A method for establishing a secure communication channel between a mobile device and and a gnb of a visited network and corresponding equipment

The method of using a SLICI with an Alternate SUPI and real SUPI to establish secure communication channels in 5G networks addresses the privacy concerns of mobile devices during roaming, ensuring confidentiality and enabling lawful interception.

WO2025125095A1PCT designated stage expired Publication Date: 2025-06-19THALES DIS FRANCE SA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/084986
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-13
Filing Date
2024-12-06
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

In 5G networks, the privacy of mobile devices is compromised when using temporary identifiers, as they can be intercepted by adversaries, and there is no effective solution to maintain privacy during roaming without preventing lawful interception.

Method used

A method is proposed to establish a secure communication channel between a mobile device and a gNB of a visited network by using a Subscription Concealed Identifier (SLICI) containing an Alternate Subscription Permanent Identifier (ASUPI) and a real SUPI. This method involves decrypting the SLICI to retrieve the ASUPI and real SUPI, performing mutual authentication, and deriving keys to establish a secure communication channel.

Benefits of technology

This solution effectively maintains the privacy of mobile devices by preventing the disclosure of real SUPIs to visited networks, while still allowing for lawful interception and ensuring secure communication channels are established.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024084986_19062025_PF_FP_ABST
    Figure EP2024084986_19062025_PF_FP_ABST
Patent Text Reader

Abstract

The invention concerns a method for establishing a secure communication channel between a mobile device (104) collaborating with a secure element (102) and a gNB of a visited network. The method comprises sending from the mobile device (104) to an equipment (104) of a home network of the secure element (102), a Subscription Concealed Identifier (SUCI). The SUCI comprises an Alternate Subscription Permanent Identifier (SUPI) and a real SUPI of the secure element (102). The method comprises, at the equipment (104), retrieving the Alternate SUPI and the real SUPI by decrypting the SUCI. The method comprises performing a mutual authentication between the secure element (102) and the equipment (104) by using the real SUPI according to 3GPP TS 33.501. The method comprises sending from the equipment (104), the Alternate SUPI and a key KSEAF. The method comprises establishing the secure communication channel between the mobile device (104).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] A method for establishing a secure communication channel between a mobile device and a gNB of a visited network and corresponding equipment

[0002] FIELD OF THE INVENTION

[0003] The present invention concerns telecommunication systems and more precisely 5G networks where a mobile device, like a smartphone, a PDA, a PC, or an loT device like a watch for example, enters in a roaming network. The roaming network can be a public or a private network.

[0004] BACKGROUND

[0005] A mobile device typically cooperates with a secure element like a SIM card, a UICC card (removable secure element), or an eSE (embedded Secure Element) like an eUlCC (embedded UICC) or an iUICC (integrated UICC). In the case of an loT device, the secure element is called a MIM (Mobile Information Management) module.

[0006] In telecommunication systems, network operators allocate to each secure element a unique identifier, known up to the 4G as an IMSI (International Mobile Subscriber Identity) and for the 5G as a SUPI (Subscription Permanent Identifier). As authentication between a user and its network provider is based on a shared symmetric key, it can only take place after user identification. However, if the IMSI / SUPI values are sent in plaintext over the radio access link, then users can be identified, located and tracked using these permanent identifiers.

[0007] To avoid this privacy breach, the secure element is assigned temporary identifiers (called Temporary Mobile Subscriber Identity (TMSI) until 3G systems and GUTI for 4G and 5G systems) by the visited network. These frequently changing temporary identifiers are then used for identification purposes over the radio access link. However, there are certain situations where authentication through the use of temporary identifiers is not possible e.g., when a user registers with a network for the first time and is not yet assigned a temporary identifier, another case is when the visited network is unable to resolve the IMSI / SUPI from the presented TMSI / GUTI. An active man-in-the-middle adversary can intentionally simulate this scenario to force an unsuspecting user to reveal its long-term identity. These attacks are known as “IMSI catching” attacks and persist in today’s mobile networks including the 4G LTE / LTE-Adv.

[0008] In 5G systems, 3GPP security specifications do not allow plain-text transmissions of the SlIPI over the radio interface. Instead, an Elliptic Curve Integrated Encryption Scheme (ECIES) - based privacy-preserving identifier containing the concealed SLIPI is transmitted. This concealed SLIPI is known as SlICI (Subscription Concealed Identifier).

[0009] A SLIPI is a 5G globally unique Subscription Permanent Identifier allocated to each subscriber and defined in 3GPP specification TS 23.501. The SLIPI value is provisioned in the secure element and in the UDM / UDR function in 5G Core.

[0010] A valid SLIPI can be either of the following:

[0011] ■ An IMSI (International Mobile Subscriber Identifier) as defined in TS 23.503 for 3GPP RAT;

[0012] ■ A NAI (Network Access Identifier) as defined in RFC 4282 based user identification as defined in TS 23.003 for non-3GPP RAT.

[0013] A SLIPI is usually a string of 15 decimal digits. The first three digits represent the Mobile Country Code (MCC) while the next two or three form the Mobile Network Code (MNC) identifying the network operator. The remaining (nine or ten) digits are known as Mobile Subscriber Identification Number (MSIN) and represent the individual user of that particular operator. SLIPI is equivalent to IMSI which uniquely identifies the subscriber. The SLIPI can be based on the IMSI or be a real NAI (which length is not predefined).

[0014] The SLICI is a privacy preserving identifier containing the concealed SLIPI. The UE (ME+ secure element) generates a SLICI using an EClES-based protection scheme with the public key of the Home Network that was securely provisioned to the IISIM (secure element) during the IISIM personalization.

[0015] Only the MSIN part of the SLIPI gets concealed by the protection scheme while the home network identifier e.g., MCC / MNC is transmitted in plain text (in case of a SLIPI having the format of a NAI, a MCC / MNC is not mandatory). IMSI privacy has been designed to provide privacy on the air interface against IMSI catcher. But for lawful interception reasons, when a subscriber is roaming, the home network must provide to the visited network the SlIPI in clear (to ensure that the provided SlIPI is the correct one, the SUPI is used as input for the AMF key (KAMF) derivation).

[0016] This could be problematic when the UE is connected to a roaming network for the case of applications where anonymity is more important that lawful intercept or when there is concern with the visited network (like the core network of visited PLMN is equipped with network elements from banned vendors in home PLMN).

[0017] Because of 3GPP requirements, the problem is that it is not possible to keep privacy in a roaming (visited) network which is a problem because the visited network can be used to eavesdrop the UE.

[0018] U.S. Patent Application Publication No. US 2018 / 020351 A1 describes a method for authentication with a privacy identity.

[0019] Non-patent literature entitled “Protecting IMSI and User Privacy in 5G Networks”, describes a method for protecting the IMSI by means of establishing a pseudonym between a user equipment a the home network.

[0020] Non-patent literature entitled “5G report to be checked for LI”, describes a 5G report on Lawful Interception.

[0021] To solve this privacy problem, it is possible to change the IMSI to enable full anonymity (SUCI is concealing the SUPI which contains the IMSI). However, this solution prevents the home network to identify the UE.

[0022] SUMMARY

[0023] The present invention proposes a solution to this problem. More precisely, the invention proposes a method for establishing a secure communication channel between a mobile device collaborating with a secure element and a gNB of a visited network. The method comprises sending from the mobile device to an equipment of a home network of the secure element, a Subscription Concealed Identifier (SlICI) comprising an Alternate Subscription Permanent Identifier (SlIPI) and a real SlIPI of the secure element. The method further comprises, at the equipment, retrieving the Alternate SLIPI and the real SLIPI by decrypting the SLICI. The method comprises performing a mutual authentication between the secure element and the equipment by using the real SLIPI. The method comprises sending from the equipment to the Access and Mobility Management Function (AMF) or a Security Anchor Function AMF / SEAF of the visited network, the Alternate SLIPI and a key KSEAF. Furthermore, the method comprises establishing the secure communication channel between the mobile device and the gNB by, at the AMF / SEAF, deriving a key KAMF from the key KSEAF and the Alternate SLIPI, at the AMF / SEAF, deriving a key KgNB from the key KAMF and, at the mobile device, deriving the key KgNB from the keys CK, IK of the secure element and the Alternate SLIPI.

[0024] According to some example embodiments, Alternate SLIPI is a random SLIPI or a SLIPI chosen in a range of predefined Alternate SLIPIs or a SLIPI previously transmitted by the equipment.

[0025] According to some example embodiments, the Alternate SLIPI is a SLIPI sent by the equipment to the secure element during a previous registration of the secure element at the equipment in a Steering of Alternate Control Plane (SoR CP) container.

[0026] According to some example embodiments, the equipment is an Authentication credential Repository and Processing Function (ARPF) I Unified Data Management (UDM) I Subscription Identifier De-concealing Function (SIDF).

[0027] According to some example embodiments, the mobile device transmits a request for an identity of the secure element and the secure element sends the SUCI comprising the Alternate SUPI and the real SUPI of the secure element.

[0028] According to some example embodiments, the sending of the SUCI from the mobile device to the equipment of the home network of the secure element is performed through the visited network. Some example embodiments disclosed herein provide an equipment of a home network of a secure element, the secure element cooperating with a mobile device, the equipment being configured for receiving from the mobile device a Subscription Concealed Identifier (SlICI) comprising an Alternate Subscription Permanent Identifier (SlIPI) and a real SlIPI of the secure element. The system is further configured for retrieving the Alternate SLIPI and the real SLIPI by decrypting the SLICI. The system is also configured for performing a mutual authentication between the secure element and the equipment by using the real SLIPI. Furthermore, the system is configured for sending to an Access and Mobility Management Function (AMF) or a Security Anchor Function (SEAF) of a network visited by the mobile device, the Alternate SLIPI and a key KSEAF, in order to allow a gNB of the visited network to establish a secure communication channel between the mobile device and the gNB by, at the AMF / SEAF, deriving a key KAMF from the key KSEAF and the Alternate SLIPI, at the AMF / SEAF, deriving a key KgNB from the key KAMF, and, at the mobile device, deriving the key KgNB from the keys CK, IK of the secure element and the Alternate SLIPI.

[0029] BRIEF DESCRIPTION OF THE DRAWINGS

[0030] The present invention will be better understood by reading the following description of the figures that represent an example of a flowchart of messages exchanged between different entities of 5G networks (figure 1) and a method for establishing a secure communication channel between a mobile device collaborating with a secure element and a gNB of a visited network (figure2).

[0031] DETAILED DESCRIPTION

[0032] Figure 1 illustrates an example of a flowchart of messages exchanged between different entities of 5G networks. This flowchart represents a preferred implementation of the invention but can be conducted in other ways.

[0033] In figure 1 , a visited network 112 and a home network 114 are represented. The home network 114 is the network chosen by a subscriber who owns the secure element.

[0034] In the visited network 112, a mobile device 104 (here noted ME standing for Mobile Equipment) collaborating with a secure element 102 (here noted UICC standing for Universal Integrated Circuit Card) is present. The terms “device” and “equipment” related to reference 104 are used interchangeably in the following description. The visited network comprises a gNB (gNodeB) 106 (a base station for 5G networks) and an AMF / SEAF (Access and Mobility Management Function I Security Anchor Function) 108. The SEAF is usually collocated with the AMF and the gNB 106 is linked to the AMF / SEAF 108.

[0035] The home network 114 comprises an equipment 110 comprising an ARPF / UDM / SIDF (Authentication credential Repository and Processing Function I Unified Data

[0036] Management (equivalent to a HSS in 4G) I Subscription Identifier De-concealing Function) 110.

[0037] The first exchanged message 122 is a read I MSI or NAI (SUPI) command transmitted from the ME 104 to the UICC 102.

[0038] At step 124, the UICC 102 answers by transmitting an Alternate SUPI to the ME 104. This Alternate SUPI is different from the real SUPI of the UICC 102.

[0039] The generation or transmission of the Alternate SUPI is done before registration to the visited network 112, the EF_IMSI / EF_NAI file is updated with this value and the UICC requests to the ME to retrieve it by a Refresh operation.

[0040] The Alternate SUPI can be: a random SUPI, or a SUPI chosen in a range of predefined Alternate SUPIs, or a SUPI previously transmitted by the equipment 110, but in any case, not the real (genuine) SUPI of the UICC 102.

[0041] More generally, the Alternate SUPI generation can be: either random from a range (like an ephemeral IMSI as described in EP-3.358.868 A1). But there is a risk of detection by an anti-clone mechanism of the visited network (in case a same Alternate SUPI used simultaneously or in too far locations in a short time frame); - Or deterministic:

[0042] Based on a predefined list, or

[0043] The next Alternate SUPI to use is sent by the home network 114 to the secure element 102 during registration thanks to for example a SoR CP container (Steering of Alternate Control Plane). In this case, the SoR CP is used to allow the UDM to provide to the card, at the end of a registration N, the Alternate SlIPI that the card must use during its next registration N+1. That is to say that the Alternate SLIPI is a SLIPI sent by the equipment 110 to the secure element 102 during a previous registration of the secure element 102 at the equipment 110 in a SoR CP container.

[0044] At step 126, the ME 104 requests the identity of the IIICC 102 and, at step 128, the IIICC 102 replies by sending a SlICI comprising an Alternate SLIPI and the real SLIPI of the secure element.

[0045] The ME 104, at this stage, owns the Alternate SLIPI and the real SLIPI of the IIICC 102, encrypted in the SLICI.

[0046] A step 130, the mobile device 104 sends to an equipment of the home network 114, through the AMF / SEAF 108 of the visited network 112 (step 132), this SLICI.

[0047] At step 120, the equipment 110 of the home network 114 (here an ARPF / UDM / SIDF) retrieves the Alternate SLIPI and the real SLIPI by decrypting the SLICI received at step 132. The SIDF performs the decryption of the SLICI.

[0048] A mutual authentication (step 134) between the secure element 102 and the equipment 110 can then be performed by using the key retrieved in the equipment 110 thanks to the real SLIPI according to 3GPP TS 33.501.

[0049] At step 138, the equipment 110 sends to the AMF / SEAF 108 of the visited network 112 the Alternate SLIPI and a key KSEAF. This key KSEAF is an anchor key derived by the ME 104 and ALISF (Authentication Server Function) from KAUSF. The exchanges between the AMF / SEAF 108 and the ARPF / UDM / SIDF 110 are protected by using a VPN.

[0050] The AUSF is linked to the UDM of the home network 114. It is responsible for verifying the identity of a subscriber, validating its subscription data, and determining the appropriate security context for the subscriber. One of the primary functions of the ALISF is to support 5G authentication and authorization procedures. When a subscriber attempts to connect to a 5G network, the ALISF verifies its identity and ensures that it has the proper authorization to access the network.

[0051] The ALISF interacts with the Access and Mobility Management Function (AMF) to manage subscriber mobility and handover procedures. It also interacts with the Unified Data Management (UDM) function to manage subscriber data and profiles.

[0052] At step 118, the AMF / SEAF 108: derives a key KAMF from the key KSEAF and the Alternate SUPI; derives a key KgNB from the key KAMF (the key KAMF is stored in the AMF / SEAF 108).

[0053] In parallel, after or before step 118, at step 116 the mobile device or equipment 104 derives the key KgNB from the keys CK, IK of the secure element 102 and the Alternate SUPI.

[0054] At this stage, the visited network only owns the Alternate SUPI with which it can establish a secured communication between the gNB 106 and the ME 104 (step 136). On his side, the ME uses the Alternate SUPI to establish this secured communication with the gNB 106. A secure communication channel has thus been established between the mobile device 104 and the gNB 106 of the visited network 112.

[0055] In a nutshell, the home network 114 uses the real SUPI of the secure element 102 for identifying the UE and the visited network 112 uses the Alternate SUPI of the secure element 102 for identifying the UE. Therefore, the real SUPI of the secure element 102 is never disclosed to the visited network 112 and confidentiality is preserved.

[0056] The equipment 110 is preferably an ARPF / UDM / SIDF but any other equipment performing the same functions can be used instead.

[0057] The invention also concerns an equipment 110 of a home network 114 of a secure element 102, the secure element 102 cooperating with a mobile device 104, the equipment 110 being configured for: receiving from the mobile device 104 a SUCI comprising an Alternate SUPI and the real SUPI of the secure element 102; retrieving the Alternate SUPI and the real SUPI by decrypting the SUCI; sending to an AMF / SEAF 108 of a network 112 visited by the mobile device 104 the Alternate SlIPI and a key KSEAF in order to allow a gNB 106 of the visited network 112 to establish a secure communication channel between the mobile device 104 and the gNB 106 by: o at the AMF / SEAF 108, deriving a key K MF from the key KSEAF and the Alternate SLIPI; o at the AMF / SEAF 108, deriving a key KgNB from the key KAMF; o at the mobile device 104, deriving the key KgNB from the keys CK, IK of the secure element 102 and the Alternate SLIPI.

[0058] The periodicity of re-registration with a new Alternate SLIPI is preferably a mix of:

[0059] - Timing (randomly in a defined each)

[0060] - Location evolution

[0061] - End user manual action.

[0062] Figure 2 illustrates a method 200 for establishing a secure communication channel between a mobile device collaborating with a secure element and a gNB of a visited network.

[0063] At step 202, the mobile device 104 sends its SlICI to an equipment 110 of a home network 114 of the secure element 102. The SLICI comprises an Alternate Subscription Permanent Identifier, Alternate SLIPI, and a real SLIPI of the secure element.

[0064] At step 204, the equipment 110 retrieves the Alternate SLIPI and the real SLIPI by decrypting the SLICI. In some embodiments the Alternate SLIPI is a random SLIPI, a SLIPI chosen in a range of predefined Alternate SLIPIs, or a SLIPI previously transmitted,

[0065] Further, at step 206, a mutual authentication is performed between the secure element 102 and the equipment 110 by using the real SLIPI. In some embodiments the Alternate SLIPI is a SLIPI sent by the equipment 110 to the secure element 102 during a previous registration of the secure element 102 at the equipment 110 in a Steering of Alternate Control Plane (SoR CP) container.

[0066] Additionally, at step 208, the equipment 110 sends the Alternate SLIPI and the key KSEAF from the equipment to an AMF or a SEAF 108 of the visited network 112. In some embodiments, the equipment 110 is an Authentication credential Repository and Processing Function (ARPF), Unified Data Management (UDM), or Subscription Identifier De-concealing Function (SIDF).

[0067] Finally, at step 210, the secure communication channel between the mobile device 104 and the gNB 106 is established. The secure communication channel between the mobile device 104 and the gNB 106 can be established by deriving a key KAMF from the key KSEAF and the Alternate SUPI, at the AMF / SEAF 108, deriving a key KgNBfrom the key KAMF, at the AMF / SEAF 108, and deriving the key KgNB from keys CK, IK of the secure element 102 and the Alternate SUPI, at the mobile device 104. In some embodiments, the mobile device 104 transmits a request for an identity of the secure element 102 which further sends the SUCI comprising the Alternate SUPI and the real SUPI of the secure element 102. In an example embodiment, sending the SUCI from the mobile device 104 to the equipment 110 of the home network 114 of the secure element 102 is performed through the visited network 112.

[0068] Various embodiments of the invention may include one or more computer programs stored or otherwise embodied on a computer-readable medium, wherein the computer programs are configured to cause a processor or the computer to perform one or more operations. A computer- readable medium storing, embodying, or encoded with a computer program, or similar language may be embodied as a tangible data storage device storing one or more software programs that are configured to cause a processor or computer to perform one or more operations. Such operations may be, for example, any of the steps or operations described herein. In some embodiments, the computer programs may be stored and provided to a computer using any type of non-transitory computer-readable media.

[0069] The invention applies to public networks and private networks. It applies to mobile network operators (MNO), mobile virtual network operators (MVNO), non-public network operators (NPNO) and Satellite Network Operators (SNO) using 5G technology. It applies to 5G networks including 5G NTN networks, and also to 6G networks in the future.

Claims

CLAIMS1. A method (200) for establishing a secure communication channel between a mobile device (104) collaborating with a secure element (102) and a gNB (106) of a visited network (112), said method comprising: sending (202) from said mobile device (104) to an equipment (110) of a home network (114) of said secure element (102), a Subscription Concealed Identifier (SUCI) comprising an Alternate Subscription Permanent Identifier (SUPI) and a real SUPI of said secure element (102); at said equipment (10), retrieving (204) said Alternate SUPI and said real SUPI by decrypting said SUCI; performing (206) a mutual authentication between said secure element (102) and said equipment (10) by using said real SUPI; sending (208) from said equipment (110) to an Access and Mobility Management Function (AMF) or a Security Anchor Function (SEAF) of said visited network (112), said Alternate SUPI and a key KSEAF; and establishing (210) said secure communication channel between said mobile device (104) and said gNB (106) by: o at said AMF / SEAF (108), deriving a key K MF from said key KSEAF and said Alternate SUPI; o at said AMF / SEAF (108), deriving a key KgNB from said key KAMF; and o at said mobile device (104), deriving said key KgNB ( 6) from keys CK, IK of said secure element (102) and said Alternate SUPI.

2. The method (200) according to claim 1 , wherein said Alternate SUPI is: a random SUPI; a SUPI chosen in a range of predefined Alternate SUPIs; or a SUPI previously transmitted by said equipment (110).

3. The method (200) according to claim 1 or 2, wherein said Alternate SUPI is a SUPI sent by said equipment (110) to said secure element (102) during a previous registration of said secure element (102) at said equipment (110) in a Steering of Alternate Control Plane (SoR CP) container.

4. The method (200) according to any of the claims 1 to 3, wherein said equipment (110) is an Authentication credential Repository and Processing Function (ARPF), Unified Data Management (UDM), or Subscription Identifier De-concealing Function (SIDF).

5. The method (200) according to any of claims 1 to 4, wherein said mobile device (104) transmits a request for an identity of said secure element (102) and wherein said secure element (102) sends said SUCI comprising said Alternate SUPI and said real SUPI of said secure element (102).

6. The method (200) according to any of claims 1 to 5, wherein sending the SUCI from said mobile device (104) to the equipment (110) of the home network (114) of said secure element (102) is performed through said visited network (112).

7. An equipment (110) of a home network (114) of a secure element (102), said secure element (102) cooperating with a mobile device (104), said equipment (110) being configured for: receiving from said mobile device (104), a Subscription Concealed Identifier (SUCI) comprising an Alternate Subscription Permanent Identifier (SUPI) and a real SUPI of said secure element (102); retrieving said Alternate SUPI and said real SUPI by decrypting said SUCI; performing a mutual authentication between said secure element (102) and said equipment (110) by using said real SUPI; and sending to an Access and Mobility Management Function (AMF) or a Security Anchor Function (SEAF) (108) of a network (112) visited by said mobile device (104), said Alternate SUPI and a key KSEAF in order to allow a gNB (106) of said visited network (112) to establish a secure communication channel between said mobile device (104) and said gNB (106) by: o at said AMF / SEAF (108), deriving a key KAMF from said key KSEAF and said Alternate SUPI; o at said AMF / SEAF (108), deriving a key KgNB < 6) from said key KAMF; and o at said mobile device (104), deriving said key KgNB(io6) from keys CK, IK of said secure element (102) and said Alternate SUPI.

8. The equipment (110) according to claim 7, wherein said equipment (110) is an Authentication credential Repository and Processing Function (ARPF) I Unified Data Management (UDM) / Subscription Identifier De-concealing Function (SIDF).

Citation Information

Patent Citations

  • Method for establishing a bidirectional communication channel between a server and a secure element, corresponding servers and secure element

    EP3358868A1

  • Authentication with privacy identity

    US20180020351A1

  • Security establishment method, terminal device, and network device

    US20200359203A1