curves), but this undermines the security of encrypted data stored and transmitted today
Solution Approach 1:
The patent applies preliminary action by implementing post-quantum cryptographic algorithms (such as lattice-based cryptography, code-based cryptography, or hash-based signatures) into network devices and protocols before quantum computers become operational. This allows systems to be upgraded to quantum-resistant cryptography in advance, protecting encrypted data from future quantum attacks without requiring immediate deployment of quantum technology.
2Productivity
If existing public key cryptography methods are used for secure communication, then current network protocols work efficiently, but they become vulnerable to quantum computer attacks
Solution Approach 1:
The patent applies parameter changes by transitioning from traditional public key cryptographic parameters (RSA key sizes, elliptic curve parameters) to post-quantum cryptographic parameters (lattice dimensions, polynomial degrees, hash function parameters). This parameter transformation enables the same communication protocols to maintain efficiency while achieving quantum-resistant security levels.
Solution Approach 2:
The patent substitutes the mechanical/crypto-system of traditional public key infrastructure with post-quantum cryptographic mechanisms. This includes replacing RSA/ECDSA key exchange and signature algorithms with quantum-resistant alternatives such as CRYSTALS-Kyber for key encapsulation, CRYSTALS-Dilithium for digital signatures, or SPHINCS+ for stateless signatures, thereby eliminating vulnerability to quantum attacks while preserving protocol functionality.
3Reliability
If quantum-resistant cryptography is implemented across enterprise deployments, then future security is ensured, but system complexity and implementation challenges increase
Solution Approach 1:
The patent applies universality by designing post-quantum cryptographic solutions that can be integrated into multiple existing network protocols and enterprise systems simultaneously. The implementation provides quantum-resistant security across diverse applications including secure email, file transfer, virtual private networks, and cloud services using a unified cryptographic framework, reducing the need for separate implementations for each system.
Solution Approach 2:
The patent introduces intermediary components such as quantum-resistant certificate authorities, key management services, and protocol translation layers that facilitate the transition to post-quantum cryptography. These intermediaries handle the complexity of key generation, distribution, and validation, allowing legacy systems to communicate securely with quantum-resistant infrastructure without requiring complete system redesign.
Data Source
AI summary
A quantum resistant method is provided for supporting user equipment (UE) roaming across APs/eNBs/gNBs belonging to various Wireless LAN Controllers (WLCs) in enterprise 5G and WiFi co-located deployments. The method may include initializing a SKS server in an electrical communication with a master WLC with a random post-quantum common secret seed (PQSEED) to generate a post-quantum pre-shared key (PQPSK) and a respective PQPSK-ID. The method may also include sending an encrypted PQSEED along with a PQPSK-ID to a second WLC. The method may further include joining AP (WiFi) to the master WLC using a CAPWAP/DTLS protocol. The method may further include sending the PQPSK-ID from the master WLC to the UE in an EAP success packet when the UE is associated with the AP (WiFi).


