WO2024242541A1 - Procédés et systèmes pour effectuer une authentification et un accord de clé - Google Patents
Procédés et systèmes pour effectuer une authentification et un accord de clé Download PDFInfo
- Publication number
- WO2024242541A1 WO2024242541A1 PCT/KR2024/095830 KR2024095830W WO2024242541A1 WO 2024242541 A1 WO2024242541 A1 WO 2024242541A1 KR 2024095830 W KR2024095830 W KR 2024095830W WO 2024242541 A1 WO2024242541 A1 WO 2024242541A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- key
- network entity
- pqc
- encrypted
- ephemeral
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0838—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
- H04L9/0841—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
- H04L9/0844—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/083—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
- H04L9/0833—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key
- H04L9/0836—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key using tree structure or hierarchical structure
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
Definitions
- the present disclosure relates to the field of wireless communication networks, and more particularly relates to methods and systems performing authentication and key agreement (AKA) in wireless communication networks.
- AKA authentication and key agreement
- 5G 5th-generation
- connected things may include vehicles, robots, drones, home appliances, displays, smart sensors connected to various infrastructures, construction machines, and factory equipment.
- Mobile devices are expected to evolve in various form-factors, such as augmented reality glasses, virtual reality headsets, and hologram devices.
- 6G communication systems are referred to as beyond-5G systems.
- 6G communication systems which are expected to be commercialized around 2030, will have a peak data rate of tera (1,000 giga)-level bps and a radio latency less than 100 ⁇ sec, and thus will be 50 times as fast as 5G communication systems and have the 1/10 radio latency thereof.
- a full-duplex technology for enabling an uplink transmission and a downlink transmission to simultaneously use the same frequency resource at the same time
- a network technology for utilizing satellites, high-altitude platform stations (HAPS), and the like in an integrated manner
- HAPS high-altitude platform stations
- an improved network structure for supporting mobile base stations and the like and enabling network operation optimization and automation and the like
- a dynamic spectrum sharing technology via collison avoidance based on a prediction of spectrum usage an use of artificial intelligence (AI) in wireless communication for improvement of overall network operation by utilizing AI from a designing phase for developing 6G and internalizing end-to-end AI support functions
- a next-generation distributed computing technology for overcoming the limit of UE computing ability through reachable super-high-performance communication and computing resources (such as mobile edge computing (MEC), clouds, and the like) over the network.
- MEC mobile edge computing
- 6G communication systems in hyper-connectivity, including person to machine (P2M) as well as machine to machine (M2M), will allow the next hyper-connected experience.
- services such as truly immersive extended reality (XR), high-fidelity mobile hologram, and digital replica could be provided through 6G communication systems.
- services such as remote surgery for security and reliability enhancement, industrial automation, and emergency response will be provided through the 6G communication system such that the technologies could be applied in various fields such as industry, medical care, automobiles, and home appliances.
- 5G Fifth Generation
- 5G Fifth Generation
- AKA Authentication and Key Agreement
- FIG. 1 is a schematic diagram 100 depicting an Authentication and Key Agreement (AKA) in 5G, in accordance with the existing art.
- AKA Authentication and Key Agreement
- the representation of authentication and key agreement consists of a user authentication function in the Universal Subscriber Identity Module (USIM) and a construction of Authentication String (AUTS) parameters at a user equipment (UE).
- USIM Universal Subscriber Identity Module
- AUTS Authentication String
- UE user equipment
- a static subscriber long term key K is provisioned to the UE during the SIM provisioning and the random number (RAND) is shared with the UE by the network during the AKA procedure. Further, all the authentication vectors are generated at the UE using K and RAND values.
- AKA provides user identity protection using public-key cryptography, i.e., Elliptical curve based integrated encryption scheme (ECIES).
- ECIES Elliptical curve based integrated encryption scheme
- FIG. 2 firstly elliptical curve based ephemeral key generation happens at a user equipment (UE) and home network (HN).
- HN public key is configured at SIM provisioning.
- Ephemeral UE private key and HN public key are used to generate ephemeral shared key at UE.
- 3rd Generation Partnership Project (3GPP) standards do not mention any specific authentication and key agreement methodology for 5G, beyond 5G, and/or sixth generation (6G) wireless communication system to protect against threats posed by quantum machines.
- 3GPP 3rd Generation Partnership Project
- 6G sixth generation
- ECIES ECIES
- an attacker i.e., an eavesdropper
- an attacker may use quantum machine to launch resource intensive attack could recover a static subscriber long-term key.
- FIG. 3 is a schematic diagram 300 depicting an exemplary representation of the key hierarchy in the 5G wireless communication system and the generation of the authentication vectors at the network, in accordance with the existing art.
- K is the long-term subscriber key or Universal Subscriber Identity Module (USIM) individual key, which is provided to the UE during Subscriber Identity Module (SIM)/Universal Integrated Circuit Card (UICC) provisioning. All keys for access security and core network security entities derive from this long-term subscriber key 'K'.
- a random number (RAND) is generated for providing different authentication vectors for every session between the UE and the network.
- the authentication vectors include a cipher key, integrity key, anonymity key, expected response (XRES), and a Message Authentication Code (MAC).
- MAC Message Authentication Code
- the attacker is enabled to launch fake base stations to communicate with UE compromising user location, privacy and all communication between UE and HN.
- the attacker would need to use resource intensive attack to recover the static subscriber long-term key. Thereafter, the attacker would be required to know parameters related to the home network or the serving network, to model a key derivation algorithm and the inputs to the KDF in the key hierarchy.
- the attacker may leverage quantum machines to recover the key hierarchy. Further, with the leverage of quantum machines and complete hierarchy, the attacker would be able to decrypt all traffic belonging to that subscriber which was not encrypted at the application layer. Moreover, recovery of the subscriber long-term key would also allow the attacker to pose as the subscriber to the network.
- quantum machines are widely used which is a threat to current wireless security systems.
- the quantum machines make use of quantum-mechanical effects which allows quantum bits (qubits) to exist in a combination of several states at once, and entanglement, which further allows connections between separate quantum systems such that they cannot be described independently.
- quantum algorithms that use the quantum-mechanical effects to solve certain cryptographic problems more efficiently than they may be solved on a classical computer.
- Shor's quantum algorithm for integer factorization runs in polynomial time on a quantum computer.
- a variant of Shor's algorithm enables a quantum computer to calculate discrete logarithms in polynomial time, both over finite fields and elliptic curves.
- the variant of Shor's algorithm renders several other public-key cryptosystems insecure, including Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH).
- DH Diffie-Hellman
- ECDH Elliptic Curve Diffie-Hellman
- FIG. 4 is a schematic diagram 400 depicting AKA procedure between the network and the UE, in accordance with the existing art.
- SEAF Security Anchor Function
- AUSF Authentication Server Function
- UDM Unified Data Management
- the RAND is generated at step 1, and is shared unencrypted with the UE in the authentication request message at step 6.
- Recovery of the long term key may also make the attacker to derive all the keys in the hierarchy using key derivation functions. Attacker can create a false base station and communicate with the UE. Thereafter, all privacy and sensitive information from the user, for example, location information, user identity, and others is compromised.
- the recovery of the long term key may also allow the attacker to pose as the subscriber to the network. Attackers may also perform spoofing, Denial of service (DoS), Distributed denial of service (DDoS), and replay attacks on the network.
- DoS Denial of service
- DDoS Distributed denial of service
- replay attacks on the network.
- the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement.
- the method comprises generating an ephemeral shared key and a corresponding encrypted ephemeral shared key using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity generated using PQC based key generation mechanism, generating a first subscriber key (K) using the ephemeral shared key based on a KDF mechanism, and transmitting the encrypted ephemeral shared key to the network entity, wherein the encrypted ephemeral shared key is used to generate a second subscriber key at the network entity, wherein the second subscriber key is same as the first subscriber key.
- PQC post quantum cryptography
- KEM key encapsulation mechanism
- the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement.
- the method comprises receiving the encrypted ephemeral shared key from the UE, wherein the encrypted ephemeral shared key is generated using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity generated using PQC based key generation mechanism, decrypting (1609) the received encrypted ephemeral shared key using the PQC-KEM and a private key of the network entity, generated using the PQC based key generation mechanism, to obtain the decrypted ephemeral shared key, and generating (1611) a second subscriber key (K) using the ephemeral shared key based on a KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
- PQC post quantum cryptography
- KEM key encapsulation mechanism
- the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement.
- the method comprises generating an ephemeral public key and an ephemeral private key using an elliptical curve (EC) based key generation mechanism, generating a first ephemeral key (s1) using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method, generating a second ephemeral shared key (s2) and a corresponding encrypted second ephemeral shared key using the post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and the public key of the network entity generated using PQC based key generation mechanism, combining the first ephemeral key (s1) and the second ephemeral shared key (s2) to generate a first hybrid ephemeral shared key, generating a first subscriber key (K) using the first hybrid
- the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement.
- the method comprises receiving the ephemeral public key and the encrypted second ephemeral shared key from the UE, wherein the ephemeral public key is generated using an elliptical curve (EC) based key generation mechanism, wherein the encrypted second ephemeral shared key is generated using a post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and the public key of the network entity generated using PQC based key generation mechanism; generating a first ephemeral key (s1) using the ephemeral public key received from UE and the ephemeral private key generated at the HN based on a predetermined key agreement method; decrypting the received encrypted second ephemeral shared key using the PQC-KEM and a private key of the network entity, generated using PQC based key generation mechanism, to obtain the decrypted second ep
- the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement.
- the method comprises generating an ephemeral public key and an ephemeral private key using an elliptical curve (EC) based key generation mechanism; generating an ephemeral shared key using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method; generating a first subscriber key (K) based on the ephemeral shared key using a predefined KDF mechanism; and transmitting the ephemeral public key generated at the UE to the network entity, wherein the ephemeral public key is used to generate a second subscriber key at the network entity, wherein the second subscriber key is same as the first subscriber key.
- EC elliptical curve
- the present disclosure refers to a method at a network entity, comprising a public key and a private key, in communication with a UE for authentication and key agreement.
- the method comprises receiving the ephemeral public key from the UE, wherein the ephemeral public key is generated using an elliptical curve (EC) based key generation mechanism, generating an ephemeral shared key using a private key of the network entity and the ephemeral public key of the UE using the predetermined key agreement method, and generating a second subscriber key (K) based on the ephemeral shared key using the predefined KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
- EC elliptical curve
- the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement.
- the method comprises generating an authentication parameter using a predetermined technique; encrypting the authentication parameter using a private key of the network entity based on a PQC based encryption technique; signing the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature to generate a digitally signed encrypted authentication parameter and transmitting the digitally signed encrypted authentication parameter to a user equipment (UE), wherein the digitally signed encrypted authentication parameter is verified and decrypted at the UE.
- PQC post quantum cryptography
- the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement.
- the method comprises obtaining the digitally signed encrypted authentication parameter, wherein the digitally signed encrypted authentication parameter is generated by encrypting authentication parameter using a private key of the network entity based on a PQC based encryption technique, wherein the digitally signed encrypted authentication parameter is further generated by signing the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature; and decrypting, upon verifying the digital signature, the encrypted authentication parameter using a public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique.
- PQC post quantum cryptography
- the present disclosure refers to a method at a network entity in communication with a UE for authentication and key agreement.
- the method comprises generating an ephemeral shared key using a key generation mechanism; generating an ephemeral encryption key from an ephemeral shared key using a key derivation function; generating an authentication parameter using a predetermined technique; encrypting the authentication parameter using the ephemeral encryption key using a symmetric encryption technique; and transmitting the encrypted authentication parameter to a user equipment (UE), wherein the encrypted authentication parameter is decrypted at the UE.
- UE user equipment
- the present disclosure refers to a method at a user equipment (UE) in communication with a network entity for performing authentication and key agreement.
- the method comprises obtaining the encrypted authentication parameter in an authentication request message, wherein the encrypted authentication parameter is generated at the network entity by encrypting an authentication parameter using an ephemeral encryption key using a symmetric encryption technique; generating an ephemeral decryption key corresponding to the ephemeral encryption key generated at the network entity using the key generation mechanism; and decrypting the authentication parameter using the ephemeral decryption key using a symmetric decryption technique corresponding to the symmetric encryption technique.
- the present disclosure refers to a user equipment (UE) and a network entity configured to perform the methods as described in the present disclosure.
- UE user equipment
- Embodiments of the present disclosure provides methods and apparatus for securely performing authentication and key agreement procedure to prevent various attacks on the network.
- FIG. 1 is a schematic diagram depicting an Authentication and Key Agreement (AKA) in 5G, in accordance with the existing art
- FIG. 2 illustrates an exemplary implementation Elliptical curve based integrated encryption scheme, in accordance with existing art
- FIG. 3 is a schematic diagram depicting an exemplary representation of the key hierarchy in the 5G wireless communication system and the generation of the authentication vectors at the network, in accordance with the existing art;
- FIG. 4 is a schematic diagram depicting AKA procedure between the network and the UE, in accordance with the existing art
- FIG. 5 is a schematic diagram depicting a sequence flow diagram of the Authentication and Key Agreement (AKA) procedure highlighting unprotected authentication request messages, in accordance with existing art;
- AKA Authentication and Key Agreement
- FIG. 6 is a block diagram depicting an exemplary system for performing authentication and key agreement (AKA), in accordance with one or more embodiments of the present disclosure
- FIG. 7 is a schematic diagram depicting a part of registration request from UE 601 to HN 603 using PQC-KEM, in accordance with one or more embodiments of the present disclosure
- FIG. 8 is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on PQC KEM based ephemeral shared key, in accordance with one or more embodiments of the present disclosure
- FIG. 9a is a schematic diagram depicting an exemplary implementation of the system for performing AKA based on hybrid ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure
- FIG. 9b is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on hybrid ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure
- FIG. 10a is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure
- FIG. 10b is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure
- FIG. 11a is a schematic diagram depicting an exemplary impact of using ephemeral shared key instead of static subscriber key on key generation at HN side, according to embodiments of the present disclosure
- FIG. 12a is a schematic diagram depicting encryption of authentication parameters using ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure
- FIG. 12b is a schematic diagram depicting decryption of authentication parameters using ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure
- FIG. 13 is a schematic diagram depicting an impact of using encrypted authentication parameters in AKA, in accordance with one or more embodiments of the present disclosure
- FIG. 14a is a schematic diagram depicting authentication parameters encryption at HN side, in accordance with one or more embodiments of the present disclosure
- FIG. 14b is a schematic diagram depicting authentication parameters encryption at UE side, in accordance with one or more embodiments of the present disclosure
- FIG. 15 is a schematic diagram depicting an impact of using authentication parameters encryption in AKA, in accordance with one or more embodiments of the present disclosure
- FIGS. 16a-16b are flow diagrams depicting a method for performing AKA, according to an embodiment of the present disclosure.
- FIGS. 17a-17b are flow diagrams depicting another method for performing AKA, according to an embodiment of the present disclosure.
- FIGS. 18a-18b are flow diagrams depicting another method for performing AKA, according to an embodiment of the present disclosure.
- FIGS. 19a-19b are flow diagrams depicting another method for performing AKA, according to an embodiment of the present disclosure.
- the embodiments disclosed herein describe the methods and systems for performing authentication and key agreement.
- Embodiments disclosed herein relate to techniques for securing the authentication and key agreement (AKA) procedure from quantum machines in both the 5G and the 6G wireless communication systems.
- Embodiments herein define a mechanism for preserving forward secrecy in generating key hierarchy in both the 5G and the 6G wireless communication systems.
- Embodiments herein further define a mechanism for utilizing shared key generated from crypto algorithms to replace the long term key.
- Embodiments disclosed herein further define a mechanism for utilizing shared key generated from crypto algorithms to secure random numbers generated during the AKA procedure.
- the crypto algorithm as disclosed herein refers to either legacy crypto algorithms, post quantum cryptography algorithms, or any hybrid algorithm.
- the post quantum cryptography algorithms are preferred over other crypto algorithms.
- the post quantum cryptography algorithms are safe against quantum attacks and offer fast key generation mechanism.
- FIG. 6 is a block diagram depicting an exemplary system 600 for performing authentication and key agreement (AKA), in accordance with one or more embodiments of the present disclosure.
- the system 600 comprises a user equipment (UE) 601, and a network entity 603 communicatively coupled with each other over a network 611.
- the network entity 603 may be associated with a home network (HN).
- the network entity 603 includes a processor 605, a memory 607, and a communication unit 609.
- the processor 605 may be a single processing unit or a number of units, all of which could include multiple computing units.
- the processor 605 may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logical processors, virtual processors, state machines, logic circuitries, and/or any devices that manipulate signals based on operational instructions.
- the processor 605 is configured to fetch and execute computer-readable instructions and data stored in memory 607.
- the memory 607 may include any non-transitory computer-readable medium known in the art including, for example, volatile memory or Random Access Memory (RAM), such as static random access memory (SRAM) and dynamic random access memory (DRAM), and/or non-volatile memory, such as read-only memory (ROM), erasable programmable ROM, flash memories, hard disks, optical disks, and magnetic tapes.
- RAM Random Access Memory
- SRAM static random access memory
- DRAM dynamic random access memory
- non-volatile memory such as read-only memory (ROM), erasable programmable ROM, flash memories, hard disks, optical disks, and magnetic tapes.
- processing unit 613 the memory unit 615, and the network interface 617 are analogous to the functions of the processor 605, the memory 607, and the communication unit 609, and are not described here again for the sake of brevity.
- each of the UE 601 and the network entity 603 may be configured to perform AKA in one or more possible manners as described in greater detail in the foregoing paragraphs.
- the system 600 may utilize post quantum cryptography (PQC) key encapsulation mechanism (KEM) based shared key generation instead of conventional ECIES.
- PQC post quantum cryptography
- KEM key encapsulation mechanism
- FIG. 7 is a schematic diagram 700 depicting a part of registration request from UE 601 to HN 603 using PQC-KEM, in accordance with one or more embodiments of the present disclosure.
- PQC based key generation happens at HN.
- PQC HN public key may be configured at SIM provisioning.
- a random number may be used, and ephemeral shared key may be generated using PQC KEM.
- the ephemeral shared key may be encrypted using PQC HN Public key to generate encrypted shared key and sent to HN in registration request.
- the network entity HN may receive the encrypted shared key and decrypt the received encrypted shared key using PQC HN private key to derive the same ephemeral shared key as UE.
- system may be configured to perform AKA based on PQC KEM based ephemeral shared key, as depicted in FIG. 8.
- the network entity 603 may be configured to receive the encrypted ephemeral shared key from the UE 601 and decrypt the received encrypted ephemeral shared key using the PQC-KEM and a private key of the network entity 603, generated using PQC based key generation mechanism, to obtain the decrypted ephemeral shared key.
- the public key, and the private key of the network entity 603 may generated using PQC based key generation mechanism.
- the network entity 603 may be configured to generate a second subscriber key (K) using the ephemeral shared key based on the predefined KDF mechanism such that the second subscriber key is same as the first subscriber key.
- the subscriber key in the network entity may be derived from the PQC based ephemeral key created from PQC KEM and using private key of HN.
- the subscriber key may be an ephemeral key generated for each user session.
- the subscriber key in the UE may be derived from the PQC based ephemeral key created from PQC KEM and using public key of HN.
- the subscriber key may be the ephemeral key generated for each user session.
- system may be configured to perform AKA based on hybrid ephemeral shared key, as depicted in FIG. 9a and 9b.
- FIG. 9a is a schematic diagram 900 depicting an exemplary implementation of the system 600 for performing AKA based on hybrid ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure.
- the hybrid ephemeral key may be obtained using a combination of elliptical curve (EC) based key generation mechanism, and PQC KEM.
- EC elliptical curve
- the UE 601 may be configured to generate a second ephemeral shared key (s2) and a corresponding encrypted second ephemeral shared key using the PQC KEM, and the public key of the network entity generated using PQC based key generation mechanism. Furthermore, the UE 601 may be configured to combine the first ephemeral key (s1) and the second ephemeral shared key (s2) to generate a first hybrid ephemeral shared key and generate a first subscriber key (K) using the first hybrid ephemeral shared key based on a predefined KDF mechanism. Moreover, the UE 601 may be configured to transmit the ephemeral public key and the encrypted second ephemeral shared key to the network entity.
- s2 second ephemeral shared key
- K subscriber key
- FIG. 9b is a schematic diagram 900 depicting an exemplary implementation of the system 600 for performing AKA based on hybrid ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure.
- the network entity 603 may be configured to receive the ephemeral public key and the encrypted second ephemeral shared key from the UE 601 and generate the first ephemeral key (s1) using the ephemeral public key received from UE and the ephemeral private key generated at the HN based on a predetermined key agreement method.
- the network entity 603 may be configured to decrypt the received encrypted second ephemeral shared key using the PQC-KEM and a private key of the network entity, generated using PQC based key generation mechanism, to obtain the decrypted second ephemeral shared key (s2).
- the private key of the network entity 603 may be generated using PQC based key generation mechanism.
- the subscriber key in the network entity may be derived from the hybrid shared key based on elliptical shared key and post quantum shared key using private key of HN.
- the subscriber key may be an ephemeral key generated for each user session.
- the subscriber key in the UE may be derived from the Hybrid shared key based on elliptical shared key and post quantum shared key using public key of HN.
- the subscriber key may be the ephemeral key generated for each user session.
- system may be configured to perform AKA based on EC based ephemeral shared key, as depicted in FIGS. 10a and 10b.
- FIG. 10a is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at UE side, in accordance with one or more embodiments of the present disclosure.
- the UE may be configured to generate an ephemeral public key and an ephemeral private key using the EC based key generation mechanism.
- the UE 601 may be configured to generate an ephemeral shared key using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method.
- the UE 601 may be configured to generate a first subscriber key (K) based on the ephemeral shared key using a predefined KDF mechanism, and transmit the ephemeral public key generated at the UE to the network entity.
- K subscriber key
- FIG. 10b is a schematic diagram depicting an exemplary implementation of the system 600 for performing AKA based on EC based ephemeral shared key at HN side, in accordance with one or more embodiments of the present disclosure.
- the network entity may be configured to receive the ephemeral public key from the UE, and generate an ephemeral shared key using a private key of the network entity and the ephemeral public key of the UE using the predetermined key agreement method. Further, the network entity may be configured to generate a second subscriber key (K) based on the ephemeral shared key using the predefined KDF mechanism, such that the second subscriber key is same as the first subscriber key.
- K subscriber key
- the subscriber key in the network entity may be derived from the elliptical shared key created from elliptical cryptography algorithms and using private key of HN.
- the subscriber key may be an ephemeral key generated for each user session.
- the subscriber key in the UE may be derived from the elliptical shared key created from elliptical cryptography algorithms and using public key of HN.
- the subscriber key may be the ephemeral key generated for each user session.
- FIG. 11a is a schematic diagram depicting an exemplary impact of using ephemeral shared key instead of static subscriber key on key generation at HN side, according to embodiments of the present disclosure.
- FIG. 11b is a schematic diagram depicting an exemplary impact of using ephemeral shared key instead of static subscriber key on key generation at UE side, according to embodiments of the present disclosure.
- the static subscriber key has been replaced with ephemeral key generated for each new session. Therefore, since the long-term subscriber key is generated for each new session, the need for generation of RAND value is eliminated. Therefore, no RAND value is shared from the network entity to the UE during AKA.
- the system 600 may be configured to use authentication parameters for performing AKA, as described below in conjunction with FIGS. 12a - 14.
- FIG. 12a is a schematic diagram depicting encryption of authentication parameters using ephemeral shared key at the HN side, in accordance with one or more embodiments of the present disclosure.
- FIG. 12b is a schematic diagram depicting decryption of authentication parameters using ephemeral shared key at the UE side, in accordance with one or more embodiments of the present disclosure.
- the network entity 603 may be configured to generate an ephemeral shared key using a predetermined key generation mechanism and generate an ephemeral encryption key from the ephemeral shared key using a predefined key derivation function. Further, the network entity 603 may be configured to generate an authentication parameter using a predetermined technique. Furthermore, the network entity may be configured to combine the encrypted authentication parameter with a MAC-tag value and transmit the encrypted authentication parameter, combined with a MAC-tag value, to the UE.
- the authentication parameter is a random number (RAND) and/or an authentication number (AUTN).
- the random number is generated using predetermined number generation technique or by a quantum random number generator (QRNG).
- the key generation mechanism comprises of at least one of the elliptical curve (EC) based key generation mechanism, and a post quantum cryptography (PQC) based key encapsulation mechanism (KEM).
- the public key and the private key of the network entity are generated using PQC based key generation mechanism.
- the UE may be configured to obtain the encrypted authentication parameter in an authentication request message, generate an ephemeral decryption key corresponding to the ephemeral encryption key generated at the network entity using the key generation mechanism, and decrypt the authentication parameter using the ephemeral decryption key using a symmetric decryption technique corresponding to the symmetric encryption technique.
- FIG. 13 is a schematic diagram 1300 depicting an impact of using encrypted authentication parameters in AKA, in accordance with one or more embodiments of the present disclosure.
- the UDM shall subsequently send this transformed authentication vector AV' (Encrypted RAND, Encrypted AUTN, Mac-tag value, XRES, CK', IK') to the AUSF from which it received the Nudm_UEAuthentication_Get Request together with an indication that the AV' is to be used for EAP-AKA' using a Nudm_UEAuthentication_Get Response message.
- the SEAF shall transparently forward the EAP-Request/AKA'-Challenge message to the UE in a NAS message Authentication Request message.
- the ME shall forward the RAND and AUTN received in EAP-Request/AKA'-Challenge message to the USIM. Mac-tag value is verified upon reception of encrypted RAND and/or AUTN by the UE. USIM/ME will decrypt the RAND and/or AUTN value upon reception from network using PQC/Hybrid/EC based key encapsulation algorithm.
- synchronisation failure indication by UE to network is trigged by UE to network if decryption of RAND and/or AUTN is failed, or verification failure of MAC-tag value occurs.
- system 600 may be configured to encrypt the authentication parameters using PQC based encryption and then digitally signing the encrypted the authentication parameters using PQC based digitally signature.
- FIG. 14a is a schematic diagram depicting authentication parameters encryption at HN side, in accordance with one or more embodiments of the present disclosure.
- the network entity may be configured to generate an authentication parameter using a predetermined technique and encrypt the authentication parameter using a private key of the network entity based on PQC based encryption technique.
- the authentication parameter is a random number (RAND) and/or an authentication number (AUTN).
- the public key and the private key of the network entity are generated using PQC key generation mechanism.
- the network entity may be configured to sign the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature to generate a digitally signed encrypted authentication parameter and transmit the digitally signed encrypted authentication parameter to the UE.
- PQC post quantum cryptography
- FIG. 14b is a schematic diagram depicting authentication parameters encryption at UE side, in accordance with one or more embodiments of the present disclosure.
- the UE may be configured to obtain the digitally signed encrypted authentication parameter, and decrypt, upon verifying the digital signature, the encrypted authentication parameter using a public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique.
- FIG. 15 is a schematic diagram 1500 depicting an impact of using authentication parameters encryption in AKA, in accordance with one or more embodiments of the present disclosure.
- the SEAF shall transparently forward the EAP-Request/AKA'-Challenge message to the UE 601 in a NAS message Authentication Request message.
- the ME shall forward the RAND and AUTN received in EAP-Request/AKA'-Challenge message to the USIM.
- Signature value is verified upon reception of encrypted RAND and/or AUTN by the UE.
- USIM/ME will decrypt the RAND and/or AUTN value upon reception from network using PQC/Hybrid/EC based decryption algorithm.
- synchronisation failure indication by UE to network is trigged by UE to network if decryption of RAND and/or AUTN is failed, or verification failure of digital signature has occurred.
- FIGS. 16a-16b illustrate flow diagrams depicting a method 1600 for performing AKA, according to an embodiment of the present disclosure.
- the method 1600 includes a series of operations 1601-1605 at the UE and 1607-1611 at the network entity.
- the processing unit 613 generates an ephemeral shared key and a corresponding encrypted ephemeral shared key using the post quantum cryptography (PQC) based key encapsulation mechanism (KEM) and a public key of the network entity generated using PQC based key generation mechanism.
- PQC post quantum cryptography
- KEM key encapsulation mechanism
- the processing unit 613 generates a first subscriber key (K) using the ephemeral shared key based on a KDF mechanism.
- the processing unit 613 transmits the encrypted ephemeral shared key to the network entity.
- the processor 605 receives the encrypted ephemeral shared key from the UE.
- the processor 605 decrypts the received encrypted ephemeral shared key using the PQC-KEM and the private key of the network entity, generated using PQC based key generation mechanism, to obtain the decrypted ephemeral shared key.
- the processor 605 generates a second subscriber key (K) using the ephemeral shared key based on a KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
- FIGS. 17a-17b illustrate flow diagrams depicting another method 1700 for performing AKA, according to an embodiment of the present disclosure.
- the method 1700 includes a series of operations 1701-1711 at the UE and 1713-1721 at the network entity.
- the processing unit 613 generates an ephemeral public key and an ephemeral private key using an elliptical curve (EC) based key generation mechanism.
- EC elliptical curve
- the processing unit 613 generates a first ephemeral key (s1) using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method.
- the processing unit 613 combines the first ephemeral key (s1) and the second ephemeral shared key (s2) to generate a first hybrid ephemeral shared key.
- the processing unit 613 generates a first subscriber key (K) using the first hybrid ephemeral shared key based on a KDF mechanism.
- the processing unit 613 transmits the ephemeral public key and the encrypted second ephemeral shared key to the network entity.
- the processor 605 receives the ephemeral public key and the encrypted second ephemeral shared key from the UE.
- the processor 605 generates the first ephemeral key (s1) using the ephemeral public key received from UE and the ephemeral private key generated at the HN based on a predetermined key agreement method.
- the processor 605 combines the generated first ephemeral key (s1) and the decrypted second ephemeral shared key (s2) to generate a second hybrid ephemeral shared key, wherein the second hybrid ephemeral shared key is same as the first hybrid ephemeral shared key.
- the processor 605 generates a second subscriber key (K) using the second hybrid ephemeral shared key based on the KDF mechanism, wherein the second subscriber key is same as the first subscriber key.
- FIGS. 18a-18b illustrate flow diagrams depicting another method 1800 for performing AKA, according to an embodiment of the present disclosure.
- the method 1800 includes a series of operations 1801-1807 at the UE and 1809-1813 at the network entity.
- the processing unit 613 generates an ephemeral shared key using a public key of the network entity and the ephemeral private key generated at the UE based on a predetermined key agreement method.
- the processing unit 613 generates a first subscriber key (K) based on the ephemeral shared key using a predefined KDF mechanism.
- the processing unit 613 transmits the ephemeral public key generated at the UE to the network entity.
- the processor 605 receives the ephemeral public key from the UE.
- the processor 605 generates an ephemeral shared key using a private key of the network entity and the ephemeral public key of the UE using the predetermined key agreement method.
- FIGS. 19a-19b illustrate flow diagrams depicting another method 1900 for performing AKA, according to an embodiment of the present disclosure.
- the method 1900 includes a series of operations 1901-1909 at the network entity and 1911-1915 at the UE.
- the processing unit 605 generates an ephemeral shared key using a key generation mechanism.
- the processing unit 605 encrypts the authentication parameter using the ephemeral encryption key using a symmetric encryption technique.
- the processing unit 605 transmits the encrypted authentication parameter to UE.
- the processor 613 obtains the encrypted authentication parameter in an authentication request message.
- the processor 613 generates an ephemeral decryption key corresponding to the ephemeral encryption key generated at the network entity using the key generation mechanism.
- the processor 613 decrypts the authentication parameter using the ephemeral decryption key using a symmetric decryption technique corresponding to the symmetric encryption technique.
- FIGS. 20a-20b illustrate flow diagrams depicting another method 2000 for performing AKA, according to an embodiment of the present disclosure.
- the method 2000 includes a series of operations 2001-2007 at the network entity and 2009-2011 at the UE.
- the processor 605 generates an authentication parameter using a predetermined technique.
- the processor 605 encrypts the authentication parameter using a private key of the network entity based on PQC based encryption technique.
- the processor 605 signs the encrypted authentication parameter using a post quantum cryptography (PQC) based digital signature to generate a digitally signed encrypted authentication parameter.
- PQC post quantum cryptography
- the processor 605 transmits the digitally signed encrypted authentication parameter to UE.
- the processing unit 613 obtains the digitally signed encrypted authentication parameter.
- the processing unit 613 decrypts, upon verifying the digital signature, the encrypted authentication parameter using a public key of the network entity based on a PQC based decryption technique corresponding to the PQC based encryption technique.
- the system and method disclosed in the present disclosure provides post quantum-safe authentication and key agreement method between subscriber and network entity.
- system and method disclosed in the present disclosure helps to prevent recovery of the subscriber's long-term key, which in turn would also avoid the attacker to pose as the subscriber to the network.
- system and method disclosed in the present disclosure prevents attacker from being able to decrypt all traffic belonging to that subscriber which is not encrypted at the application layer. Hence, subscriber location, privacy and all communication between user equipment and a network entity is not compromised.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
La présente divulgation se rapporte à un système de communication 5G ou à un système de communication 6G permettant de prendre en charge des débits de données supérieurs à ceux d'un système de communication 4G, tel qu'un système d'évolution à long terme (LTE). La divulgation concerne un procédé au niveau d'un équipement utilisateur (UE) en communication avec une entité de réseau pour effectuer une authentification et un accord de clé. Le procédé consiste à générer (1601) une clé partagée éphémère et une clé partagée éphémère chiffrée correspondante à l'aide d'un mécanisme d'encapsulation de clé (KEM) basé sur la cryptographie post quantique (PQC) et une clé publique de l'entité de réseau générée à l'aide d'un mécanisme de génération de clé basé sur PQC. De plus, le procédé consiste à générer (1603) une première clé d'abonné (K) à l'aide de la clé partagée éphémère sur la base d'un mécanisme KDF. Le procédé consiste également à transmettre (1605) la clé partagée éphémère chiffrée à l'entité de réseau, la clé partagée éphémère chiffrée étant utilisée pour générer une seconde clé d'abonné au niveau de l'entité de réseau, la seconde clé d'abonné étant la même que la première clé d'abonné.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| IN202341035704 | 2023-05-23 | ||
| IN202341035704 | 2024-05-15 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024242541A1 true WO2024242541A1 (fr) | 2024-11-28 |
Family
ID=93590363
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2024/095830 Ceased WO2024242541A1 (fr) | 2023-05-23 | 2024-05-22 | Procédés et systèmes pour effectuer une authentification et un accord de clé |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2024242541A1 (fr) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN120979836A (zh) * | 2025-10-20 | 2025-11-18 | 威胜集团有限公司 | 一种客户信息系统和智能仪表安全交互方法、介质及终端 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20220006835A1 (en) * | 2020-07-02 | 2022-01-06 | International Business Machines Corporation | Tls integration of post quantum cryptographic algorithms |
| US20220038269A1 (en) * | 2020-07-29 | 2022-02-03 | John A. Nix | Device Securing Communications Using Two Post-Quantum Cryptography Key Encapsulation Mechanisms |
| US20220078186A1 (en) * | 2018-12-18 | 2022-03-10 | Telefonaktiebolaget Lm Ericsson (Publ) | Attestation of a platform entity |
| US20220209950A1 (en) * | 2020-12-30 | 2022-06-30 | International Business Machines Corporation | Hybrid key derivation to secure data |
| US20220321333A1 (en) * | 2021-03-31 | 2022-10-06 | Deutsche Telekom Ag | Method and system for creating a quantum secured encryption key |
-
2024
- 2024-05-22 WO PCT/KR2024/095830 patent/WO2024242541A1/fr not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20220078186A1 (en) * | 2018-12-18 | 2022-03-10 | Telefonaktiebolaget Lm Ericsson (Publ) | Attestation of a platform entity |
| US20220006835A1 (en) * | 2020-07-02 | 2022-01-06 | International Business Machines Corporation | Tls integration of post quantum cryptographic algorithms |
| US20220038269A1 (en) * | 2020-07-29 | 2022-02-03 | John A. Nix | Device Securing Communications Using Two Post-Quantum Cryptography Key Encapsulation Mechanisms |
| US20220209950A1 (en) * | 2020-12-30 | 2022-06-30 | International Business Machines Corporation | Hybrid key derivation to secure data |
| US20220321333A1 (en) * | 2021-03-31 | 2022-10-06 | Deutsche Telekom Ag | Method and system for creating a quantum secured encryption key |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN120979836A (zh) * | 2025-10-20 | 2025-11-18 | 威胜集团有限公司 | 一种客户信息系统和智能仪表安全交互方法、介质及终端 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12052350B2 (en) | Quantum resistant secure key distribution in various protocols and technologies | |
| US11595832B2 (en) | Method and apparatus for base station self-configuration | |
| Fang et al. | Security for 5G mobile wireless networks | |
| JP5324665B2 (ja) | ダイレクトリンク通信のための拡張されたセキュリティ | |
| JP7461515B2 (ja) | データ伝送方法及びシステム、電子機器、並びにコンピュータ可読記憶媒体 | |
| Degefa et al. | Performance and security enhanced authentication and key agreement protocol for SAE/LTE network | |
| WO2024162661A1 (fr) | Procédés et systèmes permettant d'effectuer un cryptage de clé asymétrique basé sur la cryptographie post-quantique pendant une authentification primaire | |
| KR20250148701A (ko) | 통신 네트워크에서 하이브리드 키 교환/하이브리드 암호화를 사용한 1차 인증 방법 및 시스템 | |
| WO2024155072A1 (fr) | Procédé et système pour faciliter une authentification primaire sécurisée post-quantique d'un abonné | |
| WO2006118603A2 (fr) | Systemes et procedes d'application de cryptosystemes sur la couche liaison de donnees de reseaux sans fils paquetises | |
| Ouaissa et al. | New security level of authentication and key agreement protocol for the IoT on LTE mobile networks | |
| KR20000017574A (ko) | 이동국 및 네트워크에서의 임시 이동국 식별자 설정 방법 | |
| WO2024242541A1 (fr) | Procédés et systèmes pour effectuer une authentification et un accord de clé | |
| WO2025014198A1 (fr) | Procédé et appareil pour effectuer une assertion de justificatif d'identité de client dans un système de communication sans fil | |
| WO2024177348A1 (fr) | Procédé et appareil de chiffrement dynamique de données dans un système de communication à confidentialité directe | |
| Moroz et al. | Methods for ensuring data security in mobile standards | |
| Kaur et al. | Security Challenges and Solutions in 5G Networks | |
| WO2023008940A1 (fr) | Procédé et système de gestion sécurisée de reconnexion de dispositifs clients à un réseau sans fil | |
| Sadikin et al. | Light-weight Key Management Scheme for Active RFID Applications | |
| Yadav et al. | Security analysis of RSA and ECC in Mobile Wimax | |
| Hashmi et al. | Improved secure network authentication protocol (isnap) for ieee 802.16 | |
| Sadikin et al. | Efficient key management system for large-scale smart RFID applications | |
| Jain et al. | SAP: a low-latency protocol for mitigating evil twin attacks and high computation overhead in WI-FI networks | |
| WO2025244147A1 (fr) | Premier appareil et procédé par lesquels un premier appareil transmet des données, deuxième appareil et procédé par lesquels un deuxième appareil transmet des données, et troisième appareil et procédé par lesquels un troisième appareil transmet des données | |
| Oguta et al. | Diffie Hellman Application in Wimax Security |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24811476 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |