Method and apparatus for enhancing security of supi

By generating and verifying SUCI using sequence numbers, the method enhances the security of terminal identification in wireless communication systems, preventing unauthorized access and tracking attacks, thus ensuring secure and legitimate network interactions.

WO2025150941A1PCT designated stage expired Publication Date: 2025-07-17SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/000542
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-11
Filing Date
2025-01-09
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

In wireless communication systems, the transmission of a terminal's identification information, such as SUPI, is vulnerable to security threats including privacy invasion, location tracking, and impersonation attacks, as existing encryption methods like Elliptic Curve Cryptosystem can be compromised by quantum computing, necessitating enhanced protection mechanisms.

Method used

The proposed solution involves generating a subscription concealed identifier (SUCI) using a user equipment sequence number and a subscription permanent identifier (SUPI), with additional verification steps to ensure the authenticity of the network sequence number, including comparison with a home network's sequence number to prevent unauthorized access and tracking attacks.

Benefits of technology

This method strengthens the security of terminal identification by preventing unauthorized access and tracking, ensuring that only legitimate network interactions occur, thereby enhancing privacy and integrity of user data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025000542_17072025_PF_FP_ABST
    Figure KR2025000542_17072025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a 4G, 5G, or 6G communication system for supporting higher data transfer rates. According to an embodiment of the present invention, a method performed by user equipment (UE) in a wireless communication system may comprise the steps of: generating a subscription concealed identifier (SUCI) by using a user equipment sequence number and a subscription permanent identifier (SUPI); transmitting, to an access and mobility management function (AMF), a registration request message including the SUCI; receiving, from the AMF, response information for authentication of the user equipment including a network random value and a network sequence number; determining whether the response information has been transmitted from a home network of the user equipment; and determining whether the network sequence number is smaller than the user equipment sequence number.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for enhancing the security of SUPI

[0001] The present disclosure relates to a method and device for enhancing the security of a terminal's identification information in a wireless communication system.

[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in the sub-6GHz frequency band such as 3.5 gigahertz (3.5GHz), but also in the ultra-high frequency band called millimeter wave (mmWave) such as 28GHz and 39GHz ('Above 6GHz'). In addition, for 6G mobile communication technology, which is called the system after 5G communication (Beyond 5G), implementation in the terahertz (THz) band (for example, 3 THz band at 95GHz) is being considered to achieve a transmission speed that is 50 times faster than 5G mobile communication technology and an ultra-low latency time that is reduced to one-tenth.

[0003] In the early stages of 5G mobile communication technology, the goal is to support services and satisfy performance requirements for enhanced Mobile Broadband (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and massive Machine-Type Communications (mMTC). These include beamforming and massive MIMO to mitigate path loss of radio waves in ultra-high frequency bands and increase the transmission distance of radio waves, support for various numerologies (such as operation of multiple subcarrier intervals) and dynamic operation of slot formats for efficient use of ultra-high frequency resources, initial access technology to support multi-beam transmission and wideband, definition and operation of BWP (Bidth Part), new channel coding methods such as LDPC (Low Density Parity Check) codes for large-capacity data transmission and Polar Code for reliable transmission of control information, and L2 pre-processing (L2). Standardization has been made for network slicing, which provides dedicated networks specialized for specific services, and pre-processing.

[0004] Currently, discussions are underway to improve and enhance the initial 5G mobile communication technology in consideration of the services that 5G mobile communication technology was intended to support, and physical layer standardization is in progress for technologies such as V2X (Vehicle-to-Everything) to help autonomous vehicles make driving decisions and increase user convenience based on their own location and status information transmitted by vehicles, NR-U (New Radio Unlicensed) for the purpose of system operation that complies with various regulatory requirements in unlicensed bands, NR terminal low power consumption technology (UE Power Saving), Non-Terrestrial Network (NTN), which is direct terminal-satellite communication to secure coverage in areas where communication with terrestrial networks is impossible, and Positioning.

[0005] In addition, standardization of wireless interface architecture / protocols is in progress for technologies such as intelligent factories (Industrial Internet of Things, IIoT) to support new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) that provides nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement technology including Conditional Handover and Dual Active Protocol Stack (DAPS) handover, and 2-step random access (2-step RACH for NR) that simplifies random access procedures. Standardization is also in progress for system architecture / services such as 5G baseline architecture (e.g., Service-based Architecture, Service-based Interface) for grafting Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) that provides services based on the location of the terminal.

[0006] Once these 5G mobile communication systems are commercialized, an explosive increase in connected devices will be connected to the communication network, necessitating enhanced functionality and performance of 5G mobile communication systems and integrated operation of these connected devices. To this end, new research will be conducted on improving 5G performance and reducing complexity, supporting AI services, supporting metaverse services, and drone communications by utilizing eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).

[0007] In addition, the development of these 5G mobile communication systems includes new waveforms to ensure coverage in the terahertz band of 6G mobile communication technology, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), Array Antenna, and Large Scale Antenna, metamaterial-based lenses and antennas to improve the coverage of terahertz band signals, high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM), Reconfigurable Intelligent Surface (RIS) technology, as well as full duplex technology to improve the frequency efficiency and system network of 6G mobile communication technology, satellite, AI (Artificial Intelligence) from the design stage and AI-based communication technology that realizes system optimization by internalizing end-to-end AI support functions, and ultra-high-performance communication and computing resources to provide services with complexity that exceeds the limits of terminal computing capabilities. It can serve as a basis for the development of next-generation distributed computing technologies that can be realized by utilizing them.

[0008] In the 5G mobile communication system, to strengthen the protection of user privacy, the Subscription Permanent Identifier (SUPI), which is the unique ID of the terminal, is not transmitted as is, but an encrypted form of the Subscription Concealed Identifier (SUCI) is transmitted. The UDM, which receives the SUCI from the Serving Network (SN), decrypts it to obtain the SUPI, finds the Key (K: Authentication key) mapped to the SUPI, generates a random value (RAND), and uses K, RAND, and a Sequence number (SQN) to generate an Authentication Token (AUTN), which is then transmitted to the UE (User Equipment). After transmitting the Authentication Token to the UE, the UDM can store the SQN value it has stored by adding 1. The UE can also verify the Authentication Token using its K and the received RAND and SQN values. If the verification is successful, the UE can replace the SQN value it has stored with the SQN value received from the network and then perform the authentication process. If verification fails, the UE can send a MAC Failure message, and if verification succeeds but the SQN value received from the network is not an acceptable value (for example, if the SQN value received from the network is smaller than the SQN value stored by the UE), the UE can send a Sync Failure message.

[0009] Based on the discussion above, the present disclosure aims to solve the following problem. In a wireless communication system, a terminal must transmit its identification information to the network, and this information must be safely protected, considering security issues. However, if an attacker transmits a previously obtained SUCI to the UDM, the UDM can generate a RAND and an authentication token based on the authentication key (K: Authentication Key) mapped to the SUCI and transmit them to the UE, regardless of when the SUCI was generated. If the attacker, who received the RAND and the authentication token in the middle, transmits the previously received and stored RAND and authentication token to multiple UEs in the area under his control after a certain period of time, if the UE is the UE to which the attacker previously transmitted the SUCI, the authentication step will be performed normally or a Sync Failure message will be transmitted, indicating that the UE is in the area. If the UE is not the UE to which the attacker previously transmitted the SUCI, the attacker can also determine that the UE is not in the area, because the UE will send a MAC Failure message. In this way, even if an encrypted ID (SUCI) is sent, a new protection method may be needed because a user tracking attack is possible.

[0010] The technical problems to be achieved in the present invention are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which the present invention belongs from the description below.

[0011] According to one embodiment of the present invention for solving the above problem, a method performed by a user equipment (UE) in a wireless communication system may be configured to include the steps of: generating a subscription concealed identifier (SUCI) using a user equipment sequence number and a subscription permanent identifier (SUPI); transmitting a registration request message including the SUCI to an access and mobility management function (AMF); receiving, from the AMF, response information for authentication of the user equipment including a network random value and a network sequence number; determining whether the response information was transmitted from a home network of the user equipment; and determining whether the network sequence number is smaller than the user equipment sequence number.

[0012] The step of determining whether the response information was transmitted from the home network of the user device may further include the step of determining whether a value calculated based on a specific value stored by the user device, the network random value, and the network sequence number corresponds to the response information.

[0013] In the above method, if the user device determines that the response information has not been transmitted from the home network of the user device or if the network sequence number is determined to be smaller than the sequence number of the user device, the user device can transmit an error message for authentication to the AMF, and the error message transmitted when the response information is determined to have not been transmitted from the home network of the user device and the error message transmitted when the network sequence number is determined to be smaller than the sequence number of the user device can be configured in the same form.

[0014] According to another embodiment of the present invention, a method performed by user data management (UDM) in a wireless communication system may be configured to include the steps of: receiving an authentication request of a user equipment (UE) including a subscription concealed identifier (SUCI) from an authentication server function (AUSF); decrypting the SUCI to obtain a subscription permanent identifier (SUPI) and the user equipment sequence number; and performing verification of an authentication process of the user equipment through comparison of network sequence information and the user equipment sequence number.

[0015] The method of the above UDM may further include a step of generating an authentication vector when the verification is successfully completed; and a step of transmitting the generated authentication vector and the SUPI to the AUSF.

[0016] The method of the above UDM may further include a step of determining that the verification has failed if, during the verification process, the user device sequence number is greater than the network sequence number, or if the degree to which the user device sequence number is less than the network sequence number is greater than a predetermined threshold. In this case, the method may further include a step of transmitting, to the AUSF, a rejection message for the authentication process of the user device or a message requesting a new SUCI.

[0017] According to another embodiment of the present invention, a user equipment (UE) in a wireless communication system may be disclosed. The UE may include a transceiver; and a control unit, wherein the control unit may be configured to generate a subscription concealed identifier (SUCI) using a user equipment sequence number and a subscription permanent identifier (SUPI), transmit a registration request message including the SUCI to an access and mobility management function (AMF), receive response information for authentication of the user equipment including a network random value and a network sequence number from the AMF, determine whether the response information was transmitted from a home network of the user equipment, and determine whether the network sequence number is smaller than the user equipment sequence number.

[0018] According to another embodiment of the present invention, a user data management (UDM) in a wireless communication system may be disclosed. The UDM includes a transceiver; and a control unit, wherein the control unit may be configured to receive an authentication request of a user equipment (UE) including a subscription concealed identifier (SUCI) from an authentication server function (AUSF), decrypt the SUCI to obtain a subscription permanent identifier (SUPI) and the user equipment sequence number, and perform verification of an authentication process of the user equipment through a comparison between network sequence information and the user equipment sequence number.

[0019] According to one embodiment of the present disclosure, the security of identification information of a terminal can be enhanced.

[0020] The effects that can be obtained from the present disclosure are not limited to the effects mentioned in the various embodiments, and other effects that are not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure belongs from the description below.

[0021] FIG. 1A illustrates a communication network including core network entities in a wireless communication system according to various embodiments of the present disclosure.

[0022] FIG. 1b illustrates a wireless environment including a core network in a wireless communication system according to various embodiments of the present disclosure.

[0023] FIG. 2a illustrates an example of a functional structure of a terminal according to embodiments of the present disclosure.

[0024] FIG. 2b illustrates an example of a functional structure of a base station according to embodiments of the present disclosure.

[0025] FIG. 2c illustrates an example of a functional structure of a core network object according to embodiments of the present disclosure.

[0026] FIG. 3 is a diagram illustrating a process in which a terminal securely transmits its identification information to a network according to an embodiment of the present disclosure.

[0027] FIG. 4 is a diagram illustrating another process in which a terminal securely transmits its identification information to a network according to an embodiment of the present disclosure.

[0028] FIG. 5 is a diagram illustrating another process in which a terminal securely transmits its identification information to a network according to an embodiment of the present disclosure.

[0029] The terms used in this disclosure are used only to describe specific embodiments and may not be intended to limit the scope of other embodiments. The singular expression may include the plural expression unless the context clearly indicates otherwise. Terms used herein, including technical or scientific terms, may have the same meaning as commonly understood by those of ordinary skill in the art described in this disclosure. Terms defined in general dictionaries among the terms used in this disclosure may be interpreted as having the same or similar meaning in the context of the related technology, and shall not be interpreted in an idealized or overly formal sense unless explicitly defined in this disclosure. In some cases, even if a term is defined in this disclosure, it cannot be interpreted to exclude embodiments of the present disclosure.

[0030] The various embodiments of the present disclosure described below illustrate a hardware-based approach as an example. However, since the various embodiments of the present disclosure include techniques utilizing both hardware and software, the various embodiments of the present disclosure do not exclude a software-based approach.

[0031] 3GPP, responsible for cellular mobile communications standards, is standardizing a new core network architecture, dubbed 5G core (5GC), to facilitate the evolution of existing 4G LTE systems into 5G systems. Compared to the evolved packet core (EPC), the network core for existing 4G systems, 5GC supports the following differentiated features:

[0032] First, 5GC introduces network slicing. As a 5G requirement, 5GC must support various terminal types and services (e.g., eMBB, URLLC, or mMTC services). Each type of service has different requirements for the core network. For example, eMBB services require high data rates, while URLLC services require high reliability and low latency. One technology proposed to meet these diverse service requirements is network slicing.

[0033] Network slicing virtualizes a single physical network to create multiple logical networks. Each network slice instance (NSI) can have different characteristics. Therefore, each NSI can satisfy diverse service requirements by possessing a network function (NF) tailored to its characteristics. If each terminal is assigned an NSI that matches the characteristics of the service it requires, multiple 5G services can be efficiently supported.

[0034] Second, 5GC can facilitate support for the network virtualization paradigm by separating mobility management and session management functions. In 4G LTE (long term evolution), services were provided through signaling exchanges with a single core device called the mobility management entity (MME), which was responsible for registration, authentication, mobility management, and session management for all terminals. However, in 5G, the number of terminals increases explosively, and the mobility and traffic / session characteristics that must be supported for each terminal type become more specialized. Therefore, supporting all functions with a single device like the MME inevitably reduces scalability by adding entities for each required function. Therefore, various functions are being developed based on a structure that separates mobility management and session management functions to improve scalability in terms of functional / implementation complexity and signaling load of the core device responsible for the control plane.

[0035] Hereinafter, various embodiments will be described in detail with reference to the attached drawings. Furthermore, when describing embodiments of the present disclosure, detailed descriptions of related known functions or configurations will be omitted if they are deemed to unnecessarily obscure the gist of the embodiments. Furthermore, the terms described below are defined based on their functions in the embodiments, and may vary depending on the intent or custom of the user or operator. Therefore, their definitions should be based on the contents throughout this specification.

[0036] For the same reason, some components in the attached drawings are exaggerated, omitted, or schematically depicted. Furthermore, the dimensions of each component do not entirely reflect its actual size. Identical or corresponding components in each drawing are assigned the same reference numbers.

[0037] The advantages and features of the present disclosure, and methods for achieving them, will become clearer with reference to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided solely to ensure that the present disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Like reference numerals designate like elements throughout the specification.

[0038] At this time, it will be understood that each block of the processing flowchart drawings and combinations of the flowchart drawings can be performed by computer program instructions. These computer program instructions can be installed in a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, so that the instructions executed by the processor of the computer or other programmable data processing equipment create a means for performing the functions described in the flowchart block(s). These computer program instructions can also be stored in a computer-available or computer-readable memory that can direct a computer or other programmable data processing equipment to implement the functions in a specific manner, so that the instructions stored in the computer-available or computer-readable memory can also produce a manufactured item that includes an instruction means for performing the functions described in the flowchart block(s). Since the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).

[0039] Additionally, each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s). It should also be noted that in some alternative implementation examples, the functions described in the blocks may occur out of order. For example, two blocks depicted in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on their respective functions.

[0040] Here, the term '~ unit' used in various embodiments of the present disclosure means a software or hardware component such as an FPGA or ASIC, and the '~ unit' can perform certain roles. However, the '~ unit' is not limited to software or hardware. The '~ unit' may be configured to be on an addressable storage medium and may be configured to play one or more processors. Accordingly, as an example, the '~ unit' may include components such as software components, object-oriented software components, class components, and task components, processes, functions, properties, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and '~ units' may be combined into a smaller number of components and '~ units' or further separated into additional components and '~ units'. Additionally, components and '~parts' may be implemented to regenerate one or more CPUs within a device or secure multimedia card.

[0041] Hereinafter, a base station is an entity that performs resource allocation of a terminal, and may be at least one of an eNode B (eNB), a Node B, a BS (base station), a RAN (radio access network), an AN (access network), a RAN node, a NR NB, a gNB, a wireless access unit, a base station controller, or a node on a network. The terminal may include a user equipment (UE), a mobile station (MS), a cellular phone, a smartphone, a computer, or a multimedia system capable of performing a communication function. In various embodiments of the present disclosure, a case where the terminal is a UE will be described as an example. In addition, although various embodiments of the present disclosure are described below using a system based on LTE, LTE-A, or NR as an example, various embodiments of the present disclosure may be applied to other communication systems having a similar technical background or channel type. In addition, various embodiments of the present disclosure may be applied to other communication systems with some modifications within a range that does not significantly depart from the scope thereof at the discretion of a person having skilled technical knowledge.

[0042] The terms used in the following description to identify connection nodes, terms referring to network entities, terms referring to messages, terms referring to interfaces between network entities, terms referring to various identification information, etc. are provided as examples for convenience of explanation. Therefore, the present disclosure is not limited to the terms described below, and other terms referring to objects with equivalent technical meanings may be used.

[0043] Additionally, while this disclosure describes various embodiments using terminology used in certain communication standards (e.g., 3rd Generation Partnership Project (3GPP)), these are merely illustrative examples. The various embodiments of this disclosure can be easily modified and applied to other communication systems. Below, some terms used in the core network of this disclosure are predefined.

[0044] AMF access and mobility management function

[0045] CN core network

[0046] CNF containerized network function

[0047] DNN data network name

[0048] PCF policy control function

[0049] HSS home subscriber server

[0050] SMF session management function

[0051] UDM user data management

[0052] UPF user plane function

[0053] CNF containerized network function

[0054] VNF virtual network function

[0055] FIG. 1A illustrates a communication network including core network entities in a wireless communication system according to embodiments of the present disclosure. A 5G mobile communication network may be configured to include a 5G user equipment (UE) (110), a 5G radio access network (RAN) (120), and a 5G core network.

[0056] The 5G core network may be configured to include network functions such as an access and mobility management function (AMF) (150) that provides a mobility management function of UE, a session management function (SMF) (160) that provides a session management function, a user plane function (UPF) (170) that performs a data transfer role, a policy control function (PCF) (180) that provides a policy control function, a unified data management (UDM) (153) that provides a data management function such as subscriber data and policy control data, or a unified data repository (UDR) that stores data of various network functions.

[0057] Referring to FIG. 1A, a user equipment (UE) (110) may communicate with a base station (e.g., an eNB, a gNB) via a wireless channel, i.e., an access network. In some embodiments, the UE (110) may be a device used by a user and configured to provide a user interface (UI). As an example, the UE (110) may be a terminal mounted (equipment) on a vehicle for driving. In other embodiments, the UE (110) may be a device that performs machine type communication (MTC) that operates without user intervention, or may be an autonomous vehicle. UE may be referred to as a 'terminal', 'vehicle terminal', 'user equipment (UE)', 'mobile station', 'subscriber station', 'remote terminal', 'wireless terminal', or 'user device' or other terms having equivalent technical meanings, other than electronic devices. As the terminal, in addition to the UE, a customer-premises equipment (CPE) or a dongle-type terminal may be used. The CPE, while connected to the NG-RAN node like the UE, may also provide a network to other communication devices (e.g., a laptop).

[0058] Referring to FIG. 1A, the AMF (150) provides a function for connection and mobility management per terminal (110), and basically, one AMF (150) can be connected to one terminal (110). Specifically, the AMF (150) can perform at least one of signaling between core network nodes for mobility between 3GPP access networks, an interface (N2 interface) between wireless access networks (e.g., 5G RAN) (120), NAS signaling with the terminal (110), identification of the SMF (160), and provision of transmission of session management (SM) messages between the terminal (110) and the SMF (160). Some or all of the functions of the AMF (150) can be supported within a single instance of one AMF (150).

[0059] Referring to FIG. 1A, the SMF (160) provides a session management function, and when the terminal (110) has multiple sessions, each session may be managed by a different SMF (160). Specifically, the SMF (160) may perform at least one of the following functions: session management (e.g., session establishment, modification, and release, including tunnel maintenance between the UPF (170) and the access network node), selection and control of UP (user plane) functions, traffic steering setup for routing traffic to an appropriate destination in the UPF (170), termination of the SM portion of NAS messages, downlink data notification (DDN), and initiation of AN-specific SM information (e.g., delivery to the access network via the N2 interface via the AMF (150)). Some or all of the functions of the SMF (160) may be supported within a single instance of one SMF (160).

[0060] In the 3GPP system, conceptual links connecting NFs within a 5G system may be referred to as reference points. Reference points may also be referred to as interfaces. The following exemplifies reference points (hereafter, interchangeably referred to as interfaces) included in the 5G system architecture represented throughout various embodiments of the present disclosure.

[0061] - N1: Reference point between UE (110) and AMF (150)

[0062] - N2: Reference point between (R)AN(120) and AMF(150)

[0063] - N3: Reference point between (R)AN(120) and UPF(170)

[0064] - N4: Reference point between SMF (160) and UPF (170)

[0065] - N5: Reference point between PCF (180) and AF (130)

[0066] - N6: Reference point between UPF (170) and DN (140)

[0067] - N7: Reference point between SMF (160) and PCF (180)

[0068] - N8: Reference point between UDM (153) and AMF (150)

[0069] - N9: Reference point between two core UPFs (170)

[0070] - N10: Reference point between UDM (153) and SMF (160)

[0071] - N11: Reference point between AMF (150) and SMF (160)

[0072] - N12: Reference point between AMF (150) and authentication server function (AUSF) (151)

[0073] - N13: Reference point between UDM (153) and authentication server function (151)

[0074] - N14: Reference point between two AMFs (150)

[0075] - N15: For non-roaming scenarios, reference point between PCF (180) and AMF (150), for roaming scenarios, reference point between PCF (180) and AMF (150) within the visited network.

[0076] FIG. 1B illustrates a wireless environment including a core network in a wireless communication system according to embodiments of the present disclosure. Referring to FIG. 1B, the wireless communication system may include a radio access network (RAN) (120) and a core network (CN).

[0077] The wireless access network (120) is a network that is directly connected to a user device, for example, a terminal (110), and is an infrastructure that provides wireless access to the terminal (110). The wireless access network (120) includes a set of a plurality of base stations including a base station (125), and the plurality of base stations can communicate through interfaces formed between each other. At least some of the interfaces between the plurality of base stations can be wired or wireless. The base station (125) can have a structure that is divided into a central unit (CU) and a distributed unit (DU). In this case, one CU can control a plurality of DUs. The base station (125) can be referred to as an 'access point (AP)', 'next generation node B (gNB)', '5th generation node (5G node)', 'wireless point', 'transmission / reception point (TRP)', or other terms having an equivalent technical meaning thereto in addition to the base station. The terminal (110) can connect to a wireless access network (120) and communicate with a base station (125) via a wireless channel. The terminal (110) may be referred to as a 'user equipment (UE)', a 'mobile station', a 'subscriber station', a 'remote terminal', a 'wireless terminal', a 'user device', or other terms having an equivalent technical meaning.

[0078] The core network is a network that manages the entire system, controls the wireless access network (120), and can process data and control signals for terminals (110) transmitted and received through the wireless access network (120). The core network performs various functions, such as controlling the user plane and control plane, processing mobility, managing subscriber information, billing, and interworking with other types of systems (e.g., long term evolution (LTE) system). In order to perform the various functions described above, the core network may include a number of functionally separated entities having different network functions (NFs). For example, the core network (200) may include an access and mobility management function (AMF) (150), a session management function (SMF) (160), a user plane function (UPF) (170), a policy and charging function (PCF) (180), a network repository function (NRF) (159), a unified data management (UDM) (153), a network exposure function (NEF) (155), and a unified data repository (UDR) (157).

[0079] The terminal (110) can be connected to the AMF (150) that performs the mobility management function of the core network by being connected to the wireless access network (120). The AMF (150) may be a function or device that is in charge of both the connection to the wireless access network (120) and the mobility management of the terminal (110). The SMF (160) is an NF that manages sessions. The AMF (150) is connected to the SMF (160), and the AMF (150) can route session-related messages for the terminal (110) to the SMF (160). The SMF (160) is connected to the UPF (170) to allocate user plane resources to be provided to the terminal (110), and establishes a tunnel for transmitting data between the base station (125) and the UPF (170). PCF (180) can control information related to policy and charging for the session used by the terminal (110).

[0080] The NRF (159) can store information about NFs installed in a mobile communication service provider network and perform a function of notifying the stored information. The NRF (159) can be connected to all NFs. When each NF starts operating in the service provider network, it can notify the NRF (159) that the NF is operating within the network by registering with the NRF (159). The UDM (153) is an NF that performs a role similar to the HSS (home subscriber server) of a 4G network, and can store subscription information of the terminal (110) or the context used by the terminal (110) within the network.

[0081] The NEF (155) may connect a third-party server and an NF within a 5G mobile communication system. It may also provide data to, update, or acquire data from the UDR (157). The UDR (157) may store subscription information of the terminal (110), policy information, data exposed externally, or information required by a third-party application. Furthermore, the UDR (157) may also provide stored data to other NFs.

[0082] FIG. 2A illustrates an example of the functional structure of a terminal according to embodiments of the present disclosure. The configuration illustrated in FIG. 2A can be understood as the configuration of a terminal (110). Terms such as "... unit" and "... device" used hereinafter refer to a unit that processes at least one function or operation, which can be implemented using hardware, software, or a combination of hardware and software.

[0083] Referring to FIG. 2a, the terminal may include a communication unit (205), a storage unit (210), and a control unit (215).

[0084] The communication unit (205) can perform functions for transmitting and receiving signals via a wireless channel. For example, the communication unit (205) can perform a conversion function between a baseband signal and a bit stream according to the physical layer specifications of the system. For example, when transmitting data, the communication unit (205) can generate complex symbols by encoding and modulating a transmission bit stream. In addition, when receiving data, the communication unit (205) can restore a reception bit stream by demodulating and decoding the baseband signal. In addition, the communication unit (205) upconverts a baseband signal to an RF band signal and transmits it through an antenna, and downconverts an RF band signal received through the antenna to a baseband signal. For example, the communication unit (205) can include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a DAC, an ADC, etc.

[0085] In addition, the communication unit (205) may include a plurality of transmit / receive paths. Furthermore, the communication unit (205) may include at least one antenna array composed of a plurality of antenna elements. In terms of hardware, the communication unit (205) may be composed of digital circuits and analog circuits (e.g., radio frequency integrated circuits (RFIC)). Here, the digital circuits and analog circuits may be implemented in a single package. In addition, the communication unit (205) may include a plurality of RF chains. Furthermore, the communication unit (205) may perform beamforming.

[0086] The communication unit (205) can transmit and receive signals as described above. Accordingly, all or part of the communication unit (205) may be referred to as a "transmitter," a "receiver," or a "transmitting and receiving unit." Furthermore, in the following description, transmission and reception performed via a wireless channel may be used to mean that processing as described above is performed by the communication unit (205).

[0087] The storage unit (210) can store data such as basic programs, application programs, and setting information for the operation of the terminal. The storage unit (210) can be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. In addition, the storage unit (210) can provide stored data upon request from the control unit (215).

[0088] The control unit (215) can control the overall operations of the terminal. For example, the control unit (215) can transmit and receive signals through the communication unit (205). In addition, the control unit (215) can record and read data in the storage unit (210). In addition, the control unit (215) can perform the functions of the protocol stack required by the communication standard. To this end, the control unit (215) may include at least one processor or microprocessor, or may be a part of a processor. In addition, a part of the communication unit (205) and the control unit (215) may be referred to as a CP (communication processor). According to various embodiments, the control unit (215) can control to perform synchronization using a wireless communication network. For example, the control unit (215) can control the terminal to perform operations according to various embodiments described below.

[0089] According to various embodiments of the present disclosure, a terminal may be composed of a mobile equipment (ME) and a universal mobile telecommunications service (UMTS) subscriber identity module (USIM). The ME may include a mobile terminal (MT) and terminal equipment (TE). The MT may be a part where a wireless access protocol operates, and the TE may be a part where a control function operates. For example, in the case of a wireless communication terminal (e.g., a mobile phone), the MT and the TE may be integrated, and in the case of a laptop, the MT and the TE may be separated. The present disclosure may express the ME and the USIM as distinct entities depending on the operation of each component, but is not limited thereto, and may express the ME and the USIM as a terminal (e.g., UE) including the ME, or it is of course possible to describe various embodiments of the present disclosure by expressing the ME as a terminal.

[0090] FIG. 2B illustrates an example of the functional structure of a base station according to embodiments of the present disclosure. The configuration illustrated in FIG. 2B can be understood as the configuration of a base station (120). Terms such as "... unit" and "... unit" used hereinafter refer to a unit that processes at least one function or operation, which can be implemented using hardware, software, or a combination of hardware and software.

[0091] Referring to FIG. 2b, the base station may include a wireless communication unit (235), a backhaul communication unit (220), a storage unit (225), and a control unit (230).

[0092] The wireless communication unit (235) can perform functions for transmitting and receiving signals via a wireless channel. For example, the wireless communication unit (235) can perform a conversion function between baseband signals and bit streams according to the physical layer specifications of the system. For example, when transmitting data, the wireless communication unit (235) can generate complex symbols by encoding and modulating the transmitted bit stream. Furthermore, when receiving data, the wireless communication unit (235) can restore the received bit stream by demodulating and decoding the baseband signal.

[0093] In addition, the wireless communication unit (235) can upconvert a baseband signal into an RF (radio frequency) band signal and transmit it through an antenna, and downconvert an RF band signal received through the antenna into a baseband signal. To this end, the wireless communication unit (235) can include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a digital to analog convertor (DAC), an analog to digital convertor (ADC), etc. In addition, the wireless communication unit (235) can include a plurality of transmission and reception paths. Furthermore, the wireless communication unit (235) can include at least one antenna array composed of a plurality of antenna elements.

[0094] In terms of hardware, the wireless communication unit (235) may be composed of a digital unit and an analog unit, and the analog unit may be composed of a plurality of sub-units depending on operating power, operating frequency, etc. The digital unit may be implemented with at least one processor (e.g., a digital signal processor (DSP)).

[0095] The wireless communication unit (235) can transmit and receive signals as described above. Accordingly, all or part of the wireless communication unit (235) may be referred to as a "transmitter," a "receiver," or a "transceiver." Furthermore, in the following description, transmission and reception performed via a wireless channel may be used to mean that the wireless communication unit (235) performs the processing described above.

[0096] The backhaul communication unit (220) can provide an interface for performing communication with other nodes within the network. That is, the backhaul communication unit (220) can convert a bit string transmitted from a base station to another node, such as another access node, another base station, an upper node, a core network, etc., into a physical signal, and can convert a physical signal received from another node into a bit string.

[0097] The storage unit (225) can store data such as basic programs, application programs, and setting information for the operation of the base station. The storage unit (225) can be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. In addition, the storage unit (225) can provide stored data upon request from the control unit (230).

[0098] The control unit (230) can control the overall operations of the base station. For example, the control unit (230) can transmit and receive signals through the wireless communication unit (235) or the backhaul communication unit (220). In addition, the control unit (230) can record and read data in the storage unit (225). In addition, the control unit (230) can perform the functions of the protocol stack required by the communication standard. According to another implementation example, the protocol stack can be included in the wireless communication unit (235). For this purpose, the control unit (230) can include at least one processor. According to various embodiments, the control unit (230) can control to perform synchronization using a wireless communication network. For example, the control unit (230) can control the base station to perform operations according to various embodiments described below.

[0099] FIG. 2C illustrates an example of the functional structure of a core network object according to embodiments of the present disclosure. It may represent the configuration of a core network object in a wireless communication system according to various embodiments of the present disclosure. The configuration illustrated in FIG. 2C may be understood as a configuration of a device having the function of at least one of the network entities including the AMF (150) of FIG. 1. Terms such as "... unit" and "... device" used hereinafter mean a unit that processes at least one function or operation, and this may be implemented by hardware, software, or a combination of hardware and software.

[0100] Referring to the above drawing 2c, the core network object can be configured to include a communication unit (240), a storage unit (245), and a control unit (250).

[0101] The communication unit (240) may provide an interface for performing communication with other devices within the network. That is, the communication unit (240) may convert a bit string transmitted from a core network object to another device into a physical signal, and may convert a physical signal received from another device into a bit string. That is, the communication unit (240) may transmit and receive signals. Accordingly, the communication unit (240) may be referred to as a modem, a transmitter, a receiver, or a transceiver. In this case, the communication unit (240) may enable the core network object to communicate with other devices or systems via a backhaul connection (e.g., a wired backhaul or a wireless backhaul) or via a network.

[0102] The storage unit (245) can store data such as basic programs, application programs, and setting information for the operation of core network objects. The storage unit (245) can be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. In addition, the storage unit (245) can provide stored data upon request from the control unit (250).

[0103] The control unit (250) can control the overall operations of the core network object. For example, the control unit (250) can transmit and receive signals through the communication unit (240). In addition, the control unit (250) can record and read data in the storage unit (245). For this purpose, the control unit (250) can include at least one processor. According to various embodiments of the present disclosure, the control unit (250) can control synchronization using a wireless communication network. For example, the control unit (250) can control the core network object to perform operations according to various embodiments described below.

[0104] The terms used in the following description to identify connection nodes, terms referring to network entities, terms referring to messages, terms referring to interfaces between network entities, and terms referring to various identification information are provided as examples for convenience of explanation. Therefore, the present disclosure is not limited to the terms described below, and other terms referring to objects with equivalent technical meanings may be used.

[0105] For convenience of explanation, this disclosure uses terms and names defined in the 5GS (5G system) and NR (new radio) standards, the most recent standards defined by the 3GPP organization among the existing communication standards. However, this disclosure is not limited to these terms and names and can be equally applied to wireless communication networks conforming to other standards. In particular, this disclosure can be applied to 3GPP 5th generation mobile communication standards (e.g., 5GS and NR).

[0106] With regard to one embodiment that can be exemplified by FIGS. 3 to 5,

[0107] SUPI (Subscription Permanent Identifier) ​​may be a unique ID assigned to a terminal. SUPI can be used as identification information for a specific terminal.

[0108] If SUPI is exposed, the following security threats may occur:

[0109] - Privacy Invasion: It is possible to know what tasks a terminal with the SUPI is performing, and also to track the tasks performed by the terminal with the SUPI.

[0110] - Location tracking: The physical location of a terminal with the SUPI can be tracked.

[0111] - Impersonation attack: An entity other than the terminal corresponding to the SUPI can pretend to be the terminal corresponding to the SUPI by using the SUPI.

[0112] A terminal (UE) may need to transmit its identification information to a network to prove its identity. In this case, the terminal's identification information transmitted to the network may be SUPI. Due to the security threats described above, SUPI may be transmitted in a protected form. A method for protecting SUPI may be to encrypt it. Encrypted SUPI may be exemplified by a Subscription Concealed Identifier (SUCI). The SUCI may not simply be encrypted SUPI, but may also be encrypted together with additional information.

[0113] For the reasons described above, SUPI is transmitted encrypted in current communication systems. The encryption systems used in current communication systems may be based on public-key cryptography (e.g., Elliptic Curve Cryptosystem). Since Elliptic Curve Cryptosystem can be defeated by quantum computing, a quantum-secure cryptosystem (PQC: Post-Quantum Cryptography) could be used as a SUPI protection mechanism.

[0114] In the embodiments of FIGS. 3 to 5, various methods of protecting SUPI can be exemplified by utilizing the background knowledge described above.

[0115] FIG. 3 is a diagram illustrating a process in which a terminal (UE) securely transmits its identification information to a network according to one embodiment of the present disclosure.

[0116] According to Figure 3, the UDM may know in advance that the USIM of the corresponding terminal generates SUCI in a new way.

[0117] In step 1, the UE uses SUPI to generate SUCI, SQN UE SUCI can be generated using (the sequence number stored by the UE) and SUPI. When generating SUCI, SUPI can be encrypted using the same algorithm as before (i.e., Elliptic Curve Integrated Encryption Scheme) or a method that introduces the PQC algorithm. Specifically, the UE uses the key that encrypted SUPI to generate SQN. UE After performing a separate encryption or integrity protection process, it can be transmitted to AMF / SEAF, etc., or SUPI and SQN UE After performing encryption and integrity protection process together, it can be transferred to AMF / SEAF, etc., or alternatively, SQN UE It can also be transmitted to AMF / SEAF, etc. without protection. The operation can be performed on USIM or ME (Mobile Equipment) or UE (User Equipment).

[0118] In step 2, the UE may send a registration request message to the AMF / SEAF (Security Anchor Function) along with the SUCI generated in step 1. If the SUCI is generated by the ME, the UE may also send an indication that the SUCI was generated in a new manner along with the registration request message. In one embodiment, the SUCI and the indication that the SUCI was generated in a new manner may be included in the registration request message and transmitted.

[0119] In step 3, AMF / SEAF can send an authentication request message to AUSF by forwarding the SUCI and SN-name (Serving Network name) received in step 2. AMF / SEAF can also forward the indication received from UE in step 2 to AUSF along with the authentication request message.

[0120] In Step 4, the AUSF may forward the information received from the AMF / SEAF in Step 3 to the UDM, the Authentication Credential Repository and Processing Function (ARPF), or the Subscription Identifier De-concealing Function (SIDF). The AUSF may also forward the indication received from the AMF / SEAF in Step 3 to the UDM.

[0121] ARPF or SIDF may be functions implemented within a UDM, and in the specification below, a UDM may be understood to include either ARPF or SIDF, or a combination thereof.

[0122] In step 5, UDM decrypts the received SUCI to produce SUPI and SQN. UE can be obtained. Based on the obtained SUPI, UDM obtains K (Authentication key) and SQN corresponding to the UE. HN You can find (Sequence number stored by Home Network) and obtain SQN UE Wow SQN HN The values ​​can be compared. SQN obtained by UDM UE The value of SQN HN is different from the value of or is an unacceptable number (e.g. SQN UE The value of SQN HN If the value is smaller than the standard value, it is judged to be a previously generated SUCI, or SQN HNIt may be judged that the attacker has hijacked SUPI and attacked because it is larger than the value of SQN) or that the UE must generate SUCI in a new way. UE If the UDM does not include the SUCI, the UDM may reject the authentication process or may send a request message to generate a new SUCI. The authentication rejection message or the new SUCI request message may be delivered to the UE through the AUSF, AMF / SEAF, or the base station. Before the UDM sends the authentication rejection message or the new SUCI request message, the UDM may send a new RAND HN A value can also be generated and sent together. When the UE receives the message, it generates a new SUCI and stores the SQN stored by the UE. UE The value of RAND received from UDM HN After protecting it using the value, it can be sent to the network with a new SUCI. The UDM that receives it stores the SQN HN SQN received UE It can also be stored as a value.

[0123] In Step 6, if the verification in Step 5 was successful, the UDM can generate an Authentication Vector (AV) and pass it to the AUSF along with the SUCI. If the UDM supports a new SUCI verification feature, it can also send the relevant indicators to the AUSF along with the AV.

[0124] In step 7, AUSF includes RAND in AV along with response information for UE's authentication. HN Value and SQN HN The value of SQN can be passed to AMF / SEAF. HN The value may be passed as is or in a protected form. AUSF may also send the indication received from UDM in step 6 to AMF / SEAF.

[0125] In step 8, AMF / SEAF responds to the UE's authentication request with RAND HN Value and SQN HN The value can be passed to the UE. AMF / SEAF can also send the indication received from AUSF to the UE in step 7.

[0126] In step 9, the UE receives the RAND HN Value and SQN HN The value of K stored by the UE can be used to determine whether the value received from the network is from its home network. For example, the value of K stored by the UE and the RAND received from the network HN Value and SQN HN By calculating a value using a function agreed upon in advance with the network and comparing it with the value transmitted by the network, it is possible to determine whether the value came from a real network. For example, if the value calculated by the UE corresponds to the response information for UE authentication transmitted from the network, that is, if the calculated value and a specific value included in the response information match, it can be determined that the information received in step 8 came from a real Home Network.

[0127] If the values ​​are different, the UE may send a MAC Failure message or send a new error message (e.g., requesting a new authentication token from the UDM) to hide information from the attacker. The UE may send a MAC Failure message or a new error message, but it must not send an SQN managed by the UE. UE Information about can also be transmitted over the network in a protected manner.

[0128] If UE has K value, RAND HN Value and SQN HN The value calculated through the value and the value transmitted from the network are the same, but the SQN received by the UE HNThe value of SQN stored by UE UE If it is less than the value, the UE may send a Sync Failure message or send a new error message (e.g., requesting a new authentication token from the UDM) to avoid revealing information to the attacker. The UE may send a Sync Failure message or a new error message using the SQN managed by the UE. UE Information about can also be transmitted over the network in a protected manner.

[0129] According to one embodiment, the error message transmitted by the UE instead of the MAC failure message and the Sync failure message can be configured in the same form. That is, the error message transmitted when the value calculated by the UE and the response information for UE authentication received from the network do not correspond (when the response information is determined not to have been transmitted from the UE's home network), and the SQN message received by the UE HN The value of SQN stored by UE UE The error message transmitted when the value is less than the value may be in the same message format. However, the content transmitted via the same error message format may differ. For example, if the response information is determined not to have been transmitted from the UE's home network, the flag "0" may be sent, and if the SQN value does not match, the flag "1" may be sent. In this case, the flag can also be transmitted in a protected format (e.g., encrypted using the K value or hashed using the K value), so it can be transmitted in a way that is not exposed to an attacker.

[0130] UDM sends SQN with MAC Failure message or new error message UE If information about SQN has been protected, UE After obtaining the SQN you are saving HN Compare with the value of SQN received from UE if different UEYou can also create a new authentication vector by saving the value of .

[0131] If the UE does not receive an indication in step 8, it may operate as before. Alternatively, the UE may know in advance whether the UDM supports the new feature and operate accordingly.

[0132] In step 10, if no verification has failed up to step 9, the UE and the network can perform the authentication procedure.

[0133] UDM is SQN after the authentication process is successfully completed. HN Add 1 to the value of SQN HN can also store the value of SQN. Similarly, the UE can also store the SQN value after the authentication process is successfully completed. UE Add 1 to the value of SQN UE You can also store the value of .

[0134] FIG. 4 is a diagram illustrating a process in which a terminal (UE) securely transmits its identification information to a network according to one embodiment of the present disclosure.

[0135] According to Figure 4, the UDM may know in advance that the USIM of the corresponding terminal generates SUCI in a new way.

[0136] In step 1, USIM may request current time information from ME.

[0137] In step 2, the ME may respond to the ME with current time information.

[0138] In step 3, the UE may generate SUCI using the current time and SUPI. When generating SUCI, the UE may encrypt SUPI using the same algorithm as before (i.e., Elliptic Curve Integrated Encryption Scheme) or a method introducing the PQC algorithm to generate SUCI. Specifically, the UE may perform a separate encryption or integrity protection process on the time when SUCI was generated using the key that encrypted SUPI and then transmit it to AMF / SEAF, etc., or perform encryption and integrity protection processes on the time when SUPI and SUCI were generated together and then transmit it to AMF / SEAF, etc., or alternatively, transmit the time when SUCI was generated to AMF / SEAF, etc. without protection. The corresponding operation may be performed on USIM or ME (Mobile Equipment).

[0139] In step 4, the UE may send a registration request message to the AMF / SEAF (Security Anchor Function) along with the SUCI generated in step 3. If the SUCI is generated by the ME, the UE may also send an indication of the new SUCI generation along with the registration request message.

[0140] In step 5, AMF / SEAF can send an authentication request message to AUSF by forwarding the SUCI and SN-name (Serving Network name) received in step 4. AMF / SEAF can also forward the indication received from UE in step 4 to AUSF along with the authentication request message.

[0141] In Step 6, the AUSF may forward the information received from the AMF / SEAF in Step 5 to the UDM. The AUSF may also forward the indications received from the AMF / SEAF in Step 5 to the UDM.

[0142] In step 7, the UDM decrypts the received SUCI to obtain the SUPI and the time at which the SUCI was generated. Based on the obtained SUPI, the UDM generates the K (Authentication key) and SQN corresponding to the UE. HN (Sequence number stored by the Home Network) can be found. Based on the acquired time information, the generation time of the corresponding SUCI can be determined. If the corresponding SUCI was generated a very long time ago or does not include time information even though the UE must generate SUCI in a new way, the UDM may reject the authentication process or send a request message to generate a new SUCI. Although not shown in the drawing, the authentication rejection message or the new SUCI request message may be delivered to the UE through the AUSF, AMF / SEAF, or the base station. Before the UDM sends the authentication rejection message or the new SUCI request message, the UDM generates a new RAND HN A value can also be generated and sent together. When the UE receives the message, it generates a new SUCI and stores the SQN stored by the UE. UE The value of RAND received from UDM HN After protecting it using the value, it can be sent to the network with a new SUCI. The UDM that receives it stores the SQN HN SQN received UE It can also be stored as a value.

[0143] In Step 8, if the verification in Step 7 was successful, the UDM can generate an Authentication Vector (AV) and pass it to the AUSF along with the SUCI. If the UDM supports new SUCI verification capabilities, it can also send related indicators to the AUSF along with the AV.

[0144] In step 9, AUSF includes RAND in AV HN Value and SQN HN The value of SQN can be passed to AMF / SEAF. HN The value may be passed as is or in a protected form. AUSF may also send the indication received from UDM in step 8 to AMF / SEAF.

[0145] In step 10, AMF / SEAF RAND HN Value and SQN HN The value can be passed to the UE. AMF / SEAF can also send the indication received from AUSF to the UE in step 9.

[0146] In step 11, the UE receives the RAND HN Value and SQN HN The value of K and the value of RAND stored by the UE can be used to determine whether the value received from the network is from its home network. For example, the value of K stored by the UE and the value of RAND received from the network HN Value and SQN HN By calculating a value using a function agreed upon in advance with the network, and comparing it with the value transmitted by the network, we can determine whether the value really came from the network.

[0147] If the values ​​are different, the UE may send a MAC Failure message or send a new error message (e.g., requesting a new authentication token from the UDM) to hide information from the attacker. The UE may send a MAC Failure message or a new error message, but it must not send an SQN managed by the UE. UE Information about can also be transmitted over the network in a protected manner.

[0148] If UE has K value, RAND HN Value and SQN HNThe value calculated through the value and the value transmitted from the network are the same, but the SQN received by the UE HN The value of SQN stored by UE UE If it is less than the value, the UE may send a Sync Failure message or send a new error message (e.g., requesting a new authentication token from the UDM) to avoid revealing information to the attacker. The UE may send a Sync Failure message or a new error message using the SQN managed by the UE. UE Information about can also be transmitted over the network in a protected manner.

[0149] UDM sends SQN to MAC Failure message, Sync Failure message or new error message. UE If information about SQN has been protected, UE After obtaining the SQN you are saving HN Compare with the value of SQN received from UE if different UE You can also create a new authentication vector using the value of .

[0150] If the UE does not receive an indication in step 10, it may operate as before. Alternatively, the UE may know in advance whether the UDM supports the new feature and operate accordingly.

[0151] In step 12, if no verification has failed up to step 11, the UE and the network can perform the authentication procedure.

[0152] UDM is SQN after the authentication process is successfully completed. HN Add 1 to the value of SQN HN can also store the value of SQN. Similarly, the UE can also store the SQN value after the authentication process is successfully completed. UE Add 1 to the value of SQN UE You can also store the value of .

[0153] FIG. 5 is a diagram illustrating a process in which a terminal (UE) securely transmits its identification information to a network according to one embodiment of the present disclosure.

[0154] According to Figure 5, the UDM may know in advance that the USIM of the corresponding terminal generates SUCI in a new way.

[0155] In step 1, the UE uses SUPI to generate SUCI, RAND UE Generate RAND UE SUCI can also be generated using SUPI. When generating SUCI, SUPI can be encrypted using the same algorithm as before (i.e., Elliptic Curve Integrated Encryption Scheme) or the PQC algorithm. Specifically, the UE uses the key that encrypted SUPI to generate RAND UE After performing a separate encryption or integrity protection process, it can be transmitted to AMF / SEAF, etc., or SUPI and RAND UE After performing encryption and integrity protection process together, it can be passed to AMF / SEAF, etc., or alternatively, RAND UE It can also be transmitted in an unprotected form to AMF / SEAF, etc. The operation can be performed on USIM or ME (Mobile Equipment).

[0156] In step 2, the UE can send a registration request message to the AMF / SEAF (Security Anchor Function) along with the SUCI generated in step 1. If the SUCI is generated by the ME, the UE can also send an indication that it has generated the SUCI in a new way along with the registration request message. The UE transmits the RAND UE The value may not be deleted until authentication is complete.

[0157] In step 3, AMF / SEAF can send an authentication request message to AUSF by forwarding the SUCI and SN-name (Serving Network name) received in step 2. AMF / SEAF can also forward the indication received from UE in step 2 to AUSF along with the authentication request message.

[0158] In Step 4, the AUSF can forward the information received from the AMF / SEAF in Step 3 to the UDM. The AUSF can also forward the indications received from the AMF / SEAF in Step 3 to the UDM.

[0159] In step 5, UDM decrypts the received SUCI and produces SUPI and RAND UE can be obtained. Based on the obtained SUPI, UDM obtains K (Authentication key) and SQN corresponding to the UE. HN (Sequence number stored by the home network) can be found. Even if the UE needs to generate SUCI in a new way, RAND UE If the UDM does not include the SUCI, the UDM may reject the authentication process or may send a request message to generate a new SUCI. Although not shown in the diagram, the authentication rejection message or the new SUCI request message may be delivered to the UE through the AUSF, AMF / SEAF, or the base station. Before the UDM sends the authentication rejection message or the new SUCI request message, the UDM may generate a new RAND HN A value can also be generated and sent together. When the UE receives the message, it generates a new SUCI and a RAND UE RAND value received from UDM HN After protecting it using the value, it can be sent to the network along with a new SUCI. The UDM that receives it will receive the newly received RAND UEThe authentication process can also be initiated by generating an authentication vector using the value of .

[0160] In step 6, UDM will be RAND if the verification in step 5 is successfully completed. UE An Authentication Vector (AV) can be generated using the SUCI and passed to the AUSF along with the SUCI. If the UDM supports new features for SUCI verification, it can also send related instructions to the AUSF along with the AV.

[0161] In step 7, AUSF includes RAND in AV HN Value and SQN HN The value of SQN can be passed to AMF / SEAF. HN The value may be passed as is or in a protected form. AUSF may also send the indication received from UDM in step 6 to AMF / SEAF.

[0162] In step 8, AMF / SEAF RAND HN Value and SQN HN The value can be passed to the UE. AMF / SEAF can also send the indication received from AUSF to the UE in step 7.

[0163] In step 9, the UE receives the RAND HN Value or SQN HN The value of , or the value of K stored by the UE, or RAND UE The value of (UE is RAND UE In case of authenticating the network using the value of (it may be the case that an indicator is received from the network in step 8), it is possible to determine whether the value received from the network is from one's home network. For example, the value of K stored by the UE or the RAND UE , RAND value received from the network and SQN HNBy calculating a value using a function agreed upon in advance with the network, and comparing it with the value transmitted by the network, we can determine whether the value really came from the network.

[0164] If the values ​​are different, the UE may send a MAC Failure message or send a new error message (e.g., requesting a new authentication token from the UDM) to hide information from the attacker. The UE may send a MAC Failure message or a new error message, but it must not send an SQN managed by the UE. UE or RAND UE Information about can also be transmitted over the network in a protected manner.

[0165] If UE has K value, RAND HN Value and SQN HN The value calculated through the value and the value transmitted from the network are the same, but the SQN received by the UE HN The value of SQN stored by UE UE If it is less than the value, the UE may send a Sync Failure message or send a new error message (e.g., requesting a new authentication token from the UDM) to avoid revealing information to the attacker. The UE may send a Sync Failure message or a new error message using the SQN managed by the UE. UE or RAND UE Information about can also be transmitted over the network in a protected manner.

[0166] UDM sends SQN to MAC Failure message, Sync Failure message or new error message. UE or RAND UE If information about SQN has been protected, UE After obtaining the SQN you are saving HN Compare with the value of SQN received from UE if different UEStore the value of , and then compare that value with RAND UE You can also create a new authentication vector using the value of .

[0167] In step 10, if no verification has failed up to step 9, the UE and the network can perform the authentication procedure.

[0168] UDM is SQN after the authentication process is successfully completed. HN Add 1 to the value of SQN HN can also store the value of SQN. Similarly, the UE can also store the SQN value after the authentication process is successfully completed. UE Add 1 to the value of SQN UE The value of RAND can also be stored. Also, the UE can store the RAND value after the authentication process is successfully completed. UE You can also delete it.

[0169] The configuration diagrams, diagrams illustrating control / data signal transmission / reception methods, and diagrams illustrating operational procedures, which may be exemplified by FIGS. 1A to 5, do not limit the scope of the embodiments of the present disclosure. That is, not all components, entities, or operational steps exemplified in FIGS. 1A to 5 should be construed as essential components for implementing the disclosure, and implementations may be made within a scope that does not harm the essence of the disclosure even if only some components are included.

[0170] The operations of the embodiments described above can be realized by providing a memory device storing the corresponding program code in any component within the device. That is, the control unit within the device can execute the operations described above by reading and executing the program code stored in the memory device through a processor or a CPU (Central Processing Unit).

[0171] The various components and modules of the entity or terminal device described in the present disclosure may be operated using hardware circuits, such as logic circuits based on complementary metal oxide semiconductors, firmware, software, and / or hardware and firmware and / or software embedded in a machine-readable medium. For example, various electrical structures and methods may be implemented using electrical circuits such as transistors, logic gates, and application-specific semiconductors.

[0172] The methods according to the embodiments described in the claims or specification of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.

[0173] When implemented in software, a computer-readable storage medium storing one or more programs (software modules) may be provided. The one or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. The one or more programs include instructions that cause the electronic device to execute methods according to the embodiments described in the claims or specification of the present disclosure.

[0174] These programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, read only memory (ROM), electrically erasable programmable read only memory (EEPROM), magnetic disc storage devices, compact disc-ROMs (CD-ROMs), digital versatile discs (DVDs) or other forms of optical storage devices, magnetic cassettes, or may be stored in memories formed by a combination of some or all of these. In addition, each configuration memory may include multiple copies.

[0175] Additionally, the program may be stored on an attachable storage device that is accessible via a communication network, such as the Internet, an intranet, a local area network (LAN), a wide area network (WAN), a storage area network (SAN), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure via an external port. Additionally, a separate storage device on the communication network may be connected to a device performing an embodiment of the present disclosure.

[0176] In the specific embodiments of the present disclosure described above, components included in the disclosure are expressed in the singular or plural form, depending on the specific embodiment presented. However, the singular or plural expressions are selected to suit the presented situation for convenience of explanation, and the present disclosure is not limited to singular or plural components. Components expressed in the plural form may be composed of singular elements, or components expressed in the singular form may be composed of plural elements.

[0177] While the detailed description of this disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined not only by the scope of the claims described below, but also by equivalents thereof.

Claims

1. A method performed by a user equipment (UE) in a wireless communication system, A step of generating a subscription concealed identifier (SUCI) using a user device sequence number and a subscription permanent identifier (SUPI); A step of transmitting a registration request message including the above SUCI to an access and mobility management function (AMF); A step of receiving response information for authentication of the user device including a network random value and a network sequence number from the AMF; a step of determining whether the above response information was transmitted from the home network of the user device; and A method comprising the step of determining whether the network sequence number is less than the user device sequence number.

2. In paragraph 1, The step of determining whether the above response information was transmitted from the home network of the user device is as follows: A method comprising the step of determining whether a value calculated based on a specific value stored in the user device, the network random value and the network sequence number corresponds to the response information.

3. In paragraph 1, If it is determined that the above response information has not been transmitted from the home network of the user device or if it is determined that the network sequence number is smaller than the sequence number of the user device, an error message for authentication is transmitted to the AMF. A method wherein an error message transmitted when it is determined that the response information has not been transmitted from the home network of the user device and an error message transmitted when it is determined that the network sequence number is smaller than the sequence number of the user device are configured in the same format.

4. In paragraph 1, The above AMF forwards the authentication request of the user device to the UDM (user data management) through the AUSF (authentication server function), A method for receiving response information for authentication of the user device from the UDM through the AUSF and transmitting the information to the user device.

5. In a method performed by UDM (user data management) in a wireless communication system, A step of receiving an authentication request of a user equipment (UE) including a subscription concealed identifier (SUCI) from an authentication server function (AUSF); A step of decrypting the SUCI to obtain a subscription permanent identifier (SUPI) and the user device sequence number; and A method comprising the step of performing verification for an authentication process of the user device by comparing network sequence information and the user device sequence number.

6. In paragraph 5, If the above verification is successfully completed, a step of generating an authentication vector; and A method further comprising the step of transmitting the generated authentication vector and the SUPI to the AUSF.

7. In paragraph 5, A method further comprising a step of determining that the verification has failed if, during the verification process, the user device sequence number is greater than the network sequence number, or if the degree to which the user device sequence number is less than the network sequence number is greater than a set threshold value.

8. In paragraph 7, A method further comprising the step of transmitting, to the AUSF, a message requesting a rejection message for the authentication process of the user device or a new SUCI.

9. In a user equipment (UE) in a wireless communication system, Transmitter and receiver; and Includes a control unit, The above control unit, Generate a SUCI (subscription concealed identifier) using the user device sequence number and SUPI (subscription permanent identifier), A registration request message including the above SUCI is transmitted to the AMF (access and mobility management function), Receive response information for authentication of the user device including a network random value and a network sequence number from the AMF; Determining whether the above response information was transmitted from the home network of the user device; A user device configured to determine whether the network sequence number is less than the user device sequence number.

10. In paragraph 9, The above control unit, In the process of determining whether the above response information was transmitted from the home network of the user device, A user device configured to determine whether a value calculated based on a specific value stored in the user device, the network random value, and the network sequence number corresponds to the response information.

11. In paragraph 9, The above control unit, If it is determined that the above response information is not transmitted from the home network of the user device or if it is determined that the network sequence number is smaller than the sequence number of the user device, an error message for authentication is set to be transmitted to the AMF. A user device, wherein an error message transmitted when it is determined that the response information has not been transmitted from the home network of the user device and an error message transmitted when it is determined that the network sequence number is smaller than the sequence number of the user device are configured in the same format.

12. In UDM (user data management) in wireless communication systems, Transmitter and receiver; and Includes a control unit, The above control unit, Receive an authentication request from a user equipment (UE) including a subscription concealed identifier (SUCI) from an authentication server function (AUSF), Decrypt the SUCI above to obtain the SUPI (subscription permanent identifier) and the user device sequence number, A UDM configured to perform verification of the authentication process of the user device by comparing the network sequence information and the user device sequence number.

13. In paragraph 12, The above control unit, If the above verification is completed successfully, an authentication vector is generated, A UDM further configured to transmit the generated authentication vector and the SUPI to the AUSF.

14. In paragraph 12, The above control unit, A UDM further configured to determine that the verification has failed if, during the verification process, the user device sequence number is greater than the network sequence number, or if the degree to which the user device sequence number is less than the network sequence number is greater than a predetermined threshold value.

15. In paragraph 14, The above control unit, A UDM further configured to transmit a rejection message for the authentication process of the user device or a message requesting a new SUCI to the AUSF.

Citation Information

Patent Citations

  • Method and device for sending terminal serial number and authentication method and device

    CN110536292A

  • Secret key determination method and device

    CN111641498A

  • Method for preventing encrypted user identity from being subjected to replay attack

    CN115699672A

  • Parameter transmission method and device

    JP2022529837A

  • User equipment authentication preventing sequence number leakage

    US20220038896A1