WO2024242541A1 - Methods and systems for performing authentication and key agreement - Google Patents
Methods and systems for performing authentication and key agreement Download PDFInfo
- Publication number
- WO2024242541A1 WO2024242541A1 PCT/KR2024/095830 KR2024095830W WO2024242541A1 WO 2024242541 A1 WO2024242541 A1 WO 2024242541A1 KR 2024095830 W KR2024095830 W KR 2024095830W WO 2024242541 A1 WO2024242541 A1 WO 2024242541A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- key
- network entity
- pqc
- encrypted
- ephemeral
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0838—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
- H04L9/0841—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
- H04L9/0844—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/083—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
- H04L9/0833—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key
- H04L9/0836—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key using tree structure or hierarchical structure
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
Definitions
- the present disclosure relates to the field of wireless communication networks, and more particularly relates to methods and systems performing authentication and key agreement (AKA) in wireless communication networks.
- AKA authentication and key agreement
- 5G 5th-generation
- connected things may include vehicles, robots, drones, home appliances, displays, smart sensors connected to various infrastructures, construction machines, and factory equipment.
- Mobile devices are expected to evolve in various form-factors, such as augmented reality glasses, virtual reality headsets, and hologram devices.
- 6G communication systems are referred to as beyond-5G systems.
- 6G communication systems which are expected to be commercialized around 2030, will have a peak data rate of tera (1,000 giga)-level bps and a radio latency less than 100 ⁇ sec, and thus will be 50 times as fast as 5G communication systems and have the 1/10 radio latency thereof.
- a full-duplex technology for enabling an uplink transmission and a downlink transmission to simultaneously use the same frequency resource at the same time
- a network technology for utilizing satellites, high-altitude platform stations (HAPS), and the like in an integrated manner
- HAPS high-altitude platform stations
- an improved network structure for supporting mobile base stations and the like and enabling network operation optimization and automation and the like
- a dynamic spectrum sharing technology via collison avoidance based on a prediction of spectrum usage an use of artificial intelligence (AI) in wireless communication for improvement of overall network operation by utilizing AI from a designing phase for developing 6G and internalizing end-to-end AI support functions
- a next-generation distributed computing technology for overcoming the limit of UE computing ability through reachable super-high-performance communication and computing resources (such as mobile edge computing (MEC), clouds, and the like) over the network.
- MEC mobile edge computing
- 6G communication systems in hyper-connectivity, including person to machine (P2M) as well as machine to machine (M2M), will allow the next hyper-connected experience.
- services such as truly immersive extended reality (XR), high-fidelity mobile hologram, and digital replica could be provided through 6G communication systems.
- services such as remote surgery for security and reliability enhancement, industrial automation, and emergency response will be provided through the 6G communication system such that the technologies could be applied in various fields such as industry, medical care, automobiles, and home appliances.
- 5G Fifth Generation
- 5G Fifth Generation
- AKA Authentication and Key Agreement
- FIG. 1 is a schematic diagram 100 depicting an Authentication and Key Agreement (AKA) in 5G, in accordance with the existing art.
- AKA Authentication and Key Agreement
- the representation of authentication and key agreement consists of a user authentication function in the Universal Subscriber Identity Module (USIM) and a construction of Authentication String (AUTS) parameters at a user equipment (UE).
- USIM Universal Subscriber Identity Module
- AUTS Authentication String
- UE user equipment
- a static subscriber long term key K is provisioned to the UE during the SIM provisioning and the random number (RAND) is shared with the UE by the network during the AKA procedure. Further, all the authentication vectors are generated at the UE using K and RAND values.
- AKA provides user identity protection using public-key cryptography, i.e., Elliptical curve based integrated encryption scheme (ECIES).
- ECIES Elliptical curve based integrated encryption scheme
- FIG. 2 firstly elliptical curve based ephemeral key generation happens at a user equipment (UE) and home network (HN).
- HN public key is configured at SIM provisioning.
- Ephemeral UE private key and HN public key are used to generate ephemeral shared key at UE.
- 3rd Generation Partnership Project (3GPP) standards do not mention any specific authentication and key agreement methodology for 5G, beyond 5G, and/or sixth generation (6G) wireless communication system to protect against threats posed by quantum machines.
- 3GPP 3rd Generation Partnership Project
- 6G sixth generation
- ECIES ECIES
- an attacker i.e., an eavesdropper
- an attacker may use quantum machine to launch resource intensive attack could recover a static subscriber long-term key.
- FIG. 3 is a schematic diagram 300 depicting an exemplary representation of the key hierarchy in the 5G wireless communication system and the generation of the authentication vectors at the network, in accordance with the existing art.
- K is the long-term subscriber key or Universal Subscriber Identity Module (USIM) individual key, which is provided to the UE during Subscriber Identity Module (SIM)/Universal Integrated Circuit Card (UICC) provisioning. All keys for access security and core network security entities derive from this long-term subscriber key 'K'.
- a random number (RAND) is generated for providing different authentication vectors for every session between the UE and the network.
- the authentication vectors include a cipher key, integrity key, anonymity key, expected response (XRES), and a Message Authentication Code (MAC).
- MAC Message Authentication Code
- the attacker is enabled to launch fake base stations to communicate with UE compromising user location, privacy and all communication between UE and HN.
- the attacker would need to use resource intensive attack to recover the static subscriber long-term key. Thereafter, the attacker would be required to know parameters related to the home network or the serving network, to model a key derivation algorithm and the inputs to the KDF in the key hierarchy.
- the attacker may leverage quantum machines to recover the key hierarchy. Further, with the leverage of quantum machines and complete hierarchy, the attacker would be able to decrypt all traffic belonging to that subscriber which was not encrypted at the application layer. Moreover, recovery of the subscriber long-term key would also allow the attacker to pose as the subscriber to the network.
- quantum machines are widely used which is a threat to current wireless security systems.
- the quantum machines make use of quantum-mechanical effects which allows quantum bits (qubits) to exist in a combination of several states at once, and entanglement, which further allows connections between separate quantum systems such that they cannot be described independently.
- quantum algorithms that use the quantum-mechanical effects to solve certain cryptographic problems more efficiently than they may be solved on a classical computer.
- Shor's quantum algorithm for integer factorization runs in polynomial time on a quantum computer.
- a variant of Shor's algorithm enables a quantum computer to calculate discrete logarithms in polynomial time, both over finite fields and elliptic curves.
- the variant of Shor's algorithm renders several other public-key cryptosystems insecure, including Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH).
- DH Diffie-Hellman
- ECDH Elliptic Curve Diffie-Hellman
- FIG. 4 is a schematic diagram 400 depicting AKA procedure between the network and the UE, in accordance with the existing art.
- SEAF Security Anchor Function
- AUSF Authentication Server Function
- UDM Unified Data Management
- the RAND is generated at step 1, and is shared unencrypted with the UE in the authentication request message at step 6.
- Recovery of the long term key may also make the attacker to derive all the keys in the hierarchy using key derivation functions. Attacker can create a false base station and communicate with the UE. Thereafter, all privacy and sensitive information from the user, for example, location information, user identity, and others is compromised.
- the recovery of the long term key may also allow the attacker to pose as the subscriber to the network. Attackers may also perform spoofing, Denial of service (DoS), Distributed denial of service (DDoS), and replay attacks on the network.
- DoS Denial of service
- DDoS Distributed denial of service
- replay attacks on the network.
- the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement.
- the method comprises generating an ephemeral shared key and a corresponding encrypted ephemeral shared key using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity generated using PQC based key generation mechanism, generating a first subscriber key (K) using the ephemeral shared key based on a KDF mechanism, and transmitting the encrypted ephemeral shared key to the network entity, wherein the encrypted ephemeral shared key is used to generate a second subscriber key at the network entity, wherein the second subscriber key is same as the first subscriber key.
- PQC post quantum cryptography
- KEM key encapsulation mechanism
- the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement.
- the method comprises receiving the encrypted ephemeral shared key from the UE, wherein the encrypted ephemeral shared key is generated using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity generated using PQC based key generation mechanism, decrypting (1609) the received encrypted ephemeral shared key using the PQC-KEM and a private key of the network entity, generated using the PQC based key generation mechanism, to obtain the decrypted ephemeral shared key, and generating (1611) a second subscriber key (K) using the ephemeral shared key based on a KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
- PQC post quantum cryptography
- KEM key encapsulation mechanism
- the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement.
- the method comprises generating an ephemeral public key and an ephemeral private key using an elliptical curve (EC) based key generation mechanism, generating a first ephemeral key (s1) using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method, generating a second ephemeral shared key (s2) and a corresponding encrypted second ephemeral shared key using the post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and the public key of the network entity generated using PQC based key generation mechanism, combining the first ephemeral key (s1) and the second ephemeral shared key (s2) to generate a first hybrid ephemeral shared key, generating a first subscriber key (K) using the first hybrid
- the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement.
- the method comprises receiving the ephemeral public key and the encrypted second ephemeral shared key from the UE, wherein the ephemeral public key is generated using an elliptical curve (EC) based key generation mechanism, wherein the encrypted second ephemeral shared key is generated using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and the public key of the network entity generated using PQC based key generation mechanism; generating a first ephemeral key (s1) using the ephemeral public key received from UE and the ephemeral private key generated at the HN based on a predetermined key agreement method; decrypting the received encrypted second ephemeral shared key using the PQC-KEM and a private key of the network entity, generated using PQC based key generation mechanism, to obtain the decrypted second ep
- the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement.
- the method comprises generating an ephemeral public key and an ephemeral private key using an elliptical curve (EC) based key generation mechanism; generating an ephemeral shared key using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method; generating a first subscriber key (K) based on the ephemeral shared key using a predefined KDF mechanism; and transmitting the ephemeral public key generated at the UE to the network entity, wherein the ephemeral public key is used to generate a second subscriber key at the network entity, wherein the second subscriber key is same as the first subscriber key.
- EC elliptical curve
- the present disclosure refers to a method at a network entity, comprising a public key and a private key, in communication with a UE for authentication and key agreement.
- the method comprises receiving the ephemeral public key from the UE, wherein the ephemeral public key is generated using an elliptical curve (EC) based key generation mechanism, generating an ephemeral shared key using a private key of the network entity and the ephemeral public key of the UE using the predetermined key agreement method, and generating a second subscriber key (K) based on the ephemeral shared key using the predefined KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
- EC elliptical curve
- the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement.
- the method comprises generating an authentication parameter using a predetermined technique; encrypting the authentication parameter using a private key of the network entity based on a PQC based encryption technique; signing the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature to generate a digitally signed encrypted authentication parameter and transmitting the digitally signed encrypted authentication parameter to a user equipment (UE), wherein the digitally signed encrypted authentication parameter is verified and decrypted at the UE.
- PQC post quantum cryptography
- the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement.
- the method comprises obtaining the digitally signed encrypted authentication parameter, wherein the digitally signed encrypted authentication parameter is generated by encrypting authentication parameter using a private key of the network entity based on a PQC based encryption technique, wherein the digitally signed encrypted authentication parameter is further generated by signing the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature; and decrypting, upon verifying the digital signature, the encrypted authentication parameter using a public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique.
- PQC post quantum cryptography
- the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement.
- the method comprises generating an ephemeral shared key using a key generation mechanism; generating an ephemeral encryption key from an ephemeral shared key using a key derivation function; generating an authentication parameter using a predetermined technique; encrypting the authentication parameter using the ephemeral encryption key using a symmetric encryption technique; and transmitting the encrypted authentication parameter to a user equipment (UE), wherein the encrypted authentication parameter is decrypted at the UE.
- UE user equipment
- the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement.
- the method comprises obtaining the encrypted authentication parameter in an authentication request message, wherein the encrypted authentication parameter is generated at the network entity by encrypting an authentication parameter using an ephemeral encryption key using a symmetric encryption technique; generating an ephemeral decryption key corresponding to the ephemeral encryption key generated at the network entity using the key generation mechanism; and decrypting the authentication parameter using the ephemeral decryption key using a symmetric decryption technique corresponding to the symmetric encryption technique.
- the present disclosure refers to a user equipment (UE) and a network entity configured to perform the methods as described in the present disclosure.
- UE user equipment
- Embodiments of the present disclosure provides methods and apparatus for securely performing authentication and key agreement procedure to prevent various attacks on the network.
- FIG. 1 is a schematic diagram depicting an Authentication and Key Agreement (AKA) in 5G, in accordance with the existing art
- FIG. 2 illustrates an exemplary implementation Elliptical curve based integrated encryption scheme, in accordance with existing art
- FIG. 3 is a schematic diagram depicting an exemplary representation of the key hierarchy in the 5G wireless communication system and the generation of the authentication vectors at the network, in accordance with the existing art;
- FIG. 4 is a schematic diagram depicting AKA procedure between the network and the UE, in accordance with the existing art
- FIG. 5 is a schematic diagram depicting a sequence flow diagram of the Authentication and Key Agreement (AKA) procedure highlighting unprotected authentication request messages, in accordance with existing art;
- AKA Authentication and Key Agreement
- FIG. 6 is a block diagram depicting an exemplary system for performing authentication and key agreement (AKA), in accordance with one or more embodiments of the present disclosure
- FIG. 7 is a schematic diagram depicting a part of registration request from UE 601 to HN 603 using PQC-KEM, in accordance with one or more embodiments of the present disclosure
- FIG. 8 is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on PQC KEM based ephemeral shared key, in accordance with one or more embodiments of the present disclosure
- FIG. 9a is a schematic diagram depicting an exemplary implementation of the system for performing AKA based on hybrid ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure
- FIG. 9b is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on hybrid ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure
- FIG. 10a is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure
- FIG. 10b is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure
- FIG. 11a is a schematic diagram depicting an exemplary impact of using ephemeral shared key instead of static subscriber key on key generation at HN side, according to embodiments of the present disclosure
- FIG. 12a is a schematic diagram depicting encryption of authentication parameters using ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure
- FIG. 12b is a schematic diagram depicting decryption of authentication parameters using ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure
- FIG. 13 is a schematic diagram depicting an impact of using encrypted authentication parameters in AKA, in accordance with one or more embodiments of the present disclosure
- FIG. 14a is a schematic diagram depicting authentication parameters encryption at HN side, in accordance with one or more embodiments of the present disclosure
- FIG. 14b is a schematic diagram depicting authentication parameters encryption at UE side, in accordance with one or more embodiments of the present disclosure
- FIG. 15 is a schematic diagram depicting an impact of using authentication parameters encryption in AKA, in accordance with one or more embodiments of the present disclosure
- FIGS. 16a-16b are flow diagrams depicting a method for performing AKA, according to an embodiment of the present disclosure.
- FIGS. 17a-17b are flow diagrams depicting another method for performing AKA, according to an embodiment of the present disclosure.
- FIGS. 18a-18b are flow diagrams depicting another method for performing AKA, according to an embodiment of the present disclosure.
- FIGS. 19a-19b are flow diagrams depicting another method for performing AKA, according to an embodiment of the present disclosure.
- the embodiments disclosed herein describe the methods and systems for performing authentication and key agreement.
- Embodiments disclosed herein relate to techniques for securing the authentication and key agreement (AKA) procedure from quantum machines in both the 5G and the 6G wireless communication systems.
- Embodiments herein define a mechanism for preserving forward secrecy in generating key hierarchy in both the 5G and the 6G wireless communication systems.
- Embodiments herein further define a mechanism for utilizing shared key generated from crypto algorithms to replace the long term key.
- Embodiments disclosed herein further define a mechanism for utilizing shared key generated from crypto algorithms to secure random numbers generated during the AKA procedure.
- the crypto algorithm as disclosed herein refers to either legacy crypto algorithms, post quantum cryptography algorithms, or any hybrid algorithm.
- the post quantum cryptography algorithms are preferred over other crypto algorithms.
- the post quantum cryptography algorithms are safe against quantum attacks and offer fast key generation mechanism.
- FIG. 6 is a block diagram depicting an exemplary system 600 for performing authentication and key agreement (AKA), in accordance with one or more embodiments of the present disclosure.
- the system 600 comprises a user equipment (UE) 601, and a network entity 603 communicatively coupled with each other over a network 611.
- the network entity 603 may be associated with a home network (HN).
- the network entity 603 includes a processor 605, a memory 607, and a communication unit 609.
- the processor 605 may be a single processing unit or a number of units, all of which could include multiple computing units.
- the processor 605 may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logical processors, virtual processors, state machines, logic circuitries, and/or any devices that manipulate signals based on operational instructions.
- the processor 605 is configured to fetch and execute computer-readable instructions and data stored in memory 607.
- the memory 607 may include any non-transitory computer-readable medium known in the art including, for example, volatile memory or Random Access Memory (RAM), such as static random access memory (SRAM) and dynamic random access memory (DRAM), and/or non-volatile memory, such as read-only memory (ROM), erasable programmable ROM, flash memories, hard disks, optical disks, and magnetic tapes.
- RAM Random Access Memory
- SRAM static random access memory
- DRAM dynamic random access memory
- non-volatile memory such as read-only memory (ROM), erasable programmable ROM, flash memories, hard disks, optical disks, and magnetic tapes.
- processing unit 613 the memory unit 615, and the network interface 617 are analogous to the functions of the processor 605, the memory 607, and the communication unit 609, and are not described here again for the sake of brevity.
- each of the UE 601 and the network entity 603 may be configured to perform AKA in one or more possible manners as described in greater detail in the foregoing paragraphs.
- the system 600 may utilize post quantum cryptography (PQC) key encapsulation mechanism (KEM) based shared key generation instead of conventional ECIES.
- PQC post quantum cryptography
- KEM key encapsulation mechanism
- FIG. 7 is a schematic diagram 700 depicting a part of registration request from UE 601 to HN 603 using PQC-KEM, in accordance with one or more embodiments of the present disclosure.
- PQC based key generation happens at HN.
- PQC HN public key may be configured at SIM provisioning.
- a random number may be used, and ephemeral shared key may be generated using PQC KEM.
- the ephemeral shared key may be encrypted using PQC HN Public key to generate encrypted shared key and sent to HN in registration request.
- the network entity HN may receive the encrypted shared key and decrypt the received encrypted shared key using PQC HN private key to derive the same ephemeral shared key as UE.
- system may be configured to perform AKA based on PQC KEM based ephemeral shared key, as depicted in FIG. 8.
- the network entity 603 may be configured to receive the encrypted ephemeral shared key from the UE 601 and decrypt the received encrypted ephemeral shared key using the PQC-KEM and a private key of the network entity 603, generated using PQC based key generation mechanism, to obtain the decrypted ephemeral shared key.
- the public key, and the private key of the network entity 603 may generated using PQC based key generation mechanism.
- the network entity 603 may be configured to generate a second subscriber key (K) using the ephemeral shared key based on the predefined KDF mechanism such that the second subscriber key is same as the first subscriber key.
- the subscriber key in the network entity may be derived from the PQC based ephemeral key created from PQC KEM and using private key of HN.
- the subscriber key may be an ephemeral key generated for each user session.
- the subscriber key in the UE may be derived from the PQC based ephemeral key created from PQC KEM and using public key of HN.
- the subscriber key may be the ephemeral key generated for each user session.
- system may be configured to perform AKA based on hybrid ephemeral shared key, as depicted in FIG. 9a and 9b.
- FIG. 9a is a schematic diagram 900 depicting an exemplary implementation of the system 600 for performing AKA based on hybrid ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure.
- the hybrid ephemeral key may be obtained using a combination of elliptical curve (EC) based key generation mechanism, and PQC KEM.
- EC elliptical curve
- the UE 601 may be configured to generate a second ephemeral shared key (s2) and a corresponding encrypted second ephemeral shared key using the PQC KEM, and the public key of the network entity generated using PQC based key generation mechanism. Furthermore, the UE 601 may be configured to combine the first ephemeral key (s1) and the second ephemeral shared key (s2) to generate a first hybrid ephemeral shared key and generate a first subscriber key (K) using the first hybrid ephemeral shared key based on a predefined KDF mechanism. Moreover, the UE 601 may be configured to transmit the ephemeral public key and the encrypted second ephemeral shared key to the network entity.
- s2 second ephemeral shared key
- K subscriber key
- FIG. 9b is a schematic diagram 900 depicting an exemplary implementation of the system 600 for performing AKA based on hybrid ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure.
- the network entity 603 may be configured to receive the ephemeral public key and the encrypted second ephemeral shared key from the UE 601 and generate the first ephemeral key (s1) using the ephemeral public key received from UE and the ephemeral private key generated at the HN based on a predetermined key agreement method.
- the network entity 603 may be configured to decrypt the received encrypted second ephemeral shared key using the PQC-KEM and a private key of the network entity, generated using PQC based key generation mechanism, to obtain the decrypted second ephemeral shared key (s2).
- the private key of the network entity 603 may be generated using PQC based key generation mechanism.
- the subscriber key in the network entity may be derived from the hybrid shared key based on elliptical shared key and post quantum shared key using private key of HN.
- the subscriber key may be an ephemeral key generated for each user session.
- the subscriber key in the UE may be derived from the Hybrid shared key based on elliptical shared key and post quantum shared key using public key of HN.
- the subscriber key may be the ephemeral key generated for each user session.
- system may be configured to perform AKA based on EC based ephemeral shared key, as depicted in FIGS. 10a and 10b.
- FIG. 10a is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure.
- the UE may be configured to generate an ephemeral public key and an ephemeral private key using the EC based key generation mechanism.
- the UE 601 may be configured to generate an ephemeral shared key using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method.
- the UE 601 may be configured to generate a first subscriber key (K) based on the ephemeral shared key using a predefined KDF mechanism, and transmit the ephemeral public key generated at the UE to the network entity.
- K subscriber key
- FIG. 10b is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure.
- the network entity may be configured to receive the ephemeral public key from the UE, and generate an ephemeral shared key using a private key of the network entity and the ephemeral public key of the UE using the predetermined key agreement method. Further, the network entity may be configured to generate a second subscriber key (K) based on the ephemeral shared key using the predefined KDF mechanism, such that the second subscriber key is same as the first subscriber key.
- K subscriber key
- the subscriber key in the network entity may be derived from the elliptical shared key created from elliptical cryptography algorithms and using private key of HN.
- the subscriber key may be an ephemeral key generated for each user session.
- the subscriber key in the UE may be derived from the elliptical shared key created from elliptical cryptography algorithms and using public key of HN.
- the subscriber key may be the ephemeral key generated for each user session.
- FIG. 11a is a schematic diagram depicting an exemplary impact of using ephemeral shared key instead of static subscriber key on key generation at HN side, according to embodiments of the present disclosure.
- FIG. 11b is a schematic diagram depicting an exemplary impact of using ephemeral shared key instead of static subscriber key on key generation at UE side, according to embodiments of the present disclosure.
- the static subscriber key has been replaced with ephemeral key generated for each new session. Therefore, since the long-term subscriber key is generated for each new session, the need for generation of RAND value is eliminated. Therefore, no RAND value is shared from the network entity to the UE during AKA.
- the system 600 may be configured to use authentication parameters for performing AKA, as described below in conjunction with FIGS. 12a - 14.
- FIG. 12a is a schematic diagram depicting encryption of authentication parameters using ephemeral shared key at the HN side, in accordance with one or more embodiments of the present disclosure.
- FIG. 12b is a schematic diagram depicting decryption of authentication parameters using ephemeral shared key at the UE side, in accordance with one or more embodiments of the present disclosure.
- the network entity 603 may be configured to generate an ephemeral shared key using a predetermined key generation mechanism and generate an ephemeral encryption key from the ephemeral shared key using a predefined key derivation function. Further, the network entity 603 may be configured to generate an authentication parameter using a predetermined technique. Furthermore, the network entity may be configured to combine the encrypted authentication parameter with a MAC-tag value and transmit the encrypted authentication parameter, combined with a MAC-tag value, to the UE.
- the authentication parameter is a random number (RAND) and/or an authentication number (AUTN).
- the random number is generated using predetermined number generation technique or by a quantum random number generator (QRNG).
- the key generation mechanism comprises of at least one of the elliptical curve (EC) based key generation mechanism, and a post quantum cryptography (PQC) based key encapsulation mechanism (KEM).
- the public key and the private key of the network entity are generated using PQC based key generation mechanism.
- the UE may be configured to obtain the encrypted authentication parameter in an authentication request message, generate an ephemeral decryption key corresponding to the ephemeral encryption key generated at the network entity using the key generation mechanism, and decrypt the authentication parameter using the ephemeral decryption key using a symmetric decryption technique corresponding to the symmetric encryption technique.
- FIG. 13 is a schematic diagram 1300 depicting an impact of using encrypted authentication parameters in AKA, in accordance with one or more embodiments of the present disclosure.
- the UDM shall subsequently send this transformed authentication vector AV' (Encrypted RAND, Encrypted AUTN, Mac-tag value, XRES, CK', IK') to the AUSF from which it received the Nudm_UEAuthentication_Get Request together with an indication that the AV' is to be used for EAP-AKA' using a Nudm_UEAuthentication_Get Response message.
- the SEAF shall transparently forward the EAP-Request/AKA'-Challenge message to the UE in a NAS message Authentication Request message.
- the ME shall forward the RAND and AUTN received in EAP-Request/AKA'-Challenge message to the USIM. Mac-tag value is verified upon reception of encrypted RAND and/or AUTN by the UE. USIM/ME will decrypt the RAND and/or AUTN value upon reception from network using PQC/Hybrid/EC based key encapsulation algorithm.
- synchronisation failure indication by UE to network is trigged by UE to network if decryption of RAND and/or AUTN is failed, or verification failure of MAC-tag value occurs.
- system 600 may be configured to encrypt the authentication parameters using PQC based encryption and then digitally signing the encrypted the authentication parameters using PQC based digitally signature.
- FIG. 14a is a schematic diagram depicting authentication parameters encryption at HN side, in accordance with one or more embodiments of the present disclosure.
- the network entity may be configured to generate an authentication parameter using a predetermined technique and encrypt the authentication parameter using a private key of the network entity based on PQC based encryption technique.
- the authentication parameter is a random number (RAND) and/or an authentication number (AUTN).
- the public key and the private key of the network entity are generated using PQC key generation mechanism.
- the network entity may be configured to sign the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature to generate a digitally signed encrypted authentication parameter and transmit the digitally signed encrypted authentication parameter to the UE.
- PQC post quantum cryptography
- FIG. 14b is a schematic diagram depicting authentication parameters encryption at UE side, in accordance with one or more embodiments of the present disclosure.
- the UE may be configured to obtain the digitally signed encrypted authentication parameter, and decrypt, upon verifying the digital signature, the encrypted authentication parameter using a public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique.
- FIG. 15 is a schematic diagram 1500 depicting an impact of using authentication parameters encryption in AKA, in accordance with one or more embodiments of the present disclosure.
- the SEAF shall transparently forward the EAP-Request/AKA'-Challenge message to the UE 601 in a NAS message Authentication Request message.
- the ME shall forward the RAND and AUTN received in EAP-Request/AKA'-Challenge message to the USIM.
- Signature value is verified upon reception of encrypted RAND and/or AUTN by the UE.
- USIM/ME will decrypt the RAND and/or AUTN value upon reception from network using PQC/Hybrid/EC based decryption algorithm.
- synchronisation failure indication by UE to network is trigged by UE to network if decryption of RAND and/or AUTN is failed, or verification failure of digital signature has occurred.
- FIGS. 16a-16b illustrate flow diagrams depicting a method 1600 for performing AKA, according to an embodiment of the present disclosure.
- the method 1600 includes a series of operations 1601-1605 at the UE and 1607-1611 at the network entity.
- the processing unit 613 generates an ephemeral shared key and a corresponding encrypted ephemeral shared key using the post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity generated using PQC based key generation mechanism.
- PQC post quantum cryptography
- KEM key encapsulation mechanism
- the processing unit 613 generates a first subscriber key (K) using the ephemeral shared key based on a KDF mechanism.
- the processing unit 613 transmits the encrypted ephemeral shared key to the network entity.
- the processor 605 receives the encrypted ephemeral shared key from the UE.
- the processor 605 decrypts the received encrypted ephemeral shared key using the PQC-KEM and the private key of the network entity, generated using PQC based key generation mechanism, to obtain the decrypted ephemeral shared key.
- the processor 605 generates a second subscriber key (K) using the ephemeral shared key based on a KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
- FIGS. 17a-17b illustrate flow diagrams depicting another method 1700 for performing AKA, according to an embodiment of the present disclosure.
- the method 1700 includes a series of operations 1701-1711 at the UE and 1713-1721 at the network entity.
- the processing unit 613 generates an ephemeral public key and an ephemeral private key using an elliptical curve (EC) based key generation mechanism.
- EC elliptical curve
- the processing unit 613 generates a first ephemeral key (s1) using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method.
- the processing unit 613 combines the first ephemeral key (s1) and the second ephemeral shared key (s2) to generate a first hybrid ephemeral shared key.
- the processing unit 613 generates a first subscriber key (K) using the first hybrid ephemeral shared key based on a KDF mechanism.
- the processing unit 613 transmits the ephemeral public key and the encrypted second ephemeral shared key to the network entity.
- the processor 605 receives the ephemeral public key and the encrypted second ephemeral shared key from the UE.
- the processor 605 generates the first ephemeral key (s1) using the ephemeral public key received from UE and the ephemeral private key generated at the HN based on a predetermined key agreement method.
- the processor 605 combines the generated first ephemeral key (s1) and the decrypted second ephemeral shared key (s2) to generate a second hybrid ephemeral shared key, wherein the second hybrid ephemeral shared key is same as the first hybrid ephemeral shared key.
- the processor 605 generates a second subscriber key (K) using the second hybrid ephemeral shared key based on the KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
- FIGS. 18a-18b illustrate flow diagrams depicting another method 1800 for performing AKA, according to an embodiment of the present disclosure.
- the method 1800 includes a series of operations 1801-1807 at the UE and 1809-1813 at the network entity.
- the processing unit 613 generates an ephemeral shared key using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method.
- the processing unit 613 generates a first subscriber key (K) based on the ephemeral shared key using a predefined KDF mechanism.
- the processing unit 613 transmits the ephemeral public key generated at the UE to the network entity.
- the processor 605 receives the ephemeral public key from the UE.
- the processor 605 generates an ephemeral shared key using a private key of the network entity and the ephemeral public key of the UE using the predetermined key agreement method.
- FIGS. 19a-19b illustrate flow diagrams depicting another method 1900 for performing AKA, according to an embodiment of the present disclosure.
- the method 1900 includes a series of operations 1901-1909 at the network entity and 1911-1915 at the UE.
- the processing unit 605 generates an ephemeral shared key using a key generation mechanism.
- the processing unit 605 encrypts the authentication parameter using the ephemeral encryption key using a symmetric encryption technique.
- the processing unit 605 transmits the encrypted authentication parameter to UE.
- the processor 613 obtains the encrypted authentication parameter in an authentication request message.
- the processor 613 generates an ephemeral decryption key corresponding to the ephemeral encryption key generated at the network entity using the key generation mechanism.
- the processor 613 decrypts the authentication parameter using the ephemeral decryption key using a symmetric decryption technique corresponding to the symmetric encryption technique.
- FIGS. 20a-20b illustrate flow diagrams depicting another method 2000 for performing AKA, according to an embodiment of the present disclosure.
- the method 2000 includes a series of operations 2001-2007 at the network entity and 2009-2011 at the UE.
- the processor 605 generates an authentication parameter using a predetermined technique.
- the processor 605 encrypts the authentication parameter using a private key of the network entity based on PQC based encryption technique.
- the processor 605 signs the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature to generate a digitally signed encrypted authentication parameter.
- PQC post quantum cryptography
- the processor 605 transmits the digitally signed encrypted authentication parameter to UE.
- the processing unit 613 obtains the digitally signed encrypted authentication parameter.
- the processing unit 613 decrypts, upon verifying the digital signature, the encrypted authentication parameter using a public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique.
- the system and method disclosed in the present disclosure provides post quantum-safe authentication and key agreement method between subscriber and network entity.
- system and method disclosed in the present disclosure helps to prevent recovery of the subscriber's long-term key, which in turn would also avoid the attacker to pose as the subscriber to the network.
- system and method disclosed in the present disclosure prevents attacker from being able to decrypt all traffic belonging to that subscriber which is not encrypted at the application layer. Hence, subscriber location, privacy and all communication between user equipment and a network entity is not compromised.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
The present disclosure relates to a 5G communication system or a 6G communication system for supporting higher data rates beyond a 4G communication system such as long term evolution (LTE). Disclosed is a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement. The method comprises generating (1601) an ephemeral shared key and a corresponding encrypted ephemeral shared key using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity generated using PQC based key generation mechanism. Further, the method comprises generating (1603) a first subscriber key (K) using the ephemeral shared key based on a KDF mechanism. Further, the method comprises transmitting (1605) the encrypted ephemeral shared key to the network entity, wherein the encrypted ephemeral shared key is used to generate a second subscriber key at the network entity, wherein the second subscriber key is same as the first subscriber key.
Description
The present disclosure relates to the field of wireless communication networks, and more particularly relates to methods and systems performing authentication and key agreement (AKA) in wireless communication networks.
Considering the development of wireless communication from generation to generation, the technologies have been developed mainly for services targeting humans, such as voice calls, multimedia services, and data services. Following the commercialization of 5G (5th-generation) communication systems, it is expected that the number of connected devices will exponentially grow. Increasingly, these will be connected to communication networks. Examples of connected things may include vehicles, robots, drones, home appliances, displays, smart sensors connected to various infrastructures, construction machines, and factory equipment. Mobile devices are expected to evolve in various form-factors, such as augmented reality glasses, virtual reality headsets, and hologram devices. In order to provide various services by connecting hundreds of billions of devices and things in the 6G (6th-generation) era, there have been ongoing efforts to develop improved 6G communication systems. For these reasons, 6G communication systems are referred to as beyond-5G systems.
6G communication systems, which are expected to be commercialized around 2030, will have a peak data rate of tera (1,000 giga)-level bps and a radio latency less than 100μsec, and thus will be 50 times as fast as 5G communication systems and have the 1/10 radio latency thereof.
In order to accomplish such a high data rate and an ultra-low latency, it has been considered to implement 6G communication systems in a terahertz band (for example, 95GHz to 3THz bands). It is expected that, due to severer path loss and atmospheric absorption in the terahertz bands than those in mmWave bands introduced in 5G, technologies capable of securing the signal transmission distance (that is, coverage) will become more crucial. It is necessary to develop, as major technologies for securing the coverage, radio frequency (RF) elements, antennas, novel waveforms having a better coverage than orthogonal frequency division multiplexing (OFDM), beamforming and massive multiple input multiple output (MIMO), full dimensional MIMO (FD-MIMO), array antennas, and multiantenna transmission technologies such as large-scale antennas. In addition, there has been ongoing discussion on new technologies for improving the coverage of terahertz-band signals, such as metamaterial-based lenses and antennas, orbital angular momentum (OAM), and reconfigurable intelligent surface (RIS).
Moreover, in order to improve the spectral efficiency and the overall network performances, the following technologies have been developed for 6G communication systems: a full-duplex technology for enabling an uplink transmission and a downlink transmission to simultaneously use the same frequency resource at the same time; a network technology for utilizing satellites, high-altitude platform stations (HAPS), and the like in an integrated manner; an improved network structure for supporting mobile base stations and the like and enabling network operation optimization and automation and the like; a dynamic spectrum sharing technology via collison avoidance based on a prediction of spectrum usage; an use of artificial intelligence (AI) in wireless communication for improvement of overall network operation by utilizing AI from a designing phase for developing 6G and internalizing end-to-end AI support functions; and a next-generation distributed computing technology for overcoming the limit of UE computing ability through reachable super-high-performance communication and computing resources (such as mobile edge computing (MEC), clouds, and the like) over the network. In addition, through designing new protocols to be used in 6G communication systems, developing mecahnisms for implementing a hardware-based security environment and safe use of data, and developing technologies for maintaining privacy, attempts to strengthen the connectivity between devices, optimize the network, promote softwarization of network entities, and increase the openness of wireless communications are continuing.
It is expected that research and development of 6G communication systems in hyper-connectivity, including person to machine (P2M) as well as machine to machine (M2M), will allow the next hyper-connected experience. Particularly, it is expected that services such as truly immersive extended reality (XR), high-fidelity mobile hologram, and digital replica could be provided through 6G communication systems. In addition, services such as remote surgery for security and reliability enhancement, industrial automation, and emergency response will be provided through the 6G communication system such that the technologies could be applied in various fields such as industry, medical care, automobiles, and home appliances.
In recent years, Fifth Generation (5G) wireless communication system has been developed to provide high-speed data services The development of 5G has revolutionized several industries, such as autonomous vehicles, healthcare, and manufacturing by enabling ultra-reliability and ultra-low-latency applications. However, the development of 5G implicates potential security vulnerabilities that threaten mobile user privacy. Said potential security vulnerabilities include lack of full protection against compromised/impersonated home networks or serving networks (SNs). A major component of the specification associated with the standardization of 5G describes Authentication and Key Agreement (AKA) protocol in 5G, as depicted in FIG. 1.
FIG. 1 is a schematic diagram 100 depicting an Authentication and Key Agreement (AKA) in 5G, in accordance with the existing art. As shown in the figure, the representation of authentication and key agreement consists of a user authentication function in the Universal Subscriber Identity Module (USIM) and a construction of Authentication String (AUTS) parameters at a user equipment (UE). A static subscriber long term key K is provisioned to the UE during the SIM provisioning and the random number (RAND) is shared with the UE by the network during the AKA procedure. Further, all the authentication vectors are generated at the UE using K and RAND values.
In 5G AKA provides user identity protection using public-key cryptography, i.e., Elliptical curve based integrated encryption scheme (ECIES). In an implementation of ECIES as depicted in FIG. 2, firstly elliptical curve based ephemeral key generation happens at a user equipment (UE) and home network (HN). HN public key is configured at SIM provisioning. Ephemeral UE private key and HN public key are used to generate ephemeral shared key at UE.
However, 3rd Generation Partnership Project (3GPP) standards do not mention any specific authentication and key agreement methodology for 5G, beyond 5G, and/or sixth generation (6G) wireless communication system to protect against threats posed by quantum machines. With the rise in research and development of quantum machines, currently used cryptography techniques such as ECIES may not remain efficient. In a scenario an attacker (i.e., an eavesdropper) may use quantum machine to launch resource intensive attack could recover a static subscriber long-term key.
Recovery of the static subscriber long-term key would allow the attacker to pose as the subscriber to the home network or the serving network. The attacker can combine the recovered static subscriber long-term key with random number (RAND) and use key derivation functions (KDF) to generate Ciphering Key (CK), Integrity Key (IK). Consequently, complete key hierarchy gets compromised, since all the authentication vectors are generated from the subscriber long-term key as depicted in FIG. 3.
FIG. 3 is a schematic diagram 300 depicting an exemplary representation of the key hierarchy in the 5G wireless communication system and the generation of the authentication vectors at the network, in accordance with the existing art. As shown in the figure, K is the long-term subscriber key or Universal Subscriber Identity Module (USIM) individual key, which is provided to the UE during Subscriber Identity Module (SIM)/Universal Integrated Circuit Card (UICC) provisioning. All keys for access security and core network security entities derive from this long-term subscriber key 'K'. A random number (RAND) is generated for providing different authentication vectors for every session between the UE and the network. The authentication vectors include a cipher key, integrity key, anonymity key, expected response (XRES), and a Message Authentication Code (MAC).
Thus, the attacker is enabled to launch fake base stations to communicate with UE compromising user location, privacy and all communication between UE and HN. The attacker would need to use resource intensive attack to recover the static subscriber long-term key. Thereafter, the attacker would be required to know parameters related to the home network or the serving network, to model a key derivation algorithm and the inputs to the KDF in the key hierarchy. The attacker may leverage quantum machines to recover the key hierarchy. Further, with the leverage of quantum machines and complete hierarchy, the attacker would be able to decrypt all traffic belonging to that subscriber which was not encrypted at the application layer. Moreover, recovery of the subscriber long-term key would also allow the attacker to pose as the subscriber to the network.
Further, in the 6G wireless communication systems, quantum machines are widely used which is a threat to current wireless security systems. The quantum machines make use of quantum-mechanical effects which allows quantum bits (qubits) to exist in a combination of several states at once, and entanglement, which further allows connections between separate quantum systems such that they cannot be described independently. There exist quantum algorithms that use the quantum-mechanical effects to solve certain cryptographic problems more efficiently than they may be solved on a classical computer. Shor's quantum algorithm for integer factorization runs in polynomial time on a quantum computer. A variant of Shor's algorithm enables a quantum computer to calculate discrete logarithms in polynomial time, both over finite fields and elliptic curves. The variant of Shor's algorithm renders several other public-key cryptosystems insecure, including Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH).
Further, the generated RAND is shared in an unencrypted form over the air in authentication request message from network to UE, as shown in FIG. 4. FIG. 4 is a schematic diagram 400 depicting AKA procedure between the network and the UE, in accordance with the existing art. As shown in the figure, Security Anchor Function (SEAF), Authentication Server Function (AUSF), and Unified Data Management (UDM) are network functions that are involved in the AKA procedure. Further, as depicted in the figure, the RAND is generated at step 1, and is shared unencrypted with the UE in the authentication request message at step 6.
Furthermore, FIG. 5 is a schematic diagram 500 depicting a sequence flow diagram of the Authentication and Key Agreement (AKA) procedure highlighting unprotected authentication request messages, in accordance with existing art. During the AKA procedure at present, authentication parameters like RAND, AUTN (Authentication Token), and like are shared with the UE via the authentication request message. This authentication request message is shared via an unsecured channel to the UE as Non-Access Stratum (NAS) and Access Stratum (AS) security context is not yet established between the UE and the network. The attacker may easily read the authentication parameters and use them in quantum circuit modelling as per 3GPP 33.841 and try to decode the USIM individual key or the long term key to generate authenticate vectors.
Recovery of the long term key may also make the attacker to derive all the keys in the hierarchy using key derivation functions. Attacker can create a false base station and communicate with the UE. Thereafter, all privacy and sensitive information from the user, for example, location information, user identity, and others is compromised.
The recovery of the long term key may also allow the attacker to pose as the subscriber to the network. Attackers may also perform spoofing, Denial of service (DoS), Distributed denial of service (DDoS), and replay attacks on the network.
Therefore, there lies a need to address the above-described limitations and provide a methodology to counter the threats of quantum computing to asymmetric cryptography to secure the AKA procedures.
The purpose of this application is to be able to solve at least one of the drawbacks of the prior art. There is a need to provide a methodology to counter the threats of quantum computing to asymmetric cryptography to secure the authentication and key agreement (AKA) procedures.
In an embodiment, the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement. The method comprises generating an ephemeral shared key and a corresponding encrypted ephemeral shared key using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity generated using PQC based key generation mechanism, generating a first subscriber key (K) using the ephemeral shared key based on a KDF mechanism, and transmitting the encrypted ephemeral shared key to the network entity, wherein the encrypted ephemeral shared key is used to generate a second subscriber key at the network entity, wherein the second subscriber key is same as the first subscriber key.
In an embodiment, the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement. The method comprises receiving the encrypted ephemeral shared key from the UE, wherein the encrypted ephemeral shared key is generated using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity generated using PQC based key generation mechanism, decrypting (1609) the received encrypted ephemeral shared key using the PQC-KEM and a private key of the network entity, generated using the PQC based key generation mechanism, to obtain the decrypted ephemeral shared key, and generating (1611) a second subscriber key (K) using the ephemeral shared key based on a KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
In an embodiment, the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement. The method comprises generating an ephemeral public key and an ephemeral private key using an elliptical curve (EC) based key generation mechanism, generating a first ephemeral key (s1) using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method, generating a second ephemeral shared key (s2) and a corresponding encrypted second ephemeral shared key using the post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and the public key of the network entity generated using PQC based key generation mechanism, combining the first ephemeral key (s1) and the second ephemeral shared key (s2) to generate a first hybrid ephemeral shared key, generating a first subscriber key (K) using the first hybrid ephemeral shared key based on a KDF mechanism, and transmitting the ephemeral public key and the encrypted second ephemeral shared key to the network entity, wherein the ephemeral public key and the encrypted second ephemeral shared key are used to generate a second subscriber key at the network entity, wherein the second subscriber key is same as the first subscriber key.
In an embodiment, the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement. The method comprises receiving the ephemeral public key and the encrypted second ephemeral shared key from the UE, wherein the ephemeral public key is generated using an elliptical curve (EC) based key generation mechanism, wherein the encrypted second ephemeral shared key is generated using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and the public key of the network entity generated using PQC based key generation mechanism; generating a first ephemeral key (s1) using the ephemeral public key received from UE and the ephemeral private key generated at the HN based on a predetermined key agreement method; decrypting the received encrypted second ephemeral shared key using the PQC-KEM and a private key of the network entity, generated using PQC based key generation mechanism, to obtain the decrypted second ephemeral shared key (s2); combining the generated first ephemeral key (s1) and the decrypted second ephemeral shared key (s2) to generate a second hybrid ephemeral shared key, wherein the second hybrid ephemeral shared key is same as the first hybrid ephemeral shared key; and generating a second subscriber key (K) using the second hybrid ephemeral shared key based on the KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
In an embodiment, the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement. The method comprises generating an ephemeral public key and an ephemeral private key using an elliptical curve (EC) based key generation mechanism; generating an ephemeral shared key using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method; generating a first subscriber key (K) based on the ephemeral shared key using a predefined KDF mechanism; and transmitting the ephemeral public key generated at the UE to the network entity, wherein the ephemeral public key is used to generate a second subscriber key at the network entity, wherein the second subscriber key is same as the first subscriber key.
In an embodiment, the present disclosure refers to a method at a network entity, comprising a public key and a private key, in communication with a UE for authentication and key agreement. The method comprises receiving the ephemeral public key from the UE, wherein the ephemeral public key is generated using an elliptical curve (EC) based key generation mechanism, generating an ephemeral shared key using a private key of the network entity and the ephemeral public key of the UE using the predetermined key agreement method, and generating a second subscriber key (K) based on the ephemeral shared key using the predefined KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
In an embodiment, the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement. The method comprises generating an authentication parameter using a predetermined technique; encrypting the authentication parameter using a private key of the network entity based on a PQC based encryption technique; signing the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature to generate a digitally signed encrypted authentication parameter and transmitting the digitally signed encrypted authentication parameter to a user equipment (UE), wherein the digitally signed encrypted authentication parameter is verified and decrypted at the UE.
In an embodiment, the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement. The method comprises obtaining the digitally signed encrypted authentication parameter, wherein the digitally signed encrypted authentication parameter is generated by encrypting authentication parameter using a private key of the network entity based on a PQC based encryption technique, wherein the digitally signed encrypted authentication parameter is further generated by signing the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature; and decrypting, upon verifying the digital signature, the encrypted authentication parameter using a public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique.
In an embodiment, the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement. The method comprises generating an ephemeral shared key using a key generation mechanism; generating an ephemeral encryption key from an ephemeral shared key using a key derivation function; generating an authentication parameter using a predetermined technique; encrypting the authentication parameter using the ephemeral encryption key using a symmetric encryption technique; and transmitting the encrypted authentication parameter to a user equipment (UE), wherein the encrypted authentication parameter is decrypted at the UE.
In an embodiment, the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement. The method comprises obtaining the encrypted authentication parameter in an authentication request message, wherein the encrypted authentication parameter is generated at the network entity by encrypting an authentication parameter using an ephemeral encryption key using a symmetric encryption technique; generating an ephemeral decryption key corresponding to the ephemeral encryption key generated at the network entity using the key generation mechanism; and decrypting the authentication parameter using the ephemeral decryption key using a symmetric decryption technique corresponding to the symmetric encryption technique.
In an embodiment, the present disclosure refers to a user equipment (UE) and a network entity configured to perform the methods as described in the present disclosure.
Embodiments of the present disclosure provides methods and apparatus for securely performing authentication and key agreement procedure to prevent various attacks on the network.
These and other features, aspects, and advantages of the present disclosure will become better understood when the following detailed description is read with reference to the accompanying drawings in which like characters represent like parts throughout the drawings, wherein:
FIG. 1 is a schematic diagram depicting an Authentication and Key Agreement (AKA) in 5G, in accordance with the existing art;
FIG. 2 illustrates an exemplary implementation Elliptical curve based integrated encryption scheme, in accordance with existing art;
FIG. 3 is a schematic diagram depicting an exemplary representation of the key hierarchy in the 5G wireless communication system and the generation of the authentication vectors at the network, in accordance with the existing art;
FIG. 4 is a schematic diagram depicting AKA procedure between the network and the UE, in accordance with the existing art;
FIG. 5 is a schematic diagram depicting a sequence flow diagram of the Authentication and Key Agreement (AKA) procedure highlighting unprotected authentication request messages, in accordance with existing art;
FIG. 6 is a block diagram depicting an exemplary system for performing authentication and key agreement (AKA), in accordance with one or more embodiments of the present disclosure;
FIG. 7 is a schematic diagram depicting a part of registration request from UE 601 to HN 603 using PQC-KEM, in accordance with one or more embodiments of the present disclosure;
FIG. 8 is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on PQC KEM based ephemeral shared key, in accordance with one or more embodiments of the present disclosure;
FIG. 9a is a schematic diagram depicting an exemplary implementation of the system for performing AKA based on hybrid ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure;
FIG. 9b is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on hybrid ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure;
FIG. 10a is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure;
FIG. 10b is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure;
FIG. 11a is a schematic diagram depicting an exemplary impact of using ephemeral shared key instead of static subscriber key on key generation at HN side, according to embodiments of the present disclosure;
FIG. 11b is a schematic diagram depicting an exemplary impact of using ephemeral shared key instead of static subscriber key on key generation at UE side, according to embodiments of the present disclosure;
FIG. 12a is a schematic diagram depicting encryption of authentication parameters using ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure;
FIG. 12b is a schematic diagram depicting decryption of authentication parameters using ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure;
FIG. 13 is a schematic diagram depicting an impact of using encrypted authentication parameters in AKA, in accordance with one or more embodiments of the present disclosure;
FIG. 14a is a schematic diagram depicting authentication parameters encryption at HN side, in accordance with one or more embodiments of the present disclosure;
FIG. 14b is a schematic diagram depicting authentication parameters encryption at UE side, in accordance with one or more embodiments of the present disclosure;
FIG. 15 is a schematic diagram depicting an impact of using authentication parameters encryption in AKA, in accordance with one or more embodiments of the present disclosure;
FIGS. 16a-16b are flow diagrams depicting a method for performing AKA, according to an embodiment of the present disclosure;
FIGS. 17a-17b are flow diagrams depicting another method for performing AKA, according to an embodiment of the present disclosure;
FIGS. 18a-18b are flow diagrams depicting another method for performing AKA, according to an embodiment of the present disclosure;
FIGS. 19a-19b are flow diagrams depicting another method for performing AKA, according to an embodiment of the present disclosure; and
FIGS. 20a-20b are flow diagrams depicting another method for performing AKA, according to an embodiment of the present disclosure.
Further, skilled artisans will appreciate that those elements in the drawings are illustrated for simplicity and may not have necessarily been drawn to scale. For example, the flow charts illustrate the method in terms of the most prominent steps involved to help to improve understanding of aspects of the present invention. Furthermore, in terms of the construction of the device, one or more components of the device may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the embodiments of the present invention so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.
It will be understood by those skilled in the art that the foregoing general description and the following detailed description are explanatory of the disclosure and are not intended to be restrictive thereof.
Reference throughout this specification to "an aspect", "another aspect" or similar language means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, appearances of the phrase "in an embodiment", "in another embodiment", "in one embodiment", and similar language throughout this specification may but do not necessarily, all refer to the same embodiment.
The terms "comprises", "comprising", "includes", "comprise", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process or method that comprises a list of steps does not include only those steps but may include other steps not expressly listed or inherent to such process or method.
Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skilled in the art to which this disclosure belongs. The system, method, and examples provided herein are illustrative only and not intended to be limiting.
Embodiments of the present invention will be described below in detail with reference to the accompanying drawings.
The embodiments disclosed herein describe the methods and systems for performing authentication and key agreement.
Embodiments disclosed herein relate to techniques for securing the authentication and key agreement (AKA) procedure from quantum machines in both the 5G and the 6G wireless communication systems. Embodiments herein define a mechanism for preserving forward secrecy in generating key hierarchy in both the 5G and the 6G wireless communication systems. Embodiments herein further define a mechanism for utilizing shared key generated from crypto algorithms to replace the long term key. Embodiments disclosed herein further define a mechanism for utilizing shared key generated from crypto algorithms to secure random numbers generated during the AKA procedure. The crypto algorithm as disclosed herein refers to either legacy crypto algorithms, post quantum cryptography algorithms, or any hybrid algorithm. In an exemplary embodiment, the post quantum cryptography algorithms are preferred over other crypto algorithms. The post quantum cryptography algorithms are safe against quantum attacks and offer fast key generation mechanism.
The currently used authentication and key agreement procedures use the same long term key (K) for generating authentication vectors throughout multiple sessions for each subscriber. Technical specification (TS) 33.841 in 3GPP standard states that quantum circuit modelling can be performed by an attacker using quantum machines and can recover the subscriber's long term key. Recovery of the long term key also makes the attacker to derive all the keys in the hierarchy using key derivation functions. The attacker may create false base stations and communicate with the UE. Thereafter all privacy and sensitive information from the user for example, location information, user identity, or like gets compromised.
Moreover, the attacker may also pose as the subscriber to the network. The attacker can also perform spoofing, Denial of service (DoS), Distributed denial of service (DDoS), and replay attacks on the network. Preserving the forward secrecy with post quantum security in the 6G wireless communication system mitigates such kinds of attacks as keys keep on changing for each session.
Forward secrecy is a feature of a specific key agreement that gives assurance that shared keys will not be compromised even if a private key or long-term secrets used in the shared key exchange are compromised. Forward secrecy may be achieved by generating ephemeral public and private session keys for each session. Therefore, even if an attacker or adversary hacks any private key (for example, the most recent private key), only a minimal amount of sensitive data is exposed which is valid for only that particular session for which the key is hacked and keeping past communications secure.
FIG. 6 is a block diagram depicting an exemplary system 600 for performing authentication and key agreement (AKA), in accordance with one or more embodiments of the present disclosure. The system 600 comprises a user equipment (UE) 601, and a network entity 603 communicatively coupled with each other over a network 611. According to embodiments of the present disclosure, the network entity 603 may be associated with a home network (HN). The network entity 603 includes a processor 605, a memory 607, and a communication unit 609.
In an example, the processor 605 may be a single processing unit or a number of units, all of which could include multiple computing units. The processor 605 may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logical processors, virtual processors, state machines, logic circuitries, and/or any devices that manipulate signals based on operational instructions. Among other capabilities, the processor 605 is configured to fetch and execute computer-readable instructions and data stored in memory 607.
The memory 607 may include any non-transitory computer-readable medium known in the art including, for example, volatile memory or Random Access Memory (RAM), such as static random access memory (SRAM) and dynamic random access memory (DRAM), and/or non-volatile memory, such as read-only memory (ROM), erasable programmable ROM, flash memories, hard disks, optical disks, and magnetic tapes.
The communication unit 609 may be configured to provide network connectivity and enable communication with coupled devices such as the UE 601. The network connectivity may be provided via a wireless connection or a wired connection. For example, the network connectivity may be provided via cellular technology, such as, 5G, beyond 5G, or 6G.
The functions of the processing unit 613, the memory unit 615, and the network interface 617 are analogous to the functions of the processor 605, the memory 607, and the communication unit 609, and are not described here again for the sake of brevity.
Further, each of the UE 601 and the network entity 603 may be configured to perform AKA in one or more possible manners as described in greater detail in the foregoing paragraphs.
According to the embodiments of the present disclosure, the system 600 may utilize post quantum cryptography (PQC) key encapsulation mechanism (KEM) based shared key generation instead of conventional ECIES.
FIG. 7 is a schematic diagram 700 depicting a part of registration request from UE 601 to HN 603 using PQC-KEM, in accordance with one or more embodiments of the present disclosure. Firstly, PQC based key generation happens at HN. PQC HN public key may be configured at SIM provisioning. Further, a random number may be used, and ephemeral shared key may be generated using PQC KEM. Finally, the ephemeral shared key may be encrypted using PQC HN Public key to generate encrypted shared key and sent to HN in registration request. Thereafter, the network entity HN may receive the encrypted shared key and decrypt the received encrypted shared key using PQC HN private key to derive the same ephemeral shared key as UE.
In an implementation of the system may be configured to perform AKA based on PQC KEM based ephemeral shared key, as depicted in FIG. 8.
FIG. 8 is a schematic diagram 800 depicting an exemplary implementation of the system 600 for performing AKA based on PQC KEM based ephemeral shared key, in accordance with one or more embodiments of the present disclosure. As depicted in the figure, the UE 601 in communication with a network entity 603 may be configured to generate an ephemeral shared key and a corresponding encrypted ephemeral shared key using the post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity 603 generated using PQC based key generation mechanism. Further, the UE 601 may be configured to generate a first subscriber key (K) using the ephemeral shared key based on a predefined KDF mechanism and transmit the encrypted ephemeral shared key to the network entity 603.
Further, the network entity 603 may be configured to receive the encrypted ephemeral shared key from the UE 601 and decrypt the received encrypted ephemeral shared key using the PQC-KEM and a private key of the network entity 603, generated using PQC based key generation mechanism, to obtain the decrypted ephemeral shared key. According to the embodiments of the present disclosure, the public key, and the private key of the network entity 603 may generated using PQC based key generation mechanism. Finally, the network entity 603 may be configured to generate a second subscriber key (K) using the ephemeral shared key based on the predefined KDF mechanism such that the second subscriber key is same as the first subscriber key.
Consequent to the above-described mechanism for performing AKA, the subscriber key in the network entity may be derived from the PQC based ephemeral key created from PQC KEM and using private key of HN. According to the embodiments of the present disclosure, the subscriber key may be an ephemeral key generated for each user session. Further, the subscriber key in the UE may be derived from the PQC based ephemeral key created from PQC KEM and using public key of HN. According to the embodiments of the present disclosure, the subscriber key may be the ephemeral key generated for each user session. Since the PQC based ephemeral shared key are be generated for each session using public key of HN, the need to store a large number of long-term keys in the HN (for example, in Unified Data Management (UDM)) is eliminated, thereby reducing operational risks in the life cycle of key management.
In another implementation of the system may be configured to perform AKA based on hybrid ephemeral shared key, as depicted in FIG. 9a and 9b.
FIG. 9a is a schematic diagram 900 depicting an exemplary implementation of the system 600 for performing AKA based on hybrid ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure. According to embodiments of the present disclosure, the hybrid ephemeral key may be obtained using a combination of elliptical curve (EC) based key generation mechanism, and PQC KEM.
As depicted in the figure, the UE 601 in communication with a network entity 603 may be configured to generate an ephemeral public key and an ephemeral private key using an EC based key generation mechanism. Further, the UE 601 may be configured to generate a first ephemeral key (s1) using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method. In an embodiment, the public key of the network entity 603 may be generated using PQC based key generation mechanism.
Further, the UE 601 may be configured to generate a second ephemeral shared key (s2) and a corresponding encrypted second ephemeral shared key using the PQC KEM, and the public key of the network entity generated using PQC based key generation mechanism. Furthermore, the UE 601 may be configured to combine the first ephemeral key (s1) and the second ephemeral shared key (s2) to generate a first hybrid ephemeral shared key and generate a first subscriber key (K) using the first hybrid ephemeral shared key based on a predefined KDF mechanism. Moreover, the UE 601 may be configured to transmit the ephemeral public key and the encrypted second ephemeral shared key to the network entity.
FIG. 9b is a schematic diagram 900 depicting an exemplary implementation of the system 600 for performing AKA based on hybrid ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure. As depicted in the figure, the network entity 603 may be configured to receive the ephemeral public key and the encrypted second ephemeral shared key from the UE 601 and generate the first ephemeral key (s1) using the ephemeral public key received from UE and the ephemeral private key generated at the HN based on a predetermined key agreement method. Further, the network entity 603 may be configured to decrypt the received encrypted second ephemeral shared key using the PQC-KEM and a private key of the network entity, generated using PQC based key generation mechanism, to obtain the decrypted second ephemeral shared key (s2). In an embodiment, the private key of the network entity 603 may be generated using PQC based key generation mechanism.
Further, the network entity 603 may combine the generated first ephemeral key (s1) and the decrypted second ephemeral shared key (s2) to generate a second hybrid ephemeral shared key, wherein the second hybrid ephemeral shared key is same as the first hybrid ephemeral shared key. Upon generating the second hybrid ephemeral shared key, the network entity 60 may be configured to generate a second subscriber key (K) using the second hybrid ephemeral shared key based on the predefined KDF mechanism, such that the second subscriber key is same as the first subscriber key.
Consequent to the above-described mechanism for performing AKA, the subscriber key in the network entity may be derived from the hybrid shared key based on elliptical shared key and post quantum shared key using private key of HN. According to the embodiments of the present disclosure, the subscriber key may be an ephemeral key generated for each user session. Further, the subscriber key in the UE may be derived from the Hybrid shared key based on elliptical shared key and post quantum shared key using public key of HN. According to the embodiments of the present disclosure, the subscriber key may be the ephemeral key generated for each user session.
In yet another implementation of the system may be configured to perform AKA based on EC based ephemeral shared key, as depicted in FIGS. 10a and 10b.
FIG. 10a is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure. As depicted in the figure, the UE may be configured to generate an ephemeral public key and an ephemeral private key using the EC based key generation mechanism. Further, the UE 601 may be configured to generate an ephemeral shared key using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method. Furthermore, the UE 601 may be configured to generate a first subscriber key (K) based on the ephemeral shared key using a predefined KDF mechanism, and transmit the ephemeral public key generated at the UE to the network entity.
FIG. 10b is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure. As depicted in the figure, the network entity may be configured to receive the ephemeral public key from the UE, and generate an ephemeral shared key using a private key of the network entity and the ephemeral public key of the UE using the predetermined key agreement method. Further, the network entity may be configured to generate a second subscriber key (K) based on the ephemeral shared key using the predefined KDF mechanism, such that the second subscriber key is same as the first subscriber key.
Consequent to the above-described mechanism for performing AKA, the subscriber key in the network entity may be derived from the elliptical shared key created from elliptical cryptography algorithms and using private key of HN. According to the embodiments of the present disclosure, the subscriber key may be an ephemeral key generated for each user session. Further, the subscriber key in the UE may be derived from the elliptical shared key created from elliptical cryptography algorithms and using public key of HN. According to the embodiments of the present disclosure, the subscriber key may be the ephemeral key generated for each user session.
FIG. 11a is a schematic diagram depicting an exemplary impact of using ephemeral shared key instead of static subscriber key on key generation at HN side, according to embodiments of the present disclosure. FIG. 11b is a schematic diagram depicting an exemplary impact of using ephemeral shared key instead of static subscriber key on key generation at UE side, according to embodiments of the present disclosure. As depicted in the figure, the static subscriber key has been replaced with ephemeral key generated for each new session. Therefore, since the long-term subscriber key is generated for each new session, the need for generation of RAND value is eliminated. Therefore, no RAND value is shared from the network entity to the UE during AKA.
In addition to using at least one of the PQC KEM based ephemeral shared key, the hybrid ephemeral shared key, and the EC based ephemeral shared key, the system 600 may be configured to use authentication parameters for performing AKA, as described below in conjunction with FIGS. 12a - 14.
FIG. 12a is a schematic diagram depicting encryption of authentication parameters using ephemeral shared key at the HN side, in accordance with one or more embodiments of the present disclosure. FIG. 12b is a schematic diagram depicting decryption of authentication parameters using ephemeral shared key at the UE side, in accordance with one or more embodiments of the present disclosure. As depicted in the Figure 12a, the network entity 603 may be configured to generate an ephemeral shared key using a predetermined key generation mechanism and generate an ephemeral encryption key from the ephemeral shared key using a predefined key derivation function. Further, the network entity 603 may be configured to generate an authentication parameter using a predetermined technique. Furthermore, the network entity may be configured to combine the encrypted authentication parameter with a MAC-tag value and transmit the encrypted authentication parameter, combined with a MAC-tag value, to the UE.
In an embodiment, the authentication parameter is a random number (RAND) and/or an authentication number (AUTN). In an embodiment, the random number is generated using predetermined number generation technique or by a quantum random number generator (QRNG).
In an embodiment, the key generation mechanism comprises of at least one of the elliptical curve (EC) based key generation mechanism, and a post quantum cryptography (PQC) based key encapsulation mechanism (KEM). In an embodiment, the public key and the private key of the network entity are generated using PQC based key generation mechanism.
As depicted in FIG. 12b, the UE may be configured to obtain the encrypted authentication parameter in an authentication request message, generate an ephemeral decryption key corresponding to the ephemeral encryption key generated at the network entity using the key generation mechanism, and decrypt the authentication parameter using the ephemeral decryption key using a symmetric decryption technique corresponding to the symmetric encryption technique.
FIG. 13 is a schematic diagram 1300 depicting an impact of using encrypted authentication parameters in AKA, in accordance with one or more embodiments of the present disclosure. Consequent to using encrypted authentication parameters in AKA, the UDM shall subsequently send this transformed authentication vector AV' (Encrypted RAND, Encrypted AUTN, Mac-tag value, XRES, CK', IK') to the AUSF from which it received the Nudm_UEAuthentication_Get Request together with an indication that the AV' is to be used for EAP-AKA' using a Nudm_UEAuthentication_Get Response message. Further, the SEAF shall transparently forward the EAP-Request/AKA'-Challenge message to the UE in a NAS message Authentication Request message. The ME shall forward the RAND and AUTN received in EAP-Request/AKA'-Challenge message to the USIM. Mac-tag value is verified upon reception of encrypted RAND and/or AUTN by the UE. USIM/ME will decrypt the RAND and/or AUTN value upon reception from network using PQC/Hybrid/EC based key encapsulation algorithm.
Moreover, synchronisation failure indication by UE to network is trigged by UE to network if decryption of RAND and/or AUTN is failed, or verification failure of MAC-tag value occurs.
In yet another implementation, the system 600 may be configured to encrypt the authentication parameters using PQC based encryption and then digitally signing the encrypted the authentication parameters using PQC based digitally signature.
FIG. 14a is a schematic diagram depicting authentication parameters encryption at HN side, in accordance with one or more embodiments of the present disclosure. As depicted in the figure, the network entity may be configured to generate an authentication parameter using a predetermined technique and encrypt the authentication parameter using a private key of the network entity based on PQC based encryption technique. According to embodiments of the present disclosure, the authentication parameter is a random number (RAND) and/or an authentication number (AUTN). According to embodiments of the present disclosure, the public key and the private key of the network entity are generated using PQC key generation mechanism. Further, the network entity may be configured to sign the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature to generate a digitally signed encrypted authentication parameter and transmit the digitally signed encrypted authentication parameter to the UE.
FIG. 14b is a schematic diagram depicting authentication parameters encryption at UE side, in accordance with one or more embodiments of the present disclosure. As depicted in the figure, the UE may be configured to obtain the digitally signed encrypted authentication parameter, and decrypt, upon verifying the digital signature, the encrypted authentication parameter using a public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique.
FIG. 15 is a schematic diagram 1500 depicting an impact of using authentication parameters encryption in AKA, in accordance with one or more embodiments of the present disclosure. Consequent to using encrypted authentication parameters in AKA, Consequent to using encrypted authentication parameters in AKA. Further, the SEAF shall transparently forward the EAP-Request/AKA'-Challenge message to the UE 601 in a NAS message Authentication Request message. The ME shall forward the RAND and AUTN received in EAP-Request/AKA'-Challenge message to the USIM. Signature value is verified upon reception of encrypted RAND and/or AUTN by the UE. USIM/ME will decrypt the RAND and/or AUTN value upon reception from network using PQC/Hybrid/EC based decryption algorithm.
Further, synchronisation failure indication by UE to network is trigged by UE to network if decryption of RAND and/or AUTN is failed, or verification failure of digital signature has occurred.
FIGS. 16a-16b illustrate flow diagrams depicting a method 1600 for performing AKA, according to an embodiment of the present disclosure. The method 1600 includes a series of operations 1601-1605 at the UE and 1607-1611 at the network entity.
Referring to FIG. 16a, at step 1601, the processing unit 613 generates an ephemeral shared key and a corresponding encrypted ephemeral shared key using the post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity generated using PQC based key generation mechanism.
At step 1603, the processing unit 613 generates a first subscriber key (K) using the ephemeral shared key based on a KDF mechanism.
At step 1605, the processing unit 613 transmits the encrypted ephemeral shared key to the network entity.
Referring to FIG. 16b, at step 1607, the processor 605 receives the encrypted ephemeral shared key from the UE.
At step 1609, the processor 605 decrypts the received encrypted ephemeral shared key using the PQC-KEM and the private key of the network entity, generated using PQC based key generation mechanism, to obtain the decrypted ephemeral shared key.
At step 1611, the processor 605 generates a second subscriber key (K) using the ephemeral shared key based on a KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
FIGS. 17a-17b illustrate flow diagrams depicting another method 1700 for performing AKA, according to an embodiment of the present disclosure. The method 1700 includes a series of operations 1701-1711 at the UE and 1713-1721 at the network entity.
In FIG. 17a, at step 1701, the processing unit 613 generates an ephemeral public key and an ephemeral private key using an elliptical curve (EC) based key generation mechanism.
At step 1703, the processing unit 613 generates a first ephemeral key (s1) using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method.
At step 1705, the processing unit 613 generates a second ephemeral shared key (s2) and a corresponding encrypted second ephemeral shared key using the post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and the public key of the network entity generated using PQC based key generation mechanism.
At step 1707, the processing unit 613 combines the first ephemeral key (s1) and the second ephemeral shared key (s2) to generate a first hybrid ephemeral shared key.
At step 1709, the processing unit 613 generates a first subscriber key (K) using the first hybrid ephemeral shared key based on a KDF mechanism.
At step 1711, the processing unit 613 transmits the ephemeral public key and the encrypted second ephemeral shared key to the network entity.
In FIG. 17b, at step 1713, the processor 605 receives the ephemeral public key and the encrypted second ephemeral shared key from the UE.
At step 1715, the processor 605 generates the first ephemeral key (s1) using the ephemeral public key received from UE and the ephemeral private key generated at the HN based on a predetermined key agreement method.
At step 1717, the processor 605 decrypts the received encrypted second ephemeral shared key using the PQC-KEM and a private key of the network entity, generated using PQC based key generation mechanism, to obtain the decrypted second ephemeral shared key (s2).
At step 1719, the processor 605 combines the generated first ephemeral key (s1) and the decrypted second ephemeral shared key (s2) to generate a second hybrid ephemeral shared key, wherein the second hybrid ephemeral shared key is same as the first hybrid ephemeral shared key.
At step 1721, the processor 605 generates a second subscriber key (K) using the second hybrid ephemeral shared key based on the KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
FIGS. 18a-18b illustrate flow diagrams depicting another method 1800 for performing AKA, according to an embodiment of the present disclosure. The method 1800 includes a series of operations 1801-1807 at the UE and 1809-1813 at the network entity.
In FIG. 18a, at step 1801, the processing unit 613 generates an ephemeral public key and an ephemeral private key using an elliptical curve (EC) based key generation mechanism.
At step 1803, the processing unit 613 generates an ephemeral shared key using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method.
At step 1805, the processing unit 613 generates a first subscriber key (K) based on the ephemeral shared key using a predefined KDF mechanism.
At step 1807, the processing unit 613 transmits the ephemeral public key generated at the UE to the network entity.
In FIG. 18b, at step 1809, the processor 605 receives the ephemeral public key from the UE.
At step 1811, the processor 605 generates an ephemeral shared key using a private key of the network entity and the ephemeral public key of the UE using the predetermined key agreement method.
At step 1813, the processor 605 generates a second subscriber key (K) based on the ephemeral shared key using the predefined KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
FIGS. 19a-19b illustrate flow diagrams depicting another method 1900 for performing AKA, according to an embodiment of the present disclosure. The method 1900 includes a series of operations 1901-1909 at the network entity and 1911-1915 at the UE.
In FIG. 19a, at step 1901, the processing unit 605 generates an ephemeral shared key using a key generation mechanism.
At step 1903, the processing unit 605 generates an ephemeral encryption key from the ephemeral shared key using a predefined key derivation function.
At step 1905, the processing unit 605 generates an authentication parameter using a predetermined technique.
At step 1907, the processing unit 605 encrypts the authentication parameter using the ephemeral encryption key using a symmetric encryption technique.
At step 1909, the processing unit 605 transmits the encrypted authentication parameter to UE.
In FIG. 19b, at step 1911, the processor 613 obtains the encrypted authentication parameter in an authentication request message.
At step 1913, the processor 613 generates an ephemeral decryption key corresponding to the ephemeral encryption key generated at the network entity using the key generation mechanism.
At step 1915, the processor 613 decrypts the authentication parameter using the ephemeral decryption key using a symmetric decryption technique corresponding to the symmetric encryption technique.
FIGS. 20a-20b illustrate flow diagrams depicting another method 2000 for performing AKA, according to an embodiment of the present disclosure. The method 2000 includes a series of operations 2001-2007 at the network entity and 2009-2011 at the UE.
In FIG. 20a, at step 2001, the processor 605 generates an authentication parameter using a predetermined technique.
At step 2003, the processor 605 encrypts the authentication parameter using a private key of the network entity based on PQC based encryption technique.
At step 2005, the processor 605 signs the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature to generate a digitally signed encrypted authentication parameter.
At step 2007, the processor 605 transmits the digitally signed encrypted authentication parameter to UE.
In FIG. 20b, at step 2009, the processing unit 613 obtains the digitally signed encrypted authentication parameter.
At step 2011, the processing unit 613 decrypts, upon verifying the digital signature, the encrypted authentication parameter using a public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique.
At least by virtue of aforesaid, the present subject matter at least provides the following advantages:
The system and method disclosed in the present disclosure provides post quantum-safe authentication and key agreement method between subscriber and network entity.
Further, the system and method disclosed in the present disclosure helps to prevent recovery of the subscriber's long-term key, which in turn would also avoid the attacker to pose as the subscriber to the network.
Further, the system and method disclosed in the present disclosure prevents attacker from being able to decrypt all traffic belonging to that subscriber which is not encrypted at the application layer. Hence, subscriber location, privacy and all communication between user equipment and a network entity is not compromised.
Moreover, dynamic and ephemeral subscriber key per each session allows to decrease threat surface to limit to only one session if in case of compromised ephemeral subscriber's long-term key.
Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one ordinary skilled in the art to which this invention belongs. The system, methods, and examples provided herein are illustrative only and not intended to be limiting.
While specific language has been used to describe the present subject matter, any limitations arising on account thereto, are not intended. As would be apparent to a person in the art, various working modifications may be made to the method to implement the inventive concept as taught herein. The drawings and the forgoing description give examples of embodiments. Those skilled in the art will appreciate that one or more of the described elements may well be combined into a single functional element. Alternatively, certain elements may be split into multiple functional elements. Elements from one embodiment may be added to another embodiment.
Claims (15)
- A method performed by a user equipment (UE) in communication with a network entity for performing authentication and key agreement, the method comprising:generating an ephemeral shared key and a corresponding encrypted ephemeral shared key using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity;generating a first subscriber key (K) using the ephemeral shared key based on a key derivation function (KDF) mechanism; andtransmitting the encrypted ephemeral shared key to the network entity, wherein the encrypted ephemeral shared key is used to generate a second subscriber key at the network entity, wherein the second subscriber key is same as the first subscriber key.
- The method of claim 1, wherein the public key of the network entity is generated using PQC based key generation mechanism.
- The method of claim 1, further comprising:receiving, from the network entity, a digitally signed encrypted authentication parameter, wherein the digitally signed encrypted authentication parameter is generated by encrypting authentication parameter using a private key of the network entity based on a PQC based encryption technique, and signing the encrypted authentication parameter using a PQC based digital signature; anddecrypting, upon verifying the digital signature, the encrypted authentication parameter using the public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique
- The method of claim 3, wherein the authentication parameter is a random number (RAND) or an authentication number (AUTN).
- A method performed by a network entity in communication with a user equipment (UE) for authentication and key agreement, the method comprising:receiving the encrypted ephemeral shared key from the UE, wherein the encrypted ephemeral shared key is generated using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity;decrypting the received encrypted ephemeral shared key using the PQC-KEM and a private key of the network entity; andgenerating a second subscriber key (K) using the decrypted ephemeral shared key generated based on a KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
- The method of claim 5, wherein the private key of the network entity is generated using PQC based key generation mechanism.
- The method of claim 5, further comprising:generating an authentication parameter using a predetermined technique;encrypting the authentication parameter using the private key of the network entity based on a PQC based encryption technique;signing the encrypted authentication parameter using a PQC based digital signature to generate a digitally signed encrypted authentication parameter; andtransmitting the digitally signed encrypted authentication parameter to the UE, wherein the digitally signed encrypted authentication parameter is verified and decrypted at the UE.
- The method of claim 7, wherein the authentication parameter is a random number (RAND) or an authentication number (AUTN).
- A user equipment (UE) in communication with a network entity, the UE comprising:a transceiver; anda controller configured to:generate an ephemeral shared key and a corresponding encrypted ephemeral shared key using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity,generate a first subscriber key (K) using the ephemeral shared key based on a key derivation function (KDF) mechanism, andtransmit the encrypted ephemeral shared key to the network entity, wherein the encrypted ephemeral shared key is used to generate a second subscriber key at the network entity, wherein the second subscriber key is same as the first subscriber key
- The UE of claim 9,wherein the public key of the network entity is generated using PQC based key generation mechanism.
- The UE of claim 9,wherein the controller is further configured to:receive, from the network entity, a digitally signed encrypted authentication parameter, wherein the digitally signed encrypted authentication parameter is generated by encrypting authentication parameter using a private key of the network entity based on a PQC based encryption technique, and signing the encrypted authentication parameter using a PQC based digital signature, anddecrypt, upon verifying the digital signature, the encrypted authentication parameter using the public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique.
- The UE of claim 11, wherein the authentication parameter is a random number (RAND) or an authentication number (AUTN).
- A network entity in communication with a user equipment (UE), the network entity comprising:a transceiver; anda controller configured to:receive the encrypted ephemeral shared key from the UE, wherein the encrypted ephemeral shared key is generated using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity,decrypt the received encrypted ephemeral shared key using the PQC-KEM and a private key of the network entity, andgenerate a second subscriber key (K) using the decrypted ephemeral shared key generated based on a KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
- The network entity of claim 13, wherein the private key of the network entity is generated using PQC based key generation mechanism.
- The network entity of claim 13,wherein the controller is further configured to:generate an authentication parameter using a predetermined technique,encrypt the authentication parameter using the private key of the network entity based on a PQC based encryption technique,sign the encrypted authentication parameter using a PQC based digital signature to generate a digitally signed encrypted authentication parameter, andtransmit the digitally signed encrypted authentication parameter to the UE, wherein the digitally signed encrypted authentication parameter is verified and decrypted at the UE.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| IN202341035704 | 2023-05-23 | ||
| IN202341035704 | 2024-05-15 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024242541A1 true WO2024242541A1 (en) | 2024-11-28 |
Family
ID=93590363
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2024/095830 Ceased WO2024242541A1 (en) | 2023-05-23 | 2024-05-22 | Methods and systems for performing authentication and key agreement |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2024242541A1 (en) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN120979836A (en) * | 2025-10-20 | 2025-11-18 | 威胜集团有限公司 | A secure interaction method, medium, and terminal for customer information systems and smart meters. |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20220006835A1 (en) * | 2020-07-02 | 2022-01-06 | International Business Machines Corporation | Tls integration of post quantum cryptographic algorithms |
| US20220038269A1 (en) * | 2020-07-29 | 2022-02-03 | John A. Nix | Device Securing Communications Using Two Post-Quantum Cryptography Key Encapsulation Mechanisms |
| US20220078186A1 (en) * | 2018-12-18 | 2022-03-10 | Telefonaktiebolaget Lm Ericsson (Publ) | Attestation of a platform entity |
| US20220209950A1 (en) * | 2020-12-30 | 2022-06-30 | International Business Machines Corporation | Hybrid key derivation to secure data |
| US20220321333A1 (en) * | 2021-03-31 | 2022-10-06 | Deutsche Telekom Ag | Method and system for creating a quantum secured encryption key |
-
2024
- 2024-05-22 WO PCT/KR2024/095830 patent/WO2024242541A1/en not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20220078186A1 (en) * | 2018-12-18 | 2022-03-10 | Telefonaktiebolaget Lm Ericsson (Publ) | Attestation of a platform entity |
| US20220006835A1 (en) * | 2020-07-02 | 2022-01-06 | International Business Machines Corporation | Tls integration of post quantum cryptographic algorithms |
| US20220038269A1 (en) * | 2020-07-29 | 2022-02-03 | John A. Nix | Device Securing Communications Using Two Post-Quantum Cryptography Key Encapsulation Mechanisms |
| US20220209950A1 (en) * | 2020-12-30 | 2022-06-30 | International Business Machines Corporation | Hybrid key derivation to secure data |
| US20220321333A1 (en) * | 2021-03-31 | 2022-10-06 | Deutsche Telekom Ag | Method and system for creating a quantum secured encryption key |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN120979836A (en) * | 2025-10-20 | 2025-11-18 | 威胜集团有限公司 | A secure interaction method, medium, and terminal for customer information systems and smart meters. |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12052350B2 (en) | Quantum resistant secure key distribution in various protocols and technologies | |
| US11595832B2 (en) | Method and apparatus for base station self-configuration | |
| Fang et al. | Security for 5G mobile wireless networks | |
| JP5324665B2 (en) | Enhanced security for direct link communication | |
| JP7461515B2 (en) | Data transmission methods and systems, electronic equipment, and computer-readable storage media | |
| Degefa et al. | Performance and security enhanced authentication and key agreement protocol for SAE/LTE network | |
| WO2024162661A1 (en) | Methods and systems for performing post quantum cryptography based asymmetric key encryption during primary authentication | |
| KR20250148701A (en) | Primary authentication method and system using hybrid key exchange/hybrid encryption in a communication network | |
| WO2024155072A1 (en) | Method and system for facilitating post quantum secure primary authentication of a subscriber | |
| WO2006118603A2 (en) | Systems and methods for the application of cryptosystems to the data link layer of wireless packet networks | |
| Ouaissa et al. | New security level of authentication and key agreement protocol for the IoT on LTE mobile networks | |
| KR20000017574A (en) | Method for protecting mobile anonymity | |
| WO2024242541A1 (en) | Methods and systems for performing authentication and key agreement | |
| WO2025014198A1 (en) | Method and apparatus for performing client credential assertion in wireless communication system | |
| WO2024177348A1 (en) | Method and apparatus for dynamic data encryption in a communication system with forward secrecy | |
| Moroz et al. | Methods for ensuring data security in mobile standards | |
| Kaur et al. | Security Challenges and Solutions in 5G Networks | |
| WO2023008940A1 (en) | Method and system for securely handling re-connection of client devices to a wireless network | |
| Sadikin et al. | Light-weight Key Management Scheme for Active RFID Applications | |
| Yadav et al. | Security analysis of RSA and ECC in Mobile Wimax | |
| Hashmi et al. | Improved secure network authentication protocol (isnap) for ieee 802.16 | |
| Sadikin et al. | Efficient key management system for large-scale smart RFID applications | |
| Jain et al. | SAP: a low-latency protocol for mitigating evil twin attacks and high computation overhead in WI-FI networks | |
| WO2025244147A1 (en) | First apparatus and method by which first apparatus transmits data, second apparatus and method by which second apparatus transmits data, and third apparatus and method by which third apparatus transmits data | |
| Oguta et al. | Diffie Hellman Application in Wimax Security |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24811476 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |