User identity privacy protection in a communication network environment

Enhanced SUCI mechanisms and temporary identifiers in 5G networks address user identity privacy issues, ensuring secure communication and authentication by concealing sensitive information and preventing unauthorized access.

WO2025233891A1PCT designated stage Publication Date: 2025-11-13NOKIA TECHNOLOGIES OY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/054856
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-09
Filing Date
2025-05-08
Publication Date
2025-11-13

AI Technical Summary

Technical Problem

Existing communication networks face challenges in protecting user identity privacy, particularly in 5G networks, due to the need for enhanced security management to prevent linkability and trackability attacks that expose sensitive user information.

Method used

Implementing an enhanced SUCI mechanism that includes a user identifier (User_ID) along with the IMSI, using a new 5G-Global Unique Temporary User Identifier (TMUI) for identification, and defining a new NAI format to protect user identity privacy during communication and exposure, along with assigning temporary identifiers for each session.

Benefits of technology

The proposed solutions effectively safeguard user identity privacy by concealing sensitive information, preventing unauthorized access and ensuring secure user authentication and service access in 5G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000026_0000
    Figure 00000026_0000
  • Figure 00000027_0000
    Figure 00000027_0000
  • Figure 00000028_0000
    Figure 00000028_0000
Patent Text Reader

Abstract

Techniques for user identity privacy protection in a communication network environment are disclosed. For example, a method includes obtaining, at the user equipment, a user identifier for a user of the user equipment, wherein the user is one or more users associated with a subscription for the user equipment. The method includes securing, by the user equipment, the user identifier and a subscription identifier for the subscription. The method includes sending, from the user equipment, the secured user identifier and subscription identifier in a request to a communication network.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] USER IDENTITY PRIVACY PROTECTION IN A COMMUNICATION NETWORK ENVIRONMENT

[0002] Field

[0003] The field relates generally to communication networks, and more particularly, but not exclusively, to security management in such communication networks.

[0004] Background

[0005] This section introduces aspects that may be helpful in facilitating a better understanding of the inventions. Accordingly, the statements of this section are to be read in this light and are not to be understood as admissions about what is in the prior art or what is not in the prior art.

[0006] Fourth generation (4G) wireless mobile telecommunications technology, also known as Long Term Evolution (LTE) technology, was designed to provide high-capacity mobile multimedia with high data rates particularly for human interaction. Next generation or fifth generation (5G) technology is intended to be used not only for human interaction, but also for machine type communications in so-called Internet of Things (loT) networks.

[0007] While 5G networks are intended to enable massive loT services (e.g., very large numbers of limited capacity devices) and mission-critical loT services (e.g., requiring high reliability), improvements over legacy mobile communication services are supported in the form of enhanced mobile broadband (eMBB) services providing improved wireless Internet access for mobile devices.

[0008] In an example communication system, user equipment (5G UE in a 5G network or, more broadly, a UE) such as a mobile terminal (subscriber) communicates over an air interface with a base station or access point of an access network referred to as a 5G AN in a 5G network. The access point (e.g., gNB) is illustratively part of an access network of the communication system.

[0009] For example, in a 5G network, the access network referred to as a 5G AN is described in 5G Technical Specification (TS) 23.501, entitled “Technical Specification Group Services and System Aspects; System Architecture for the 5G System,” and TS 23.502, entitled “Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS),” the disclosures of which are incorporated by reference herein in their entireties. In general, the access point (e.g., gNB) provides access for the UE to a core network (CN or 5GC), which then provides access for the UE to other UEs and / or a data network such as a packet data network (e.g., Internet).

[0010] TS 23.501 goes on to define a 5G Service-Based Architecture (SBA) which models services as network functions (NFs) that communicate with each other using representational state transfer application programming interfaces (Restful APIs).

[0011] Furthermore, TS 33.501, entitled “Technical Specification Group Services and System Aspects; Security Architecture and Procedures for the 5G System,” the disclosure of which is incorporated by reference herein in its entirety, further describes security management details associated with a 5G network.

[0012] Security management is an important consideration in any communication network environment. However, due to continuing attempts to improve the architectures and protocols associated with a 5G network in order to increase network efficiency and / or subscriber convenience, security management issues associated with data exchanged in the communication network environment can present a significant challenge. For example, implementing user privacy protection in the communication network environment is a technical challenge.

[0013] Summary

[0014] Illustrative embodiments provide techniques for user identity privacy protection in a communication network environment.

[0015] In one illustrative embodiment from a perspective of user equipment, a method includes obtaining, at the user equipment, a user identifier for a user of the user equipment, wherein the user is one or more users associated with a subscription for the user equipment. The method includes securing, by the user equipment, the user identifier and a subscription identifier for the subscription. The method includes sending, from the user equipment, the secured user identifier and subscription identifier in a request to a communication network.

[0016] In another illustrative embodiment from a perspective of a communication network, a method includes receiving, at a first entity of the communication network, a request from user equipment, wherein the request comprises a secured user identifier for a user of the user equipment, wherein the user is one or more users associated with a subscription for the user equipment, and a secured subscription identifier for the subscription. The first entity then processes the request based on the type of request (e.g., a registration request, a packet session establishment request, a service request, etc.). Further illustrative embodiments are provided in the form of a non-transitory computer readable medium having embodied therein executable program code that when executed by a processor causes the processor to perform the above and / or other steps, operations, and the like. Still further illustrative embodiments comprise an apparatus with a processor and a memory configured to perform the above and / or other steps, operations, and the like. Some illustrative embodiments comprise a system configured to perform the above and / or other steps, operations, and the like. Further, some illustrative embodiments comprise an apparatus or a system comprising means for performing the above and / or other steps, operations, and the like.

[0017] Advantageously, illustrative embodiments provide security techniques for protecting the privacy of one or more user identities transmitted in a communication network environment.

[0018] These and other features and advantages of embodiments described herein will become more apparent from the accompanying drawings and the following detailed description.

[0019] Brief Description of the Drawings

[0020] FIG. 1 illustrates a communication network environment with which one or more illustrative embodiments may be implemented.

[0021] FIG. 2 illustrates user equipment and entities with which one or more illustrative embodiments may be implemented.

[0022] FIG. 3 illustrates a procedure for user identity privacy protection in a communication network environment according to an illustrative embodiment.

[0023] FIG. 4 illustrates a procedure for user identity privacy protection in a communication network environment according to another illustrative embodiment.

[0024] FIG. 5 illustrates a procedure for user identity privacy protection in a communication network environment according to yet another illustrative embodiment.

[0025] FIG. 6 illustrates a procedure for user identity privacy protection in a communication network environment according to a further illustrative embodiment.

[0026] Detailed Description

[0027] Embodiments will be illustrated herein in conjunction with example communication systems and associated techniques for security management in communication systems. It should be understood, however, that the scope of the claims is not limited to particular types of communication systems and / or processes disclosed. Embodiments can be implemented in a wide variety of other types of communication systems, using alternative processes and operations. For example, although illustrated in the context of wireless cellular systems utilizing the 3rd Generation Partnership Project (3GPP) system elements such as a 3GPP next generation system (5G), the disclosed embodiments can be adapted in a straightforward manner to a variety of other types of communication systems such as 6G communication systems.

[0028] In accordance with illustrative embodiments implemented in a 5G communication system environment, one or more 3GPP technical specifications (TS) and technical reports (TR) may provide further explanation of network elements / functions and / or operations that may interact with parts of the inventive solutions, e.g., the above-referenced 3GPP TS 23.501, TS 23.502, and TS 33.501. Other 3GPP TS / TR documents may provide other details that one of ordinary skill in the art will realize, for example, TS 22.101 entitled, “Technical Specification Group Services and System Aspects; Service Aspects; Service Principles,” TS 22.115 entitled, “Technical Specification Group Services and System Aspects; Service Aspects; Charging and Billing,” TS 23.316 entitled, “Technical Specification Group Services and System Aspects; Wireless and Wireline Convergence Access Support for the 5G System (5GS),” TR 23.700-32 entitled, “Technical Specification Group Services and System Aspects; Study on User Identities and Authentication Architecture,” and Internet Engineering Task Force (IETF) Request for Comment (RFC) 7542: A. DeKok, Internet Engineering Task Force (IETF), Request for Comments: 7452, “The Network Access Identifier,” the disclosures of which are incorporated by reference herein in their entireties. Note that 3GPP TS / TR documents are non-limiting examples of communication network standards (e.g., specifications, procedures, reports, requirements, recommendations, and the like). However, while well-suited for 5G-related 3GPP standards, embodiments are not necessarily intended to be limited to any particular standards.

[0029] It is to be understood that the term 5G network, and the like (e.g., 5G system, 5G communication system, 5G environment, 5G communication environment etc.), in some illustrative embodiments, may be understood to comprise all or part of an access network and all or part of a core network. However, the term 5G network, and the like, may also occasionally be used interchangeably herein with the term 5GC network, and the like, without any loss of generality, since one of ordinary skill in the art understands any distinctions.

[0030] Prior to describing illustrative embodiments, a general description of certain main components of a 5G network will be described below in the context of FIGS. 1 and 2. FIG. 1 shows a communication system 100 within which illustrative embodiments are implemented. It is to be understood that the elements shown in communication system 100 are intended to represent some main functions provided within the system, e.g., control plane functions, user plane functions, etc. As such, the blocks shown in FIG. 1 reference specific elements in 5G networks that provide some of these main functions. However, other network elements may be used to implement some or all of the main functions represented. Also, it is to be understood that not all functions of a 5G network are depicted in FIG. 1. Rather, at least some functions that facilitate an explanation of illustrative embodiments are represented. Subsequent figures may depict some additional elements / functions (i.e., network entities).

[0031] Accordingly, as shown, communication system 100 comprises user equipment (UE) 102 that communicates via an air interface 103 with an access point 104. It is to be understood that UE 102 may use one or more other types of access points (e.g., access functions, networks, etc.) to communicate with the 5GC network other than a gNB. By way of example only, the access point 104 may be any 5G access network (gNB), an untrusted non-3GPP access network that uses an Non-3GPP Interworking Function (N3IWF), a trusted non-3GPP network that uses a Trusted Non-3GPP Gateway Function (TNGF) or wireline access that uses a Wireline Access Gateway Function (W-AGF) or may correspond to a legacy access point (e.g., eNB). Furthermore, access point 104 may be a wireless local area network (WLAN) access point as will be further explained in illustrative embodiments described herein.

[0032] The UE 102 may be a mobile station, and such a mobile station may comprise, by way of example, a mobile telephone, a computer, an loT device, or any other type of communication device. The term “user equipment” as used herein is therefore intended to be construed broadly, so as to encompass a variety of different types of mobile stations, subscriber stations or, more generally, communication devices, including examples such as a combination of a data card inserted in a laptop or other equipment such as a smart phone. Such communication devices are also intended to encompass devices commonly referred to as access terminals.

[0033] In one illustrative embodiment, UE 102 is comprised of a Universal Integrated Circuit Card (UICC) part and a Mobile Equipment (ME) part. The UICC is the user-dependent part of the UE and contains at least one Universal Subscriber Identity Module (USIM) and appropriate application software. The USIM securely stores a permanent subscription identifier and its related key, which are used to uniquely identify and authenticate subscribers to access networks. The ME is the user-independent part of the UE and contains terminal equipment (TE) functions and various mobile termination (MT) functions. Alternative illustrative embodiments may not use UICC-based authentication, e.g., a Non-Public (Private) Network (NPN).

[0034] Note that, in one example, the permanent subscription identifier is an International Mobile Subscriber Identity (IMSI) unique to the UE. In one embodiment, the IMSI is a fixed 15 -digit length and consists of a 3 -digit Mobile Country Code (MCC), a 3 -digit Mobile Network Code (MNC), and a 9-digit Mobile Station Identification Number (MSIN). In a 5G communication system, an IMSI is referred to as a Subscription Permanent Identifier (SUPI). In the case of an IMSI as a SUPI, the MSIN provides the subscriber identity. Thus, only the MSIN portion of the IMSI typically needs to be encrypted. The MNC and MCC portions of the IMSI provide routing information, used by the serving network to route to the correct home network. When the MSIN of a SUPI is encrypted, it is referred to as Subscription Concealed Identifier (SUCI). Another example of a SUPI uses a Network Access Identifier (NAI). NAI is typically used for loT communication.

[0035] The access point 104 is illustratively part of a radio access network or RAN of the communication system 100. Such a radio access network may comprise, for example, a 5G System having a plurality of base stations. Components of a radio access network may, more generally, be considered “radio access entities.”

[0036] Further, the access point 104 in this illustrative embodiment is operatively coupled to an Access and Mobility Management Function (AMF / SEAF) 106. In a 5G network, the AMF / SEAF supports, inter alia, mobility management (MM) and security anchor (SEAF) functions.

[0037] AMF / SEAF 106 in this illustrative embodiment is operatively coupled to (e.g., uses the services of) other network functions 108. As shown, some of these other network functions 108 include, but are not limited to, an Authentication Server Function (AUSF) and a Unified Data Management (UDM) function. These listed network function examples are typically implemented in the home network of the UE subscriber, further explained below. Note that, in a 5GC network, the 4G function of the HSS (home subscriber server) is split into the AUSF, UDM, and a Unified Data Repository (UDR, not expressly shown) functions. Typically, AUSF authenticates UEs and provides any needed cryptographic keys, while UDR stores the user data and UDM manages the user data.

[0038] Other network functions 108 may include network functions that can act as service producers (NFp) and / or service consumers (NFc). Note that any network function can be a service producer for one service and a service consumer for another service. Further, when the service being provided includes data, the data-providing NFp is referred to as a data producer, while the data-requesting NFc is referred to as a data consumer. A data producer may also be an NF that generates data by modifying or otherwise processing data produced by another NF. Note that NFs may, more generally, be considered “network entities.”

[0039] Note that a UE, such as UE 102, is typically subscribed to what is referred to as a Home Public Land Mobile Network (HPLMN) in which some or all of the functions 106 and 108 reside. Alternatively the UE, such as UE 102, may receive services from an NPN where these functions may reside. The HPLMN is also referred to as the Home Environment (HE). If the UE is roaming (not in the HPLMN), it is typically connected with a Visited Public Land Mobile Network (VPLMN) also referred to as a visited network, while the network that is currently serving the UE is also referred to as a serving network. In the roaming case, some of the functions 106 and 108 can reside in the VPLMN, in which case, functions in the VPLMN communicate with functions in the HPLMN as needed. However, in a non-roaming scenario, access and mobility management functions 106 and the other network functions 108 reside in the same communication network, i.e., HPLMN. Embodiments described herein, unless otherwise specified, are not necessarily limited by which functions reside in which PLMN (i.e., HPLMN or VPLMN).

[0040] The access point 104 is also operatively coupled (via one or more of functions 106 and / or 108) to a Session Management Function (SMF) 110, which is operatively coupled to a User Plane Function (UPF) 112. UPF 112 is operatively coupled to a Packet Data Network, e.g., Internet 114. Note that the thicker solid lines in this figure denote a user plane (UP) of the communication network, as compared to the thinner solid lines that denote a control plane (CP) of the communication network. It is to be appreciated that network (e.g., Internet) 114 in FIG. 1 may additionally or alternatively represent other network infrastructures including, but not limited to, cloud computing infrastructure and / or edge computing infrastructure. Further typical operations and functions of such network elements are not described here since they are not the focus of the illustrative embodiments and may be found in appropriate 3GPP 5G documentation. Note that functions shown in 106, 108, 110 and 112 are examples of network functions (NFs).

[0041] It is to be appreciated that this particular arrangement of system elements is an example only, and other types and arrangements of additional or alternative elements can be used to implement a communication system in other embodiments. For example, in other embodiments, the communication system 100 may comprise other elements / functions not expressly shown herein.

[0042] Accordingly, the FIG. 1 arrangement is just one example configuration of a wireless cellular system, and numerous alternative configurations of system elements may be used. For example, although only single elements / functions are shown in the FIG. 1 embodiment, this is for simplicity and clarity of description only. A given alternative embodiment may of course include larger numbers of such system elements, as well as additional or alternative elements of a type commonly associated with conventional system implementations.

[0043] It is also to be noted that while FIG. 1 illustrates system elements as singular functional blocks, the various subnetworks that make up the 5G network are partitioned into so-called network slices. Network slices (network partitions) are logical networks that provide specific network capabilities and network characteristics that can support a corresponding service type, optionally using network function virtualization (NFV) on a common physical infrastructure. With NFV, network slices are instantiated as needed for a given service, e.g., eMBB service, massive loT service, and mission-critical loT service. A network slice or function is thus instantiated when an instance of that network slice or function is created. In some embodiments, this involves installing or otherwise running the network slice or function on one or more host devices of the underlying physical infrastructure. UE 102 is configured to access one or more of these services via access point 104.

[0044] FIG. 2 is a block diagram illustrating computing architectures for various participants in methodologies according to illustrative embodiments. More particularly, system 200 is shown comprising user equipment (UE) 202 and a plurality of entities 204-1, . . . . , 204-N. For example, in illustrative embodiments and with reference back to FIG. 1, UE 202 can represent UE 102, while entities 204-1, . . . , 204-N can represent functions 106 and 108 (i.e., network entities such as, but not limited to, AMF, AUSF, and UDM), as well as access point 104 (i.e., radio access entity such as, but not limited to, a RAN node or gNB). It is to be appreciated that the UE 202 and entities 204-1, . . . . , 204-N are configured to interact to provide security management and other techniques described herein.

[0045] The user equipment 202 comprises a processor 212 coupled to a memory 216 and interface circuitry 210. The processor 212 of the user equipment 202 includes a security management processing module 214 that may be implemented at least in part in the form of software executed by the processor. The security management processing module 214 performs security management described in conjunction with subsequent figures and otherwise herein. The memory 216 of the user equipment 202 includes a security management storage module 218 that stores data generated or otherwise used during security management operations.

[0046] Each of the entities (individually or collectively referred to herein as 204) comprises a processor 222 (222-1, . . . , 222-N) coupled to a memory 226 (226-1, . . . , 226-N) and interface circuitry 220 (220-1, . . . , 220-N). Each processor 222 of each entity 204 includes a security management processing module 224 (224-1, . . . , 224-N) that may be implemented at least in part in the form of software executed by the processor 222. The security management processing module 224 performs security management operations described in conjunction with subsequent figures and otherwise herein. Each memory 226 of each entity 204 includes a security management storage module 228 (228-1, . . . , 228-N) that stores data generated or otherwise used during security management operations.

[0047] The processors 212 and 222 may comprise, for example, microprocessors such as central processing units (CPUs), application-specific integrated circuits (ASICs), digital signal processors (DSPs) or other types of processing devices, as well as portions or combinations of such elements.

[0048] The memories 216 and 226 may be used to store one or more software programs that are executed by the respective processors 212 and 222 to implement at least a portion of the functionality described herein. For example, security management operations and other functionality as described in conjunction with subsequent figures and otherwise herein may be implemented in a straightforward manner using software code executed by processors 212 and 222.

[0049] A given one of the memories 216 and 226 may therefore be viewed as an example of what is more generally referred to herein as a computer program product or still more generally as a computer or processor readable (non-transitory or storage) medium that has executable program code embodied therein. Other examples of computer or processor readable media may include disks or other types of magnetic or optical media, in any combination. Illustrative embodiments can include articles of manufacture comprising such computer program products or other computer or processor readable media.

[0050] Further, the memories 216 and 226 may more particularly comprise, for example, electronic random- access memory (RAM) such as static RAM (SRAM), dynamic RAM (DRAM) or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memories such as flash memory, magnetic RAM (MRAM), phase- change RAM (PC-RAM) or ferroelectric RAM (FRAM). The term “memory” as used herein is intended to be broadly construed, and may additionally or alternatively encompass, for example, a read-only memory (ROM), a disk-based memory, or other type of storage device, as well as portions or combinations of such devices.

[0051] The interface circuitries 210 and 220 illustratively comprise transceivers or other communication hardware or firmware that allows the associated system elements to communicate with one another in the manner described herein.

[0052] It is apparent from FIG. 2 that user equipment 202 and plurality of entities 204 are configured for communication with each other as security management participants via their respective interface circuitries 210 and 220. This communication involves each participant sending data to and / or receiving data from one or more of the other participants. The term “data” as used herein is intended to be construed broadly, so as to encompass any type of information that may be sent between participants including, but not limited to, identity data, key pairs, key indicators, tokens, secrets, security management messages, registration request / response messages and data, request / response messages, authentication request / response messages and data, metadata, control data, audio, video, multimedia, consent data, other messages, etc.

[0053] It is to be appreciated that the particular arrangement of components shown in FIG. 2 is an example only, and numerous alternative configurations may be used in other embodiments. For example, any given network element / function and / or access point can be configured to incorporate additional or alternative components and to support other communication protocols.

[0054] Other system elements such as access point 104, SMF 110, and UPF 112 may each be configured to include components such as a processor, memory and network interface. Also, entities such as third-party applications and network operators can participate in methodologies described herein via computing devices configured to include components such as a processor, memory and network interface. These elements and devices need not be implemented on separate stand-alone processing platforms, but could instead, for example, represent different functional portions of a single common processing platform.

[0055] More generally, FIG. 2 can be considered to represent processing devices configured to provide respective security management functionalities and operatively coupled to one another in a communication system. By way of example only, all or parts of each of UE 202 and the plurality of entities 204 (e.g., processor and memory) can be considered examples of means for performing one or more operations, one or more steps, one or more functions, one or more processes, etc. as described herein.

[0056] As mentioned above, the 3GPP TS 23.501 defines the 5GC network architecture as service-based, e.g., Service-Based Architecture (SBA). It is realized herein that in deploying different NFs, there can be many situations where an NF may need to interact with an entity external to the SBA-based 5GC network (e.g., including the corresponding PLMN(s), e.g., HPLMN and VPLMN). Thus, the term “internal” as used herein illustratively refers to operations and / or communications within the SBA-based 5GC network (e.g., SBA-based interfaces) and the term “external” illustratively refers to operations and / or communications outside the SBA-based 5GC network (non-SBA interfaces).

[0057] Given the above general description of some features of a 5GC network, problems with existing security approaches in a communication network environment and solutions proposed in accordance with illustrative embodiments will now be described herein below.

[0058] It is realized that there is a need for support of multiple user identities for a given user in a 5GC network. More particularly, it is realized there is a need for the 5GC network to be enhanced to be able to utilize such user identities in the network.

[0059] Consider two non-limiting use cases. In both use cases, one or more user identities may be associated with the subscription (i.e., identified by a SUPI) of a UE and the users require or desire different treatment (i.e., service differentiation). It is to be appreciated that, in some embodiments, the UE may be a residential gateway (RG) which provides a connection between the networked equipment within a given location (e.g., home or small office) to the 5GC network and then on to a data network such as the Internet.

[0060] The first non-limiting use case is a scenario wherein the user identity is used to identify the traffic that is sent to / from the UE. For example, this applies to the case where the user identity identifies all traffic to / from the UE (i.e., the human user case). The first use case may also include exposure aspects. For example, a network operator can provide a user authentication service and third parties can request authentication / authorization from the network operator for a particular user. The second non-limiting use case is a scenario where an identity identifies a non-3GPP device behind a UE or RG. Note that the above use cases are intended to be non-limiting examples and, thus, it is desirable to provide support for other user identities.

[0061] Thus, as illustratively used herein, a user identifier may refer to information used to identify one specific user identity, which is privacy sensitive. Such information may be referred to as user identity profile information. Thus, it is realized that during communication using a user identifier or during the exposure of user identity profile information, without proper protection against linkability and trackability attacks, the privacy sensitive information may be leaked to an undesired party so that the privacy of the user is violated. Accordingly, it is desirable for the 5GC network to provide for privacy protection of user identifiers during the communication between the UE and the network, including the procedures for user authentication and service access. The 5GC network should also provide for privacy protection during the exposure of user identity profile information by the network to entities outside the network operator domain.

[0062] Illustrative embodiments address the above and other technical challenges and / or technical deficiencies in existing security approaches in a communication network environment by providing user identity (identifier) privacy in a communication network environment. As illustratively used herein, a “user” in terms of user identity privacy protection can be one or more individuals, one or more systems or devices, or some combination thereof.

[0063] More particularly, illustrative embodiments address the above-described and other technical challenges by providing user identity privacy solutions comprising: (i) an enhanced SUCI mechanism to include a user identifier (e.g., User_ID or SUCIuser) along with the IMSI of the subscriber; (ii) an enhanced SUCI that can be sent in registration request and service request messages, as well as other use cases; (iii) a new 5G-Global Unique Temporary User Identifier (TMUI) is defined which can be used to identify the user at the network such that, when used in an unsecured way, a new TMUI can be assigned; and (iv) a new NAI format between the UE and the UDM for user identity specific purposes.

[0064] Further, in some embodiments, the UE sends the temporary identifier (e.g., TMUI) to the network in a service request, and the network identifies the UE based on this temporary identifier. Then, the network assign a new temporary identifier such that, for the next communication, the UE will use this newly assigned identifier. Thus, a new temporary identifier is assigned for each communication between the UE and the network.

[0065] As illustratively defined in the above-referenced TS 33.501, the SUCI is formatted to include a SUPI type field (e.g., value in range 0-7), a home network identifier field (e.g., format dependent on SUPI type), a routing indicator field (e.g., 1-4 digits), a protection scheme ID field (e.g., value in range 0-15), a home network public key ID field (e.g., value in range 0- 255), and a scheme output field (e.g., format dependent on protection scheme). The SUPI type field identifies the type of SUPI concealed in the SUCI and has the following field format: 0: IMSI; 1: network specific identifier (NSI); 2: global line identifier (GLI); 3: global cable identifier (GCI); and 4 to 7: spare values for future use. Accordingly, in some user identity privacy embodiments described herein, one or more of the spare values in the SUPI type field (e.g., spare value 4) can be used to specify a user identifier (e.g., User_ID) from a plurality of user identities, along with the IMSI, associated with a given user.

[0066] Given the user identity concept, several illustrative embodiments are described herein in the context of FIGS. 3-6, respectively, that depict procedures for privacy protecting the user identity.

[0067] FIG. 3 illustrates a procedure 300 for user identity privacy protection in a communication network environment according to an illustrative embodiment. As shown, procedure 300 involves a user 302, a UE 304 (including a USIM and ME), an AMF 306, and an AUSF / UDM 308.

[0068] In step 1 , user 302 sends a registration request with User_ID to the ME of UE 304.

[0069] In step 2, the ME of UE 304 send the GET IDENITY with User_ID towards the USIM of UE 304.

[0070] In step 3, the USIM of UE 304 performs the concealment of User_ID along with IMSI such that the generated SUCI (enhanced SUCI) has both User_ID and SUPI.

[0071] In step 4, the USIM of UE 304 sends the GET IDENITY response with the enhanced SUCI towards the ME of UE 304. Alternatively, the User_ID is concealed in the SUCI format in the ME of UE 304 instead of the USIM of UE 304.

[0072] In step 5, the ME of UE 304 sends a registration request with the enhanced SUCI towards AMF 306.

[0073] In step 6, AMF 306 sends the authenticate request towards AUSF / UDM 308.

[0074] In step 7, the UDM of AUSF / UDM 308 de-conceals the SUCI to retrieve the SUPI and the User_ID therefrom.

[0075] In step 8, the user authentication procedure is completed.

[0076] FIG. 4 illustrates a procedure 400 for user identity privacy protection in a communication network environment according to another illustrative embodiment. As shown, procedure 400 involves a user 402, a UE 404 (including a USIM and ME), an AMF / SMF 406, and an AUSF / UDM 408.

[0077] In step 1 , user 402 sends a registration request with User_ID to the ME of UE 404.

[0078] In step 2, the ME of UE 404 send the GET IDENITY with User_ID towards the USIM of UE 404. In step 3, the USIM of UE 404 performs the concealment of User_ID along with IMSI such that the generated SUCI (enhanced SUCI) has both User_ID and SUPI.

[0079] In step 4, the USIM of UE 404 send the GET IDENITY response with the enhanced SUCI (also referred to as SUCIuser herein) towards the ME of UE 404. Alternatively, the User_ID is concealed in the SUCI format in the ME of UE 404 instead of the USIM of UE 404.

[0080] In step 5, the ME of UE 404 sends a PDU (packet data unit) session establishment request with the enhanced SUCI and 5G-GUTI towards AMF / SMF 406. The SMF of AMF / SMF 406 sends the request (with new message content described below) to the AMF of AMF / SMF 406 for user authentication.

[0081] In step 6, the AMF of AMF / SMF 406 sends the authenticate request towards AUSF / UDM 408.

[0082] In step 7, the UDM of AUSF / UDM 408 de-conceals the SUCI to retrieve the SUPI and the User_ID therefrom.

[0083] In step 8, the user authentication procedure is completed then the PDU session is established.

[0084] The new message content sent by the SMF to the AMF in step 5 of procedure 400 above may include an Namf_UserAuthenticate_Request (e.g., new service based interface (SBI) message introduced for user ID authentication). In such a use case, the AMF is acting as an NF service producer and provides a user authentication service to a requester NF. The NF service consumer is the SMF. For this service, an Authenticate service operation is defined as an operation that allows the AMF to authenticate the user (via AUSF / UDM) and allows the SMF to inform the AMF (then to the AUSF) to remove the user authentication result in the UDM. The Authenticate service operation permits the requester NF to initiate the authentication of the user by providing to the AMF the following information: UE ID (e.g., SUPI or SUCI), the serving network name, and User_ID.

[0085] FIG. 5 illustrates a procedure 500 for user identity privacy protection in a communication network environment according to another illustrative embodiment. As shown, procedure 500 involves a user 502, a UE 504 (including a USIM and ME), and an AMF 506.

[0086] In step 1, user 502 sends a service request with a User_ID towards the ME of UE 504.

[0087] In step 2, the ME of UE 504 maps the User_ID to a 5G-GUSTI. 5G-GUSTI refers to a

[0088] Globally Unique User Temporary Identifier, which is a temporary ID for the user 502. Note that it is assumed that the ME already has a mapping table stored therein of User_ID to 5G- GUSTI.

[0089] In some illustrative embodiments, 5G-GUSTI can take the form:

[0090] <GUAMI> <5G-TMSI> <5G-TMUI> where <GUAMI> = <MCC> <MNC> <AMF Identified and <AMD Identified = <AMF Region ID> <AMF Set ID> <AMF Pointed

[0091] GUAMI is Globally Unique AMF ID. TMSI is a Temporary Mobile Subscriber Identity. TMUI is a Temporary Mobile User Identity. TMUI can function as a shortened form of 5G-GUSTI to enable a more efficient radio signaling procedure (e.g., paging and service request). For example, a UE may be paged with 5G-S-TMUI defined as:

[0092] <5G-S-TMUI> = <AMF Set ID> <AMF Pointed <5G-TMUI>.

[0093] In step 3, the ME of UE 504 sends the 5G-GUSTI along with the 5G-GUTI (Globally Unique Temporary Identifier) towards the AMF 506 as part of the service request.

[0094] In step 4, depending on the type of service request, the service request procedure is completed.

[0095] While performing the Extensible Authentication Protocol (EAP) procedure when a non- 5G capable over WEAN (N5CW) device attempts to register to 5GCN via a trusted non-3GPP access network in a selected PEMN, the N5CW device derives a NAI from the identity of the selected PLMN in the following format:

[0096] <5G_device_unique_identity>@nai.<UserID>.5gc- nn.mnc<MNC>.mcc<MCC>.3gppnetwork.org; where: a) the username part <5G_device_unique_identity> is to identify the N5CW device and contains either:

[0097] - SUCI as defined as the username part of the NAI format if the UE is not registered to 5GCN via NG-RAN; or

[0098] 5G-GUTI as defined as the username part of the NAI format, if the N5CW device is registered to 5GCN via NG-RAN; and b) the label 5gc-nn in the realm part indicates the NAI is used by N5CW devices via trusted non-3GPP access. <UserID> identifies a person registered as a user of a mobile subscription identified by the SUCI or 5G-GUTI. <MNC> and <MCC> identify the PLMN (either HPLMN or VPLMN) to which the N5CW device attempts to connect via the trusted non-3GPP access network. The NAI format of the 5G-GUTI has the form username @ realm. The username part of the NAI takes the following form: tmsi<5G-TMSI>.pt<AMF Pointer>.set<AMF Set Id>.region<AMF Region Id>

[0099] <5G-TMSI>, <AMF Pointer>, <AMF Set Id> and <AMF Region Id> are the hexadecimal strings of the 5G-TMSI, AMF Pointer, AMF Set ID and AMF Region ID. If there are less than 8 significant digits in <5G-TMSI>, “0” digit(s) shall be inserted at the left side to fill the 8 digits coding. If there are less than 2 significant digits in <AMF Pointer> or <AMF Region Id>, “0” digit(s) shall be inserted at the left side to fill the 2 digits coding of the AMF Pointer or AMF Region Id respectively. If there are less than 3 significant digits in <AMF Set Id>, “0” digit(s) shall be inserted at the left side to fill the 3 digits coding.

[0100] Example:

[0101] Assuming 5G-TMSI = 06666666 (hexadecimal), AMF Pointci- 12 (hexadecimal), AMF Set = 001 (hexadecimal), AMF Region = 48 (hexadecimal), the username part of the NAI is encoded as, e.g.: tmsi06666666.ptl2.set001.region48

[0102] The NAI for an N5CW device in a PLMN (either HPLMN or VPLMN) with MNC=012 and MCC=345. to which the N5CW device attempts to connect via the trusted non-3GPP access, e.g.: tmsi06666666.ptl2.set001.region48@nai.5gc-nn.mnc012.mcc345.3gppnetwork.org useridentityanonymous@nai.useridentity.5gc-nn.mnc012.mcc345.3gppnetwork.org useridentity anonymous @ nai.userid.5gc-nn.mnc012. mcc345.3gppnetwork.org userid or useridentity identifies a person registered as a user of a mobile subscription identified by the SUCI or 5G-GUTI.

[0103] Useridentityanonymous is the anonymous user identity used to support privacy during EAP authentication.

[0104] For NAI format of SUCI, when the SUPI is defined as a Network Specific Identifier, the SUCI takes the form of an NAI. In this case, the NAI format of the SUCI has the form username @ realm, where the realm part is identical to the realm part of the Network Specific Identifier. In stand-alone non-public network (SNPN) scenarios, the realm part of the NAI may include MCC, MNC and the network ID (NID) of the SNPN.

[0105] When the SUPI is defined as an IMSI, the SUCI in NAI format shall have the form username @ realm, where the realm part shall be constructed by converting the leading digits of the IMSI, i.e., MNC and MCC, into a domain name, as described in clause 28.2. In stand-alone non-public network (SNPN) scenarios, the realm part additionally includes the NID of the SNPN, if available. The resulting realm part of the NAI is in the form, e.g.: useridentity.5gc.mnc<MNC>.mcc<MCC>.3gppnetwork.org, or useridentity.5gc.nid<NID>.mnc<MNC>.mcc<MCC>.3gppnetwork.org (for SNPN scenarios where the NID is available).

[0106] User identity is adapted for the PLMN use case and also for SNPN scenarios.

[0107] FIG. 6 illustrates a procedure 600 for user identity privacy protection in a communication network environment according to an illustrative embodiment. As shown, procedure 600 involves a user-A 602, a UE-B 604, an AMF 606, an AUSF 608, and a UDM 610.

[0108] In step 1, UE-B 604 is authenticated and registered in the network as defined in the above-referenced TS 33.501 and TS 23502.

[0109] In step 2, user-A 602 is attached / linked with UE-B 604 and provides User_ID.

[0110] In step 3, UE-B 604 generates the SUCIuser with UE credentials. For SUCIuser, a new SUCI type is used where SUPI and User_ID are concatenated.

[0111] In step 4, UE-B 604 sends a NAS Registration request with 5G-GUTI of the subscriber and SUCIuser of the user to AMF 606. Note that if AMF 606 finds that the 5G-GUTI is unknown, then AMF 606 initiates primary authentication of the subscriber and then after successful completion of primary authentication, the steps below are performed.

[0112] In step 5, AMF 606 sends Nausf_UE Authentication- Authenticate Request with the SUPI of the subscriber and SUCIuser of the user to AUSF 608 selected for UE-B 604.

[0113] In step 6, AUSF 608 sends Nudm_UEAuthentication_Authentication Get request to UDM 610 with SUPI and SUCIuser.

[0114] In step 7, UDM 610 de-conceals the SUCIuser and retrieves the User_ID.

[0115] In step 8, AUSF 608 / UDM 610 perform the user authentication procedure.

[0116] In an alternative embodiment, authentication, authorization and accounting (AAA) based authentication can be performed where UDM 610 provides the User_ID to AUSF 608 and AUSF 608 provides User_ID to an AAA-S server (not expressly shown) and AAA-S server performs the authentication.

[0117] In step 9, once authentication is successful, then AUSF 608 provides User_ID to AMF

[0118] 606. In step 10, based on authentication being successful, AMF 606 generate a new type of 5G-GUTI that includes user and UE information and provides it to UE-B 604. UE-B 604 uses this new 5G-GUTI in further communications.

[0119] Note that similar procedures can be executed if user authentication is performed at the PDU session level where SUCIuser can be provided at a PDU session request and accordingly, AMF / SMF performs the authentication.

[0120] Advantageously, as described herein, illustrative embodiments provide solutions for authentication and authorization of a user of a UE in addition to its mobile subscription, wherein one or more persons are registered as authorized users of the mobile subscription, and wherein protection is provided against privacy attacks based on unauthorized entities capturing messages between the UE and a PLMN comprising user IDs. Accordingly, illustrative embodiments protect user privacy while enabling authentication and authorization of a current user of a UE in addition to a mobile subscription when a UE registers to a network, establishes a PDU session or changes from 5GMM-IDLE mode to 5GMM-CONNECTED mode, with minimal changes to connection management protocols and messages between a UE and a PLMN, wherein one or more persons can be authorized to use a mobile subscription.

[0121] More particularly, illustrative embodiments introduce extended and / or new identifiers for mobile subscriptions, e.g.:

[0122] (i) The existing subscription concealed identifier (SUCI) format is enhanced to include a user identifier in addition to an IMSI, both encrypted to avoid exposing a permanent identifier of the user, and which can be sent in registration request and service request messages.

[0123] (ii) 5G-Global Unique Temporary User Identifier (5G-GUSTI) and its shortened form (5G-S-TMUI) are introduced and can be used as temporary identifiers for identifying a user in signaling between 5GS entities without exposing a permanent identifier of the user. When a 5G-GUSTI or 5G-S-TMUI has been used in an unsecured way, it will be re-assigned.

[0124] (iii) A 5G-GUTI NAI format comprising a user identifier is introduced, for use in EAP authentication procedure between a non-5G capable WLAN device (N5CW) and a 5G core network via a trusted non-3GPP access network (TNAN).

[0125] Further, illustrative embodiments introduce extensions for registering a user identifier together with a mobile subscription identifier in the UDM, e.g.:

[0126] (i) Extensions to a registration request according to the above-referenced TS 24.501.

[0127] (ii) Extensions to a PDU session establishment request according to the abovereferenced TS 24.501. Still further, illustrative embodiments introduce extensions to the service request procedure in the above-referenced TS 24.501 to include an indication of user ID when a UE changes from 5GMM-IDLE mode to 5GMM-CONNECTED mode.

[0128] Advantageously, illustrative embodiments enable authorized network entities to determine an individual user associated with mobile network resources allocated to a UE, such as a registrations to the network, changes from idle to connected mode, and establishment of PDU sessions, without requiring changes to existing NAS protocols or message formats other than extensions / additions of mobile subscription identifiers, while protecting users from privacy attacks based on unauthorized entities capturing messages between a UE and the network comprising user identifiers.

[0129] By way of example, in some embodiments, an apparatus comprises at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: obtain a user identifier for a user of the apparatus, wherein the user is one or more users associated with a subscription for the apparatus; secure the user identifier and a subscription identifier for the subscription; and send the secured user identifier and subscription identifier in a request to a communication network.

[0130] In some embodiments, the user identifier (e.g., User_ID) and subscription identifier are secured in a subscription concealed identifier (e.g., SUCI) sent in the request.

[0131] In some embodiments, the subscription concealed identifier is in a network access identifier (e.g., NAI) format.

[0132] In some embodiments, the subscription identifier is a subscription permanent identifier (e.g., SUPI) wherein the user identifier is concatenated with the SUPI.

[0133] In some embodiments, the request comprises a registration request (e.g., a non-access stratum (NAS) registration request).

[0134] In some embodiments, the request comprises a packet session establishment request (e.g., a PDU session establishment request).

[0135] In some embodiments, the request comprises a service request wherein the user identifier is a globally unique temporary identifier mapped to an identity of the user (e.g., GUSTI). The globally unique temporary identifier changes after each communication between the apparatus and the communication network.

[0136] In some embodiments, securing the user identifier and the subscription identifier for the subscription further comprises a mobile equipment portion of the apparatus concealing the user identifier and the subscription. In some embodiments, securing the user identifier and the subscription identifier for the subscription further comprises a universal subscriber identity module portion of the apparatus concealing the user identifier and the subscription identifier.

[0137] In some embodiments, the apparatus is part of user equipment connected to the communication network.

[0138] In some embodiments, a method comprises: obtaining, at user equipment, a user identifier for a user of the user equipment, wherein the user is one or more users associated with a subscription for the user equipment; securing, by the user equipment, the user identifier and a subscription identifier for the subscription; and sending, from the user equipment, the secured user identifier and subscription identifier in a request to a communication network.

[0139] Furthermore, in some embodiments, a system comprises at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the system at least to: receive, at a first entity of a communication network, a request from user equipment, wherein the request comprises a secured user identifier for a user of the user equipment, wherein the user is one or more users associated with a subscription for the user equipment, and a secured subscription identifier for the subscription.

[0140] In some embodiments, the system is further caused to send an authentication request from the first entity to a second entity of the communication network in response to receipt of the request from the user equipment.

[0141] In some embodiments, the system is further caused to obtain the user identifier from the authentication request to enable the second entity to authenticate the user along with the subscription.

[0142] In some embodiments, the first entity is an access and mobility management entity (e.g., AMF) and the second entity is an authentication entity (e.g., AUSF, AAA server).

[0143] In some embodiments, the first entity is a session management entity (e.g., SMF) and the second entity is an access and mobility management entity (e.g., AMF).

[0144] As used herein, it is to be understood that the term “communication network” in some embodiments can comprise two or more separate communication networks. Further, the particular processing operations and other system functionality described in conjunction with the diagrams described herein are presented by way of illustrative example only and should not be construed as limiting the scope of the disclosure in any way. Alternative embodiments can use other types of processing operations and messaging protocols. For example, the ordering of the steps may be varied in other embodiments, or certain steps may be performed at least in part concurrently with one another rather than serially. Also, one or more of the steps may be repeated periodically, or multiple instances of the methods can be performed in parallel with one another.

[0145] It should again be emphasized that the various embodiments described herein are presented by way of illustrative example only and should not be construed as limiting the scope of the claims. For example, alternative embodiments can utilize different communication system configurations, user equipment configurations, base station configurations, provisioning and usage processes, messaging protocols and message formats than those described above in the context of the illustrative embodiments. These and numerous other alternative embodiments within the scope of the appended claims will be readily apparent to those skilled in the art.

Claims

Claims:

1. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: obtain a user identifier for a user of the apparatus, wherein the user is one or more users associated with a subscription for the apparatus; secure the user identifier and a subscription identifier for the subscription; and send the secured user identifier and subscription identifier in a request to a communication network.

2. The apparatus of claim 1, wherein the user identifier and subscription identifier are secured in a subscription concealed identifier sent in the request.

3. The apparatus of claim 2, wherein the subscription concealed identifier is in a network access identifier format.

4. The apparatus of claim 2, wherein the subscription identifier is a subscription permanent identifier.

5. The apparatus of claim 4, wherein the user identifier is concatenated with the subscription permanent identifier.

6. The apparatus of claim 1, wherein the request comprises a registration request.

7. The apparatus of claim 1, wherein the request comprises a packet session establishment request.

8. The apparatus of claim 1, wherein the request comprises a service request.

9. The apparatus of claim 8, wherein the user identifier is a globally unique temporary identifier mapped to an identity of the user.

10. The apparatus of claim 9, wherein the globally unique temporary identifier changes after each communication between the apparatus and the communication network.

11. The apparatus of claim 1, wherein securing the user identifier and the subscription identifier for the subscription further comprises a mobile equipment portion of the apparatus concealing the user identifier and the subscription.

12. The apparatus of claim 1, wherein securing the user identifier and the subscription identifier for the subscription further comprises a universal subscriber identity module portion of the apparatus concealing the user identifier and the subscription identifier.

13. The apparatus of claim 1, wherein the apparatus is part of user equipment connected to the communication network.

14. A method comprising: obtaining, at user equipment, a user identifier for a user of the user equipment, wherein the user is one or more users associated with a subscription for the user equipment; securing, by the user equipment, the user identifier and a subscription identifier for the subscription; and sending, from the user equipment, the secured user identifier and subscription identifier in a request to a communication network.

15. A system comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the system at least to: receive, at a first entity of a communication network, a request from user equipment, wherein the request comprises a secured user identifier for a user of the user equipment, wherein the user is one or more users associated with a subscription for the user equipment, and a secured subscription identifier for the subscription.

16. The system of claim 15, wherein the user identifier and subscription identifier are secured in a subscription concealed identifier sent in the request.

17. The system of claim 16, wherein the subscription concealed identifier is in a network access identifier format.

18. The system of claim 16, wherein the subscription identifier is a subscription permanent identifier.

19. The system of claim 18, wherein the user identifier is concatenated with the subscription permanent identifier.

20. The system of claim 15, wherein the request comprises a registration request.

21. The system of claim 15, wherein the request comprises a packet session establishment request.

22. The system of claim 15, wherein the request comprises a service request.

23. The system of claim 22, wherein the user identifier is a globally unique temporary identifier mapped to an identity of the user.

24. The system of claim 23, wherein the globally unique temporary identifier changes after each communication between the user equipment and the communication network.

25. The system of claim 15, wherein the system is further caused to send an authentication request from the first entity to a second entity of the communication network in response to receipt of the request from the user equipment.

26. The system of claim 25, wherein the system is further caused to obtain the user identifier from the authentication request to enable the second entity to authenticate the user along with the subscription.

27. The system of claim 25, wherein the first entity is an access and mobility management entity and the second entity is an authentication entity.

28. The system of claim 25, wherein the first entity is a session management entity and the second entity is an access and mobility management entity.

Citation Information

Patent Citations

  • Method and system for handling of closed access group related procedure

    US20200396673A1