IP Library Granted Patent US 12,052,350
Granted Patent B2
US 12,052,350 · App. 17/370,888 · Granted Jul 30, 2024

Quantum resistant secure key distribution in various protocols and technologies

Inventors: Niranjan M M (Karnataka, IN); Nagaraj Kenchaiah (Karnataka, IN)
Assignee: Cisco Technology, Inc.
H04L9/0852H04L5/0053H04L9/0819H04L9/085H04L9/30H04W36/10H04W76/11G06N10/00H04L67/1097H04W84/042H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,052,350
App. No.
17/370,888
Granted
Jul 30, 2024
Kind
B2
Abstract

A quantum resistant method is provided for supporting user equipment (UE) roaming across APs/eNBs/gNBs belonging to various Wireless LAN Controllers (WLCs) in enterprise 5G and WiFi co-located deployments. The method may include initializing a SKS server in an electrical communication with a master WLC with a random post-quantum common secret seed (PQSEED) to generate a post-quantum pre-shared key (PQPSK) and a respective PQPSK-ID. The method may also include sending an encrypted PQSEED along with a PQPSK-ID to a second WLC. The method may further include joining AP (WiFi) to the master WLC using a CAPWAP/DTLS protocol. The method may further include sending the PQPSK-ID from the master WLC to the UE in an EAP success packet when the UE is associated with the AP (WiFi).

Claims (34)

1. A quantum resistant method for supporting user equipment (UE) roaming across APs/eNBs/gNBs belonging to various Wireless LAN Controllers (WLCs) in enterprise 5G and WiFi co-located deployments, the method comprising:

initializing a SKS server in an electrical communication with a master WLC with a random post-quantum common secret seed (PQSEED) to generate a post-quantum pre-shared key (PQPSK) and a respective PQPSK-ID;

sending, by the master WLC, an encrypted PQSEED along with a PQPSK-ID to a second WLC to establish a quantum secure connection with the second WLC;

joining AP (WiFi) to the master WLC using a CAPWAP/DTLS protocol; and

sending the PQPSK-ID from the master WLC to the UE in an EAP success packet when the UE is associated with the AP (WiFi).

2. The method of claim 1 , wherein the master WLC generates the PQSEED having a one-time PQSEED value for initializing the SKS server in an electrical communication with the WLC.

3. The method of claim 2 , wherein the master WLC encrypts the PQSEED using a public key of the second WLC to generate the encrypted PQSEED.

4. The method of claim 3 , wherein the second WLC decrypts the encrypted PQSEED using a private key of the second WLC.

5. The method of claim 4 , wherein the decrypted PQSEED initializes a second SKS server in an electrical communication with the second WLC to obtain a respective PQPSK to the PQPSK-ID.

6. The method of claim 1 , wherein the UE generates WiFi keys (PMK, GMK) using MSK.

7. The method of claim 6 , wherein the UE generates LTE keys using the PMK and PQPSK.

8. The method of claim 7 , wherein eNB/gNB joins to the second WLC over S1-MME when the UE roams to the second WLC.

9. The method of claim 8 , wherein a MME of the second WLC receives “Attach Request” from the UE using PQPSK-ID along NAS key set identifier, generates KASME using the PQPSK with the PMK, sends Initial Context Setup Request (KeNB, Selected Security Algorithm) to the eNB/gNB, and sends “Attach Accept” (NAS encrypted and Integrity Protected) to the UE.

10. The method of claim 9 , wherein the Key Access Security Management Entries (KASME) is used for generating integrity and security keys for a private LTE session by the MME of the second WLC.

11. The method of claim 9 , wherein the Initial Context Setup has KeNB keys for eNB/gNB and selected Integrity and Cipher algorithms.

12. The method of claim 11 , wherein the eNB/gNB generates KRRC_integrity, KRRC_encryption, KUP_encryption using the KeNB keys.

13. The method of claim 8 , wherein a Radio Resource Control (RRC) signaling between the UE and the eNB/gNB is protected by Integrity and Encryption.

14. The method of claim 8 , wherein a Network-attached storage (NAS) signaling between the UE and MME/WLC is protected by Integrity and Encryption.

15. The method of claim 8 , wherein a User Plane data between the UE and the eNB/gNB is protected by Encryption (ciphered).

16. A system comprising:

one or more processors;

a non-transitory computer readable medium comprising instructions stored therein, the instructions, when executed by the one or more processors, cause the processors perform operations comprising:

initializing a SKS server in an electrical communication with a master WLC with a random post-quantum common secret seed (PQSEED) to generate a post-quantum pre-shared key (PQPSK) and a respective PQPSK-ID;

sending, by the master WLC, an encrypted PQSEED along with a PQPSK-ID to a second WLC to establish a quantum secure connection with the second WLC;

joining AP (WiFi) to the master WLC using a CAPWAP/DTLS protocol; and

sending the PQPSK-ID from the master WLC to the UE in an EAP success packet when the UE is associated with the AP (WiFi).

17. The system of claim 16 , wherein the master WLC generates the PQSEED having a one-time PQSEED value for initializing the SKS server in an electrical communication with the WLC.

18. The method of claim 16 , wherein the UE generates WiFi keys (PMK, GMK) using MSK and generates LTE keys using the PMK and PQPSK.

19. The method of claim 16 , wherein eNB/gNB joins to the second WLC over S1-MME when the UE roams to the second WLC.

20. A non-transitory computer readable medium comprising instructions, the instructions, when executed by a computing system, cause the computing system to perform operations comprising:

initializing a SKS server in an electrical communication with a master WLC with a random post-quantum common secret seed (PQSEED) to generate a post-quantum pre-shared key (PQPSK) and a respective PQPSK-ID;

sending, by the master WLC, an encrypted PQSEED along with a PQPSK-ID to a second WLC to establish a quantum secure connection with the second WLC;

joining AP (WiFi) to the master WLC using a CAPWAP/DTLS protocol; and

sending the PQPSK-ID from the master WLC to the UE in an EAP success packet when the UE is associated with the AP (WiFi).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: M M, NIRANJAN; KENCHAIAH, NAGARAJ
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056796/0495 →
Continuity (1)
Related Publication 20230014894A1 · Jan 19, 2023
Cited By (2)
US 12,627,503 US 12,640,915