IP Library › Granted Patent US 12,568,068
Granted Patent B2
US 12,568,068 · App. 18/583,284 · Granted Mar 3, 2026

Method and apparatus for dynamic data encryption in a communication system with forward secrecy

Inventors: Ramesh Chandra Vuppala (Bangalore, IN); Dixit Kumar (Bangalore, IN); Donghyun Je (Suwon-si, KR); Neha Sharma (Bangalore, IN); Anshuman Nigam (Bangalore, IN); Dongmyoung Kim (Suwon-si, KR)
Assignee: Samsung Electronics Co., Ltd.
H04L63/0428H04L9/085H04L9/14H04L9/3073
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,068
App. No.
18/583,284
Granted
Mar 3, 2026
Kind
B2
Abstract

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. A method performed by a terminal for dynamic data encryption in a communication system is provided. The method includes receiving, from a network entity, a list of network public keys including a plurality of network public keys and corresponding key indexes, generating a pair of keys including a user equipment (UE) public key and a UE private key in response to receiving the list of network public keys, randomly selecting a network public key from the list of network public keys received from the network entity, generating a shared secret key corresponding to the UE by using the randomly selected network public key and the UE private key, and encrypting data to be transferred between the UE and the network entity by using the generated shared secret key corresponding to the UE.

Claims (58)

1 . A method performed by a terminal for dynamic data encryption in a communication system, the method comprising:

receiving, from a network entity, a list of network public keys including a plurality of network public keys and corresponding key indexes;

updating previously stored network public keys with the list of network public keys;

generating a pair of keys including a user equipment (UE) public key and a UE private key in response to receiving the list of network public keys;

selecting, for each of a plurality of sessions, a network public key from the list of network public keys received from the network entity;

generating a shared secret key corresponding to the terminal by using the selected network public key and the UE private key;

encrypting data to be transferred between the terminal and the network entity by using the generated shared secret key corresponding to the terminal; and

transmitting, to the network entity, the UE public key and a key index corresponding to the selected network public key for enabling the network entity to generate a shared secret key corresponding to the network entity using the UE public key and the key index corresponding to the selected network public key.

2 . The method of claim 1 , wherein the list of network public keys is received over one of a secured communication channel or an unsecured communication channel.

3 . The method of claim 2 , wherein the receiving of the list of network public keys from the network entity over the secured communication channel comprises:

establishing a radio resource control (RRC) channel with the network entity; and

receiving, from the network entity, the list of network public keys using at least one of a registration accept message, an N1 message, and an RRC connection message.

4 . The method of claim 2 , wherein the receiving of the list of network public keys from the network entity over the unsecured communication channel comprises:

receiving, from the network entity, the list of network public keys signed with a digital signature using a network private key.

5 . The method of claim 1 , wherein the data to be transferred between the UE and the network entity corresponds to a subscription permanent identifier (SUPI).

6 . The method of claim 1 , wherein the list of network public keys corresponds to a list of temporary public keys of a network provided during subscriber identity module (SIM) provisioning.

7 . A method performed by a network entity for dynamic data encryption in a communication system, the method comprising:

transmitting, to a terminal, a list of network public keys including a plurality of network public keys and corresponding key indexes;

receiving, from the terminal, a user equipment (UE) public key and a key index corresponding to a network public key selected from the transmitted list of network public keys for each of a plurality of sessions, in response to the transmitted list of network public keys;

generating a shared secret key corresponding to the network entity using the UE public key and the key index corresponding to the network public key; and

encrypting data to be transferred between the terminal and the network entity by using the generated shared secret key corresponding to the network entity.

8 . The method of claim 7 , wherein the list of network public keys is transmitted over one of a secured communication channel or an unsecured communication channel.

9 . The method of claim 8 , wherein the transmitting of the list of network public keys over the secured communication channel comprises:

establishing a radio resource control (RRC) channel with the terminal; and

transmitting, to the terminal, the list of network public keys using at least one of a registration accept message, an N1 message, and an RRC connection message.

10 . A terminal, comprising:

a transceiver;

memory storing one or more computer programs; and

one or more processors communicatively coupled to the transceiver and the memory,

wherein the one or more computer programs include computer-executable instructions that, when executed by the one or more processors individually or collectively, cause the terminal to:

receive, from a network entity via the transceiver, a list of network public keys including a plurality of network public keys and corresponding key indexes,

update previously stored network public keys with the list of network public keys,

generate a pair of keys including a user equipment (UE) public key and a UE private key in response to receiving the list of network public keys,

select, for each of a plurality of sessions, a network public key from the list of network public keys received from the network entity,

generate a shared secret key corresponding to the terminal by using the selected network public key and the UE private key,

encrypt data to be transferred between the terminal and the network entity by using the generated shared secret key corresponding to the terminal, and

transmit, to the network entity via the transceiver, the UE public key and a key index corresponding to the selected network public key for enabling the network entity to generate a shared secret key corresponding to the network entity using the UE public key and the key index corresponding to the selected network public key.

11 . The terminal of claim 10 , wherein the list of network public keys is received over one of a secured communication channel or an unsecured communication channel.

12 . The terminal of claim 11 , wherein the one or more computer programs further include computer-executable instructions that, when executed by the one or more processors, cause the terminal to:

establish a radio resource control (RRC) channel with the network entity; and

receive, from the network entity, the list of network public keys using at least one of a registration accept message, an N1 message, and an RRC connection message.

13 . The terminal of claim 11 , wherein the one or more computer programs further include computer-executable instructions that, when executed by the one or more processors, cause the terminal to:

receive, from the network entity via the transceiver, the list of network public keys signed with a digital signature using a network private key.

14 . The terminal of claim 10 , wherein the data to be transferred between the UE and the network entity corresponds to a subscription permanent identifier (SUPI).

15 . The terminal of claim 10 , wherein the list of network public keys corresponds to a list of temporary public keys of a network provided during subscriber identity module (SIM) provisioning.

16 . A network entity, comprising:

a transceiver;

memory storing one or more computer programs; and

one or more processors communicatively coupled to the transceiver and the memory,

wherein the one or more computer programs include computer-executable instructions that, when executed by the one or more processors, cause the network entity to:

transmit, to a terminal via the transceiver, a list of network public keys including a plurality of network public keys and corresponding key indexes,

receive, from the terminal via the transceiver, a user equipment (UE) public key and a key index corresponding to a network public key selected from the transmitted list of network public keys for each of a plurality of sessions, in response to the transmitted list of network public keys,

generate a shared secret key corresponding to the network entity using the UE public key and the key index corresponding to the network public key, and

encrypt data to be transferred between the terminal and the network entity by using the generated shared secret key corresponding to the network entity.

17 . The network entity of claim 16 , wherein the list of network public keys is transmitted over one of a secured communication channel or an unsecured communication channel.

18 . The network entity of claim 17 , wherein the one or more computer programs further include computer-executable instructions that, when executed by the one or more processors, cause the network entity to:

establish a radio resource control (RRC) channel with the terminal; and

transmit, to the terminal, the list of network public keys using at least one of a registration accept message, an N1 message, and an RRC connection message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2024
From: VUPPALA, RAMESH CHANDRA; KUMAR, DIXIT; JE, DONGHYUN; SHARMA, NEHA; NIGAM, ANSHUMAN; KIM, DONGMYOUNG
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 066517/0794 →
Priority Claims (2)
IN 202341012160 · Feb 22, 2023 · national
IN 2023 41012160 · Dec 15, 2023 · national
Continuity (1)
Related Publication 20240283780A1 · Aug 22, 2024
References Cited (18)
US 5230020A · Hardy · 1993 [cited by examiner]
US 5864667A · Barkan · 1999 [cited by examiner]
US 6925182B1 · Epstein · 2005 [cited by examiner]
US 8412157B2 · Wang · 2013 [cited by examiner]
US 20050144463A1 · Rossebo · 2005 [cited by examiner]
US 20150003615A1 · Vanstone · 2015 [cited by examiner]
US 20160302061A1 · Park · 2016 [cited by examiner]
US 20180199205A1 · Zhu et al. · 2018 [cited by applicant]
US 20200084028A1 · Wang · 2020 [cited by examiner]
US 20200371777A1 · Zhang · 2020 [cited by examiner]
WO 2008005162A1 · 2008 [cited by applicant]
WO 2016163796A1 · 2016 [cited by applicant]
3GPP TR 33.969 V12.0.0, 3rd Generation Partnership Project; Technical Specification on Group Services and System Aspects; Study on Security Aspects of Public Warning System (PWS), Release 12 (2014) (Year: 2014). [cited by examiner]
ZTE, Discussion on visited network control of using null-scheme, S3-180542, 3GPP TSG SA WG3 (Security) Meeting #90, San Diego, CA, USA, Feb. 18, 2018. [cited by applicant]
ZTE, Visited network control of null-scheme, S3-180543, 3GPP TSG SA WG3 (Security) Meeting #90Bis, San Diego, CA, USA, Feb. 18, 2018. [cited by applicant]
International Search Report and Written Opinion dated May 23, 2024, issued in International Patent Application No. PCT/KR2024/002181. [cited by applicant]
3GPP TS 31.102 V17.8.0, 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Characteristics of the Universal Subscriber Identity Module (USIM) application, (Release 17), Jan. 6,… [cited by applicant]
3GPP TS 24.501 V18.1.0, Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3; (Release 18), Dec. 15, 2022. [cited by applicant]