Unified subscription identifier management in communication systems

An integrated subscription identifier data structure addresses the challenge of managing SUPI, SUCI, and IMSI in 5G networks by providing a unified format for efficient authentication and access, reducing transmission overhead and enhancing network operations.

JP2025108599APending Publication Date: 2025-07-23NOKIA TECHNOLOGIES OY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025067326
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2018-04-05
Filing Date
2025-04-16
Publication Date
2025-07-23

AI Technical Summary

Technical Problem

Existing communication systems face challenges in managing subscription identifiers such as SUPI, SUCI, and IMSI across different authentication scenarios in 5G networks, lacking an integrated structure to efficiently represent and manage these identifiers during registration and authentication procedures.

Method used

An integrated subscription identifier data structure is introduced, incorporating various fields to support multiple subscription identifier types (SUPI, SUCI, IMSI) with parameters for authentication scenarios, enabling efficient access to 5G networks by user equipment.

Benefits of technology

The integrated structure facilitates seamless representation and management of subscription identifiers, enhancing authentication efficiency and reducing transmission overhead by supporting multiple formats and encryption methods, thus improving network access operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025108599000001_ABST
    Figure 2025108599000001_ABST
Patent Text Reader

Abstract

To construct a unified subscription identifier data structure at given user equipment in a communication system.SOLUTION: A unified subscription identifier data structure includes a plurality of fields that specify information for a selected one of two or more subscription identifier types and selectable parameters associated with the selected subscription identifier type. The information in the unified subscription identifier data structure is useable by given user equipment to access one or more networks associated with a communication system based on an authentication scenario corresponding to the selected subscription identifier type.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This field generally relates to communication systems, and more specifically, although not exclusively, to user subscription identifier management within such systems.

Background Art

[0002] This section introduces aspects that can assist in promoting a better understanding of the invention. Therefore, the description in this section should be read from this perspective and should not be understood as an admission of what is in the prior art or what is not in the prior art.

[0003] The 4th generation (4G) wireless mobile communication technology, also known as Long Term Evolution (LTE) technology, has been designed to provide high-capacity mobile multimedia with high data rates, especially for human interaction. Next-generation or 5th generation (5G) technology is intended to be used not only for human interaction but also for machine-type communication in the so-called Internet of Things (IoT) networks.

[0004] 5G networks are intended to enable large-scale IoT services (e.g., a very large number of devices with limited capacity) and mission-critical IoT services (e.g., those requiring high reliability), and improvements to legacy mobile communication services are supported in the form of enhanced mobile broadband (eMBB) services that provide improved wireless Internet access to mobile devices.

[0005] In an exemplary communication system, a user equipment (such as a mobile terminal (subscriber), a 5G UE in a 5G network, or more generally a UE) communicates in a 5G network through an air interface with a base station or access point referred to as a gNB. An access point (e.g., gNB) is an exemplary part of the access network of the communication system. For example, in a 5G network, the access network is referred to as a 5G system and is described in 3GPP Technical Specification (TS) 23.501, V15.0.0, entitled "Technical Specification Group Services and System Aspects; System Architecture for the 5G System", the disclosure of which is hereby incorporated by reference in its entirety. Generally, an access point (e.g., gNB) provides access to a core network (CN) for a UE, and the CN then provides access for the UE to other UEs and / or a data network such as a packet data network (e.g., the Internet). Further, 5G network access procedures are described in 3GPP Technical Specification (TS) 23.502, VI5.1.0, entitled "Technical Specification Group Services and System Aspects; Security Architecture and Procedures for the 5G System", the disclosure of which is hereby incorporated by reference in its entirety. Still further, 3GPP Technical Specification (TS) 33.501, V0.7.0, entitled "Technical Specification Group Services and System Aspects; Security Architecture and Procedures for the 5G System", further describes details of security management associated with the 5G network, the disclosure of which is hereby incorporated by reference in its entirety.

[0006] In a 5G network, a 5G-compatible UE may include a Concealed Subscription Identifier (SUCI) as described in 3GPP TS 33.501 during the registration request procedure described in 3GPP TS 23.502. The SUCI is an encrypted form of the Subscriber Permanent Identifier (SUPI). In a legacy 4G (LTE) network, the subscription identifier used is the International Mobile Station Identifier (IMSI) defined in 3GPP Technical Specification (TS) 23.003, V15.3.0, entitled "Technical Specification Group Core Network and Terminals; Numbering, Addressing and Identification", the disclosure of which is hereby incorporated by reference in its entirety. The management of such subscription identifiers can present significant challenges.

[0007] 3GPP; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for 5G Systems (5GS); Stage 3 (Release 15) discloses how a user equipment requests and obtains a specific type of mobile identifier among existing identifier types.

[0008] International Publication No. WO2014 / 053197A1 discloses a method for policy control and further discloses an extended apparatus that enables support for user community profiles applied to multiple subscribers. Further disclosed are the generation and enforcement of community policies and charging rules derived from user community profiles and preferably introduced when establishing a session for a first user. Sessions to be established for subsequent users of multiple users may be enforced by the aforementioned community policies, and charging rules may be enabled without the need to handle them for individual criteria.

[0009] 3GPP; 23.501: SUPI terminology correction; 3GPP draft discloses a "Subscriber Permanent Identifier" such that a globally unique 5G subscriber permanent identifier (SUPI) can be assigned to each subscriber in a 5G system.

[0010] 3GPP; SA WG3; LS on Security aspects of ECIES for concealing IMSI or SUPI discloses a next-generation mobile network (referred to as 5G). A new and common term called SUPI (Subscription Permanent Identifier) is disclosed, which is proposed to be used to represent a globally unique 5G subscription permanent identifier. D4 further proposes to conceal IMSI or SUPI over the air in 5G by ECIES (Elliptic Curve Integrated Encryption Scheme). SUMMARY OF THE INVENTION

[0011] Exemplary embodiments provide an improved technique for managing subscription identifiers in a communication system.

[0012] For example, in one exemplary embodiment, the method includes the following steps. In a given user equipment in a communication system, an integrated subscription identifier data structure is constructed. The integrated subscription identifier data structure includes one selected from two or more subscription identifier types and a plurality of fields specifying information about selectable parameters associated with the selected subscription identifier type, and the information in the integrated subscription identifier data structure is based on an authentication scenario corresponding to the selected subscription identifier type and can be used by the given user equipment to access one or more networks associated with the communication system.

[0013] A further exemplary embodiment is provided in the form of a non-transitory computer-readable storage medium having executable program code embodied therein that, when executed by a processor, causes the processor to perform the above steps. Yet another exemplary embodiment includes an apparatus having a processor and a memory configured to perform the above steps.

[0014] Advantageously, between different authentication scenarios, a given user equipment utilizes the integrated subscription identifier data structure to provide an appropriate subscription identifier (e.g., SUPI, SUCI, or IMSI) and related parameters for a given authentication scenario.

[0015] These and other features and advantages of the embodiments described herein will become more apparent from the accompanying drawings and the following detailed description.

Brief Description of the Drawings

[0016]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

[0017] Embodiments are presented herein with exemplary communication systems and related technologies that provide subscription identifier management during authentication procedures and other procedures in a communication system. However, it should be understood that the claims are not limited to the specific types of communication systems and / or processes disclosed. Embodiments may be implemented in a variety of other types of communication systems using alternative processes and operations. For example, although shown in the context of a radio cellular system utilizing 3GPP system elements such as a 3GPP next-generation system (5G), the disclosed embodiments may be adapted in a direct manner to a variety of other types of communication systems.

[0018] In accordance with exemplary embodiments implemented in a 5G communication system environment, one or more 3GPP Technical Specifications (TS) and Technical Reports (TR), e.g., the 3GPP TS 23.003, 23.501, 23.502, and 33.501 referenced above, can provide further description of network elements / functions and / or operations that can interact with part of the solutions of the present invention. Other 3GPP TS / TR documents can provide other conventional details that those skilled in the art can implement. However, while being well adapted to 5G-related 3GPP standards, the embodiments are not necessarily limited to any particular standard.

[0019] Exemplary embodiments relate to subscription identifier management associated with a 5G network. Before describing such exemplary embodiments, an overall description of the main components of a 5G network is described below in the context of FIGS. 1 and 2.

[0020] FIG. 1 shows a communication system 100 in which an exemplary embodiment is implemented. It will be understood that the elements shown in communication system 100 are intended to represent the main functions provided within the system, e.g., UE access function, mobility management function, authentication function, serving gateway function, etc. In that way, the blocks shown in FIG. 1 refer to specific elements in a 5G network that provide those main functions. However, other network elements may be used to implement some or all of the main functions represented. Also, it will be understood that not all functions of the 5G network are described in FIG. 1. Rather, functions are represented to facilitate the description of the exemplary embodiments. Subsequent figures can describe some additional elements / functions.

[0021] Thus, as shown, communication system 100 includes user equipment (UE) 102 that communicates with access point (gNB) 104 via air interface 103. UE 102 may be a mobile station, and such mobile stations may include, by way of example, cellular phones, computers, or any other type of communication device. Thus, the term "user equipment" as used herein is intended to be construed broadly to include communication devices that include examples such as various different types of mobile stations, subscriber stations, or more generally, combinations of data cards inserted into other devices such as laptops or smartphones. Such communication devices are also intended to include devices commonly referred to as access terminals.

[0022] In one embodiment, UE 102 is composed of a Universal Integrated Circuit Card (UICC) portion and a Mobile Equipment (ME) portion. The UICC is the user-dependent portion of the UE and includes at least one Universal Subscriber Identity Module (USIM) and appropriate application software. The USIM securely stores the permanent subscription identifier and its associated keys used to identify and authenticate subscribers accessing the network. The ME is the user-independent portion of the UE and includes terminal equipment (TE) functions and various mobile terminal (MT) functions.

[0023] Access point 104 is an exemplary portion of the access network of communication system 100. Such an access network may include, for example, a 5G system having a plurality of base stations and one or more associated radio network control functions. The base stations and radio network control functions may be logically separate entities, but in a given embodiment, may be implemented in the same physical network element, such as a base station router or a femtocell access point.

[0024] In this exemplary embodiment, access point 104 is operatively coupled to a mobility management function 106. In a 5G network, the mobility management function is implemented by an access and mobility management function (AMF). A security anchor function (SEAF) may also be implemented by the AMF to enable the UE to securely connect to the mobility management function. As used herein, the mobility management function manages, or otherwise participates in, access and mobility (including authentication / authorization) operations with the UE (via access point 104) among other network operations, or is an element or function (i.e., entity) in the core network (CN) portion of a communication system. The AMF may also be more generally referred to herein as an access and mobility management entity.

[0025] In this exemplary embodiment, AMF 106 is operatively coupled to a home subscriber function 108, i.e., one or more functions existing in the subscriber's home network. As shown, some of those functions include an authentication server function (AUSF) along with an integrated data management (UDM) function. The AUSF and UDM (separately or collectively according to a 4G home subscriber server or HSS) may also be more generally referred to herein as an authentication entity. In addition, the home subscriber function may include, but is not limited to, a network slice selection function (NSSF), a network exposure function (NEF), a network repository function (NRF), a policy control function (PCF), and an application function (AF).

[0026] Access point 104 is also operatively coupled to a serving gateway function, i.e., a session management function (SMF) 110, which is operatively coupled to a user plane function (UPF) 112. UPF 112 is operatively coupled to a packet data network, such as the Internet 114. Further typical operations and functions of such network elements are not described herein as they are not the focus of the exemplary embodiment and can be found in appropriate 3GPP 5G documents.

[0027] This particular arrangement of system elements is for illustrative purposes only, and it should be recognized that other types and arrangements of additional or alternative elements may be used to implement a communication system in other embodiments. For example, in other embodiments, system 100 may include other elements / functions not explicitly shown herein.

[0028] Thus, the arrangement in FIG. 1 is only a configuration of one example of a wireless cellular system, and many alternative configurations of system elements may be used. For example, only a single element / function is shown in the embodiment of FIG. 1, but this is only for simplicity and clarity of explanation. Of course, a given alternative embodiment may include a greater number of such system elements, along with additional or alternative elements of the types associated with the implementation of conventional systems.

[0029] FIG. 1 also shows system elements as single functional blocks, but it should also be noted that the various sub-networks that make up a 5G network are partitioned into so-called network slices. A network slice (network partition) includes a set of network functions (NFs) (i.e., a function chain) for each corresponding service type using network function virtualization (NFV) on a common physical infrastructure. Network slices are instantiated as needed for a given service, such as an eMBB service, a massive IoT service, and a mission-critical IoT service. Thus, a network slice or function is instantiated when an instance of that network slice or function is created. In some embodiments, this involves installing or otherwise operating the network slice or function on one or more host devices of the underlying physical infrastructure. UE102 is configured to access one or more of those services via gNB104.

[0030] FIG. 2 is a block diagram of a portion of a communication system 200 that includes a user device 202 and a network element / function 204 that provides subscription identifier management as part of an authentication procedure in an exemplary embodiment. In one embodiment, the network element / function 204 may be a UDM (as described above). However, it will be appreciated that the network element / function 204 can represent any network element / function that is configurable to provide subscription identifier management and other authentication techniques described herein.

[0031] The user device 202 includes a processor 212 coupled to a memory 216 and an interface circuit 210. The processor 212 of the user device 202 includes an authentication processing module 214 that can be implemented at least in the form of software executed by the processor. The processing module 214 performs subscription identifier management and other related techniques described in connection with subsequent figures and other places herein. The memory 216 of the user device 202 includes a subscription identifier management data storage module 218 that stores data generated or otherwise used during subscription identifier management and other operations.

[0032] The network element / function 204 includes a processor 222 coupled to a memory 226 and an interface circuit 220. The processor 222 of the network element / function 204 includes an authentication processing module 224 that can be implemented at least in the form of software executed by the processor 222. The processing module 224 performs authentication techniques using the subscription identifier provided by the UE 202 and other techniques described in connection with subsequent figures and other places herein. The memory 226 of the network element / function 204 includes an authentication processing data storage module 228 that stores data generated or otherwise used during authentication operations and other operations.

[0033] Each of the processors 212 and 222 of the user equipment 202 and the network element / function 204 may include, for example, a microprocessor, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP), or other types of processing devices or integrated circuits, along with some or a combination of such elements. Along with such integrated circuit devices, some or a combination of them are examples of "circuits" as the term is used herein. In implementing exemplary embodiments, a wide variety of other arrangements of hardware and associated software or firmware may be used.

[0034] Each of the memories 216 and 226 of the user equipment 202 and the network element / function 204 may be used to store one or more software programs to be executed by the respective processors 212 and 222 so as to implement at least some of the functionality described herein. For example, subscription identifier management operations, as well as other authentication functionality described in connection with subsequent figures and elsewhere herein, may be implemented in a direct manner using software code executed by the processors 212 and 222.

[0035] Thus, a given one of the memories 216 or 226 may be regarded as an example of what is more generally referred to herein as a computer program product, or more generally still as a processor-readable storage medium having executable program code embodied therein. Other examples of processor-readable storage media may include disks or other types of magnetic media or optical media in any combination. Exemplary embodiments can include products that include such computer program products or other processor-readable storage media.

[0036] Memory 216 or 226 may more specifically include, for example, an electronic random access memory (RAM) such as a static RAM (SRAM), a dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memory such as flash memory, magnetic RAM (MRAM), phase change RAM (PC-RAM), ferroelectric RAM (FRAM). The term "memory" as used herein is intended to be construed broadly and may additionally or alternatively include, for example, a read-only memory (ROM), disk-based memory, or other types of storage devices, as well as a part or combination of such devices.

[0037] Each interface circuit 210 and 220 of user equipment 202 and network element / function 204 illustratively includes a transceiver or other communication hardware or firmware that enables the associated system elements to communicate with each other in the manner described herein.

[0038] User equipment 202 is configured to communicate with network element / function 204 via each of their interface circuits 210 and 220, and vice versa, as is clear from FIG. 2. When network element / function 204 is a UDM, the user equipment and the UDM are operably coupled (as shown in FIG. 1) via gNB 104 and AMF 106 and communicate via gNB 104 and AMF 106. This communication involves the user equipment 202 sending data to the network element / function 204 and the network element / function 204 sending data to the user equipment 202. However, in alternative embodiments, more or fewer network elements (in addition to or instead of gNB and AMF) may be operably coupled between network elements / functions 202 and 204. The term "data" as used herein is intended to be construed broadly to include any type of information that can be transmitted between a user equipment and one or more network element / functions, including but not limited to messages, identifiers, keys, indicators, user data, control data, etc.

[0039] It will be appreciated that the components of the particular arrangement shown in FIG. 2 are merely examples, and that numerous alternative configurations may be used in other embodiments. For example, any given network element / function may be configured to incorporate additional or alternative components and support other communication protocols.

[0040] Other system elements (including but not limited to other elements shown in FIG. 1) may each also be configured to include components such as a processor, memory, and network interface. Those elements need not be implemented on separate stand-alone processing platforms, but instead, for example, represent different functional parts of a single common processing platform.

[0041] Assuming the general concepts described above, exemplary embodiments addressing the problem of subscription identifier management are described herein.

[0042] As mentioned above, in a legacy 4G (LTE) communication system, the permanent subscription identifier is typically the UE's International Mobile Station Identifier, i.e., the IMSI. As defined in the referenced 3GPP TS 23.003, the IMSI consists of a Mobile Country Code (MCC), a Mobile Network Code (MNC), and a Mobile Station Identification Number (MSIN). Typically, when the subscription identifier needs to be protected, only the MSIN part of the IMSI needs to be encrypted. The MNC and MCC parts provide routing information that is used by the serving network to route to the correct home network. In a 5G communication system, the permanent subscription identifier is called the Subscriber Permanent Identifier, i.e., the SUPI. Similar to the IMSI, the SUPI may utilize the MSIN to uniquely identify the subscriber. When the MSIN of the SUPI is encrypted, it is called the Subscription Concealed Identifier, i.e., the SUCI.

[0043] However, it is understood herein that in different operating scenarios, the UE may need to represent the subscription identifier as a SUCI, a SUPI, or an IMSI. To address those issues and other subscription identifier management issues, exemplary embodiments propose an integrated representation structure for the subscription identifier.

[0044] More specifically, the exemplary embodiments address the issue of using a registration request message sent by a UE to a network and an appropriate subscription identifier representation in the UE authentication procedure in a 5G network, i.e., a SUPI or its encrypted form, the SUCI, or even the IMSI (note that the same or similar integrated data structures may be exchanged between network entities). For example, during the execution of the 5G authentication and key agreement (AKA) procedure (see, e.g., 3GPP TS 33.501 referenced above), the UE may need to present the subscription identifier in three different formats: SUCI, SUPI, or IMSI. If the authentication procedure uses the Extensible Authentication Protocol (EAP) AKA' procedure (see, e.g., 3GPP TS 33.501 referenced above), then the representation uses the network access identifier (NAI) format, i.e., "joe@example.com", as defined in Internet Engineering Task Force (IETF) Request for Comment (RFC) 7542, "The Network Access Identifier", May 2015, the disclosure of which is hereby incorporated by reference in its entirety.

[0045] The issue of different subscription identifier formats is not addressed in TS 33.501 referenced above or in any other stage 3 specification. 3GPP Technical Specification (TS) 33.401, V15.3.0, entitled "Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); System architecture", only defines the usage of the IMSI, the disclosure of which is hereby incorporated by reference in its entirety.

[0046] Figure 3A shows an IMSI format 300 that can implement one or more exemplary embodiments. As shown, format 300 includes a fixed 15-digit length and is composed of a 3-digit Mobile Country Code (MCC), a 3-digit Mobile Network Code (MNC), and a 9-digit Mobile Station Identification Number (MSIN). In some cases, the MNC may be 2 digits and the MSIN may be 10 digits. Further details regarding IMSI are defined in the above-referenced 3GPP TS 23.003.

[0047] As described above, when the authentication procedure uses the EAP-AKA’ procedure or the EAP Transport Layer Security (TLS) procedure (each defined in the above-referenced 3GPP TS 33.501), then the subscription identifier representation uses the NAI format. RFC7542 states that for 3GPP, the “username” part is a unique identifier derived from device-specific information, and the “realm” part is composed of information regarding the home network followed by the base string “3gppnetwork.org”. For example, the subscription identifier in the NAI format may be represented as follows. 234150999999999@ims.mnc015.mcc234.3gppnetwork.org

[0048] Thus, for the EAP-AKA’ procedure, the UE encodes its subscription identifier SUPI or SUCI in the NAI format as specified in RFC7542, e.g., MSIN@mnc.mcc.3gppnetwork.org.

[0049] Figures 3B and 3C respectively show a SUPI format 310 and a SUCI format 320 that can implement one or more exemplary embodiments. In this example, the SUPI format 310 includes an MCC field (3 digits), as well as an MNC field (3 digits), an MSIN, and a UDM selector (8 bits). The SUCI format 320 is an encrypted form of the SUPI format 310 and includes, as shown, an MCC field (3 digits), an MNC field (3 digits), a UDM selector field, an encrypted MSIN, and a parameter for decrypting the encrypted MSIN.

[0050] In 3GPP SA3, it has been agreed to support at least two elliptic curves, Elliptic Curve Integrated Encryption Scheme (ECIES) curve A and curve B, to encrypt the MSIN part of the SUPI while using the encryption identifier as SUCI. In subsequent releases, 3GPP may specify more or fewer curves from the elliptic curve encryption (ECC) family of curves, or may allow the use of proprietary curves to encrypt the MSIN. However, it is understood that it is preferable to use a standardized scheme, and a network operator can also decide to use its own specific encryption method. Further, especially during the transition period, a network operator can configure a device to use only a null scheme for SUCI. The null scheme is implemented to return the same output as the input, which is applied to both encryption and decryption (i.e., the MSIN is not encrypted). The null scheme is indicated by a scheme identifier in the SUCI and thus may also be presented by the integrated subscription identifier format in a similar manner.

[0051] Since the concealed subscription identifier SUCI is exchanged between the UE (102 in FIG. 1) and the UDM (part of 108 in FIG. 1) in the core network, the UDM needs to be configured to be able to understand how the UE encoded the MSIN. Thus, since no other messages are exchanged between the UE and the UDM during the authentication process, the encoding method needs to be part of the format exchanged together with the encoded output itself. Therefore, the scheme representing the SUCI needs to support a flexible representation that conforms to multiple fields, and it is understood that each field is flexible enough to support multiple options.

[0052] Exemplary embodiments address the above and other problems by providing an integrated structure for representing subscription identifiers. For example, the integrated structure in one exemplary embodiment can represent various options associated with the use of each identifier during authentication operations and other operations, along with subscription identifiers such as SUCI, SUPI, and IMSI.

[0053] FIG. 4 shows an integrated subscription identifier format (data structure) 400 according to an exemplary embodiment. Further, FIG. 5 shows an exemplary field length 500 for each field shown in the integrated subscription identifier format 400 of FIG. 4.

[0054] As shown, the integrated subscription identifier format 400 includes the following fields (with exemplary field lengths in parentheses). MCC field 402 (24 bits / 3 digits), MNC field 404 (24 bits / 3 digits), UDM selection parameter field 406 (8 bits), Encryption on / off field 408 (1 bit), KDF (key derivation function) field 410 (3 bits), Optional parameter field 412 of KDF (n bits / dependent on optional parameters), Identifier type SUPI / SUCI / IMSI field 414 (2 bits), ECIES curve selected for encryption field 416 (4 bits), Temporary public key pair field 418 (256 bits), Length field 420 of encrypted MSIN (4 bits / 128, 192, 256, 512 bits / dependent on MSIN format), MSIN or encrypted MSIN field 422 (length specified in field 420), MSIN MAC (message authentication code of MSIN field calculated using the selected ECIES curve) field 424 (256 bits), and Encryption algorithm identifier field 426 (4 bits)

[0055] It should be recognized that the field lengths described herein are essentially exemplary and thus are not intended to be limiting. Depending on the operating scenario in which the UE and 5G network function, the field lengths may be set to different values. In alternative embodiments, it should also be recognized that one or more other fields may be added to the data structure, and / or some of the above fields may be deleted, and / or simply not used. Also, the positioning of the fields within the structure format 400 in FIG. 4 is essentially exemplary, and thus in other embodiments, alternative field arrangements are contemplated. Merely by way of example, one additional field that could be part of the data structure (or could be indicated in the UDM selection or other fields) is the network slice selection assistance information (NSSAI) field.

[0056] Some exemplary embodiments result in the UE sending a complete integrated subscription identifier data structure (i.e., 400 in FIG. 4) to a given UDM (or one or more other network entities), while alternative exemplary embodiments avoid carrying parameters that are many indicators such as, for example, KDF, optional parameters of KDF, selected elliptic curve, encryption algorithm identifier, etc., so as to minimize transmission overhead. In that way, an alternative exemplary integrated subscription identifier data structure 600 is described in FIG. 6. As shown, the integrated subscription identifier format 600 includes the following fields (having exemplary field lengths in parentheses). MCC field 602 (24 bits / 3 digits), MNC field 604 (24 bits / 3 digits), UDM selection parameter field 606 (8 bits), Identifier type SUPI / SUCI / IMSI field 608 (2 bits), Length field of encrypted MSIN 610 (4 bits / 128, 192, 256, 512 bits / depending on the MSIN format), MSIN or encrypted MSIN field 612 (length specified in field 610), MSIN MAC (message authentication code of the MSIN field calculated using the selected ECIES curve) field 614 (256 bits), and Profile selection field 616 (4 bits)

[0057] The field lengths described in this specification are essentially exemplary and thus it should be recognized that they are not intended to be limiting. Depending on the operating scenario in which the UE and 5G network function, the field lengths may be set to different values. It should also be recognized that in alternative embodiments, one or more other fields may be added to the data structure, and / or some of the above fields may be removed, and / or simply not used. Also, the positioning of the fields within the structure format 600 in FIG. 6 is essentially exemplary and thus, in other embodiments, alternative field arrangements are contemplated. By way of example only, one additional field that may be part of the data structure (or may be indicated in the UDM selection or other fields) is the Network Slice Selection Assistance Information (NSSAI) field.

[0058] Fields 602 - 614 provide the same information as their similarly named counterparts in data structure 400. However, data structure 600 includes a profile selection field 616. It is understood that it may be beneficial to pre - establish specific standard profiles to be used in the integrated subscription identifier representation format between the UE and the UDM. Those agreed - upon profiles may be defined as pre - set values (by way of example only, a 4 - bit ECIES curve selected for an encryption field). In such cases, the agreed - upon values from the profile are used by the transmitting UE and UDM, avoiding the actual exchange of values for those parameters.

[0059] For example, in such a profile-based reduced field version of the integrated subscription identifier data structure, the UDM is configured to know that a given profile selection field of "0011" (when it is 4 bits) corresponds to a specific predefined setting for the field from the format of FIG. 4 that is not sent in the reduced field version of FIG. 6, and a profile selection field of "1010" means a different predefined setting, etc. Thus, the UDM pre-stores (or obtains in real time) the data structure for each possible profile that the UE may send (since the UE is configured to select different authentication scenarios).

[0060] Exemplary embodiments provide all UEs (e.g., 102 in FIG. 1), as well as network elements / functions including but not limited to gNB (104 in FIG. 1), AMF (portion of 106 in FIG. 1), SEAF (portion of 106 in FIG. 1), AUSF (portion of 108 in FIG. 1), and UDM (portion of 108 in FIG. 1) to support alternative variations along with integrated subscription identifier formats 400 and 600.

[0061] FIG. 7 shows a method 700 of utilizing an integrated subscription identifier format (e.g., data structure 400 of FIG. 4 or data structure 600 of FIG. 6) from the perspective of a UE according to an exemplary embodiment.

[0062] In step 702, the UE maintains a permanent subscription identifier (SUPI) or IMSI.

[0063] In step 704, the UE maintains its own secret key / public key pair along with the public key of the UDM.

[0064] In step 706, the UE selects parameters (algorithm, curve, etc.) for encrypting the MSIN.

[0065] In step 708, the UE constructs an integrated subscription identifier data structure (e.g., 400 in FIG. 4) using the identifier type, encryption algorithm, curve indicator, public key, encrypted MSIN, MSIN MAC, MCC, MNC, UDM selector, KDF, optional KDF parameters, etc.

[0066] In step 710, the UE transmits the integrated subscription identifier data structure to the selected UDM during a network access request (e.g., a registration request). In one embodiment, the integrated subscription identifier data structure may be the data structure 400 in FIG. 4 (i.e., the version with all fields filled), and in an alternative embodiment, the integrated subscription identifier data structure may be the data structure 600 in FIG. 6 (the profile-based reduced field version). In further alternative embodiments, other variations of the integrated subscription identifier data structure may be transmitted. The network entity (e.g., UDM) is also configured to construct or otherwise obtain / maintain such an integrated subscription identifier data structure.

[0067] FIG. 8 shows a method 800 of utilizing an integrated subscription identifier format (e.g., the data structure 400 in FIG. 4 or the data structure 600 in FIG. 6) from the perspective of a network entity (e.g., one or more of the network elements / functions described herein) according to an exemplary embodiment.

[0068] In step 802, the network entity receives the integrated subscription identifier data structure.

[0069] In step 804, the network entity decrypts the integrated subscription identifier data structure if necessary.

[0070] In step 806, the network element performs authentication of the transmitting UE based on an authentication scenario corresponding to the selected subscription identifier type in the received data structure.

[0071] Accordingly, it should be emphasized again that the various embodiments described herein are presented by way of example only and should not be construed as limiting the claims. For example, alternative embodiments may utilize different communication system configurations, user equipment configurations, base station configurations, key pair provisioning and usage processes, messaging protocols, and message formats than those described above in the context of the exemplary embodiments. Those and numerous other alternative embodiments within the scope of the appended claims will be readily apparent to those skilled in the art.

Claims

1. A user equipment (102, 202) for a wireless communication system (100, 200), wherein in the user equipment (102, 202) in the wireless communication system (100, 200), constructing an integrated subscription identifier data structure; storing the integrated subscription identifier data structure (400, 600), the integrated subscription identifier data structure (400, 600) comprising a plurality of fields (402 - 426, 602 - 616) that specify one of the selected ones of two or more subscription identifier fields (300, 310, 320) associated with a selected subscription identifier type, the storing; using the selected one of the two or more subscription identifier fields (300, 310, 320) in the integrated subscription identifier data structure (400, 600) to access one or more networks associated with the wireless communication system (100, 200) based on an authentication scenario corresponding to the selected subscription identifier type; comprising a processor (212) and a memory (216) configured to perform the above; the user equipment (102, 202).

2. The user equipment (102, 202) according to claim 1, wherein the plurality of fields (402 - 426, 602 - 616) comprise a subscription identifier type field (414, 608).

3. The user equipment (102, 202) according to claim 2, wherein the subscription identifier type is selectable from a group comprising a Secret Subscriber Identity (SUCI), a Subscriber Permanent Identifier (SUPI), and an International Mobile Subscriber Identity (IMSI).

4. The user equipment (102, 202) according to claim 1, wherein the plurality of fields (402 - 426, 602 - 616) comprise a network entity selection parameter field (406, 606).

5. The user equipment (102, 202) according to claim 4, wherein the network entity (104, 204) performs one or more of integrated data management, Unified Data Management (UDM), function, and Authentication Server Function (AUSF).

6. The user equipment (102, 202) according to claim 1, wherein the plurality of fields (402 to 426) includes an encryption on / off field (408). **Claim 7** The user equipment (102, 202) according to claim 6, wherein the plurality of fields (402 to 426) includes an encryption algorithm identifier field (426). **Claim 8** The user equipment (102, 202) according to claim 1, wherein the plurality of fields (402 to 426) includes a key derivation function field (410). **Claim 9** The user equipment (102, 202) according to claim 8, wherein the plurality of fields (402 to 426) includes a key derivation function parameter field (412). **Claim 10** The user equipment (102, 202) according to claim 1, wherein the plurality of fields (402 to 426, 602 to 616) includes a mobile country code field (402, 602). **Claim 11** The user equipment (102, 202) according to claim 1, wherein the plurality of fields (402 to 426, 602 to 616) includes a mobile network code field (404, 604). **Claim 12** The user equipment (102, 202) according to claim 1, wherein the plurality of fields (402 to 426) includes a field (416) specifying a curve selected from elliptic curve integrated encryption schemes. **Claim 13** The user equipment (102, 202) according to claim 1, wherein the plurality of fields (402 to 426) includes a temporary public key pair field (418). **Claim 14** The user equipment (102, 202) according to claim 1, wherein the plurality of fields (402 to 426, 602 to 616) includes fields (420, 610) specifying the length of an encrypted mobile station identification number, MSIN. **Claim 15** The user equipment (102, 202) according to claim 14, wherein the plurality of fields (402 to 426, 602 to 616) includes an encrypted MSIN field (422, 612). **Claim 16** The user equipment (102, 202) according to claim 14, wherein the plurality of fields (402 to 426, 602 to 616) includes an MSIN message authentication code field (424, 614). **Claim 17** The user equipment (102, 202) according to claim 1, wherein the wireless communication system (100, 200) includes a 5G system. **Claim 18** The user equipment (102, 202) according to claim 1, further comprising transmitting the integrated subscription identifier data structure (400, 600) to at least one network entity (104, 204) in the wireless communication system (100, 200) to obtain access to the one or more networks associated with the wireless communication system (100, 200).

19. The user equipment (102, 202) according to claim 1, wherein the plurality of fields (602 - 616) comprises a profile selection field (616).

20. The profile selection field (616) of the user equipment (102, 202) according to claim 19 enables notification to one or more network entities in the one or more networks associated with the wireless communication system (100, 200) to use pre - established values for one or more selectable parameters associated with the selected subscription identifier field (300, 310, 320).

21. The user equipment (102, 202) according to claim 20, further comprising transmitting the integrated subscription identifier data structure (600) having the profile selection field (616) and a set of reduced fields to at least one of the one or more network entities in the wireless communication system (100, 200) to obtain access to the one or more networks associated with the wireless communication system (100, 200).

22. In a user equipment (102, 202) in a wireless communication system (100, 200), constructing an integrated subscription identifier data structure (400, 600); Storing the integrated subscription identifier data structure (400, 600), wherein the integrated subscription identifier data structure (400, 600) comprises a plurality of fields (402 - 426, 602 - 616) specifying one of the selected ones of two or more subscription identifier fields (300, 310, 320) associated with a selected subscription identifier type; the storing; Based on an authentication scenario corresponding to the selected subscription identifier type, use the selected one of two or more subscription identifier fields (300, 310, 320) in the integrated subscription identifier data structure (400, 600) to access one or more networks associated with the wireless communication system (100, 200). A method comprising the above.

23. A non-transitory computer-readable storage medium in which executable program code is embodied, and when the executable program code is executed by a processor (212), cause the processor (212) to In a user equipment (102, 202) in a wireless communication system (100, 200), construct an integrated subscription identifier data structure (400, 600). Store the integrated subscription identifier data structure (400, 600), where the integrated subscription identifier data structure (400, 600) comprises a plurality of fields (402-426, 602-616) specifying a selected one of two or more subscription identifier fields (300, 310, 320) associated with the selected subscription identifier type, the storing. Based on an authentication scenario corresponding to the selected subscription identifier type, use the selected one of two or more subscription identifier fields (300, 310, 320) in the integrated subscription identifier data structure (400, 600) to access one or more networks associated with the wireless communication system (100, 200). The non-transitory computer-readable storage medium that causes the above to be executed.

Citation Information

Patent Citations

  • Method, device and system for authenticating to a mobile network and a server for authenticating devices to a mobile network

    WO2017092968A1