System and method for managing subscriber identity in a network

The system enriches trace records with SUPI information at the TCE, addressing the challenge of subscriber-anonymous trace data in 5G networks by passively tapping AMF interfaces, thereby improving network observability and reducing overhead, while maintaining service delivery efficiency.

WO2026047743A1PCT designated stage Publication Date: 2026-03-05JIO PLATFORMS LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

In 5G networks, the lack of direct access to the subscription permanent identifier (SUPI) in trace records due to stringent privacy protections limits the effectiveness of trace-based diagnostics and user-centric analytics, leading to subscriber-anonymous trace data and increased processing overhead in critical core network functions.

Method used

A system and method that enriches trace records with SUPI information at the Trace Control Entity (TCE) by passively tapping AMF interfaces (N2, N12, N13) to correlate SUCI with SUPI, eliminating the need for additional signalling and reducing processing overhead at gNB and AMF nodes.

Benefits of technology

Enables real-time, non-intrusive, and standards-compliant subscriber-level analytics, enhancing network observability and reducing infrastructure and operational costs while maintaining service delivery efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IN2025051373_05032026_PF_FP_ABST
    Figure IN2025051373_05032026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a system (102) and a method (600) for managing a subscriber identity in a network (108). The method (600) includes capturing, by a trace control entity (TCE) (308), a plurality of mapping parameters based on signalling information associated with at least one subscriber session. The method (600) further includes receiving, by the TCE (308), a plurality of trace records (316) associated with the at least one subscriber session from a network node. The method (600) further includes correlating, by the TCE (308), the plurality of captured mapping parameters and the plurality of received trace records (316) to obtain a set of correlation parameters associated with the subscriber identity. The method (600) further includes mapping, by the TCE (308), the set of obtained correlation parameters to a trace record of the plurality of received trace records (316) for managing the subscriber identity within the network (108).
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEM AND METHOD FOR MANAGING SUBSCRIBER IDENTITY IN A NETWORKRESERVATION OF RIGHTS

[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to JIO PLATFORMS LIMITED or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.FIELD OF DISCLOSURE

[0002] The present disclosure generally relates to the field of wireless communication systems. More particularly, the present disclosure relates to a system and a method for managing a subscriber identity in a network.DEFINITION

[0003] As used in the present disclosure, the following terms are generally intended to have the meaning as set forth below, except to the extent that the context in which they are used to indicate otherwise.

[0004] The expression ‘Tapping Mechanism’ used hereinafter in the specification refers to a passive or active method of safe and secured intercepting and duplicating control-plane traffic flowing over the network interface such as N2, N12, or N11 without interrupting or altering the ongoing communication.

[0005] The expression ‘Control Plane’ used hereinafter in the specification refers to the logical network layer responsible for signalling, configuration, and management operations necessary to establish and maintain network services. The control plane includes signalling messages exchanged between network functions and the user equipment (UE) to handle mobility, authentication, session management, and policy control.

[0006] The expression ‘signalling information’ used hereinafter in the specification refers to control-plane data exchanged between the network entities and / or between the UE and an access network, which is used to establish, manage, authenticate, and release communication sessions. In the network, the signalling information includes registration messages and authentication request / response messages.

[0007] The expression ‘subscriber session’ used hereinafter in the specification refers to a logical communication context established between the UE and the network to support data and / or control plane communication, including registration, authentication, mobility management, and session management functions.

[0008] The expression ‘Network Function (NF)’ used hereinafter in the specification refers to a logical entity within a telecommunications core network, such as a fifth generation (5G) core network, that provides a specific service or performs a designated control or user-plane task. The NF is implemented as a software running on one or more physical or virtualized network nodes and is configured to interact with other NFs through service-based interfaces.

[0009] The expression ‘Access and Mobility Management Function (AMF)’ used hereinafter in the specification refers to a control-plane function in the 5G core network responsible for registration, connection management, reachability, mobility handling, and access authentication of the UE.

[0010] The expression ‘Session Management Function (SMF)’ used hereinafter in the specification refers to a control-plane function in the 5G core network that is responsible for session establishment, modification, and release, as well as allocation of internet protocol (IP) addresses and enforcement of quality of service (QoS) and charging rules.

[0011] The expression ‘network entities’ used hereinafter in the specification refers to functional components or logical nodes within the network, such as 5G core (5GC) or access network, that participate in control or user plane operations for managing connectivity, mobility, session, and authentication of the UE.

[0012] The expression ‘User Plane Function (UPF)’ used hereinafter in the specification refers to a user-plane function in the 5G core network that is responsible for packet routing and forwarding, quality of service (QoS) handling, traffic usage reporting, and interconnection with the data network (DN).

[0013] The expression ‘network node’ used hereinafter in the specification refers to a Next Generation NodeB (gNB), which is a radio access network node in a 5G wireless communication system. The gNB is configured to provide radio access connectivity to user equipment (UE) and is responsible for functions including radio resource management, radio bearer setup and modification, mobility management within the radio access network, and forwarding of signalling and user-plane data between the UE and the core network over standardized interfaces (for example, the N2 and N3 interfaces).

[0014] The expression ‘Unified Data Management (UDM)’ used hereinafter in the specification refers to a network function in the 5G core responsible for subscriber data management, user identity handling, access authorization, and policy provisioning.

[0015] The expression ‘network interface’ used hereinafter in the specification refers to a defined point of interaction between the network entities (e.g., between the gNB and the AMF, or between the AMF and AUSF), over which the signalling messages are exchanged as part of control plane operations.

[0016] The expression ‘gNodeB (gNB)’ used hereinafter in the specification refers to a radio access node in a 5G network that provides wireless connectivity between the UE and the 5G core network. The gNB handles both control-plane and user-plane communication over the air interface and interfaces with the core network via next generation (NG) interfaces.

[0017] The expression ‘Subscriber Concealed Identifier (SUCI)’ used hereinafter in the specification refers to privacy-preserving identifier generated by the UE to protect a permanent identity of the subscriber, such as SubscriptionPermanent Identifier (SUPI), during transmission over the access network. The SUCI is derived by encrypting the SUPI using a public key of a home network.

[0018] The expression ‘Radio Access Node’ used hereinafter in the specification refers to a network element that provides wireless communication between user equipment (UE) and a core network. The radio access node (e.g., gNB in 5G) manages radio resources, performs scheduling, handles mobility functions, and ensures the transmission and reception of user-plane and control-plane signals.

[0019] The expression ‘Non-Access Stratum (NAS)’ used hereinafter in the specification refers to a layer of signalling protocols between the (UE) and the core network functions (e.g., AMF in 5G). It operates independently of the underlying radio access (RAN) and is responsible for functions such as, mobility management (e.g., registration, tracking area updates), session management (e.g., session establishment and release), authentication and security procedures, and so forth.

[0020] The expression ‘trace records’ used hereinafter in the specification refers to detailed logs and data records that capture activities and interactions within the network. These records are essential for monitoring, troubleshooting, and analyzing network performance.

[0021] The expression ‘trace reference (TR)’ used hereinafter in the specification refers to a unique identifier allocated per trace session, representing a trace configuration instance.

[0022] The expression ‘trace recording session reference (TRSR)’ used hereinafter in the specification refers to a unique session-specific ID used to correlate trace records collected during the same trace recording session.

[0023] The expression ‘NCGI (NR Cell Global Identity)’ used hereinafter in the specification refers to a globally unique identifier of a cell in a 5G network, composed of the Public Land Mobile Network (PLMN) ID and the NR Cell Identity (NCI), enabling precise identification of a serving NR cell.

[0024] The expression ‘Public Land Mobile Network (PLMN) ID’ used hereinafter in the specification refers to a unique identifier of a mobile network operator, comprising a Mobile Country Code (MCC) and a Mobile Network Code (MNC), which together uniquely identify a network in a specific country.

[0025] The expression ‘NR Cell Identity (NCI)’ used hereinafter in the specification refers to a 36-bit identifier uniquely identifying a cell within a PLMN, allowing differentiation between NR cells of a mobile network operator.

[0026] The expression ‘Mobile Country Code (MCC)’ used hereinafter in the specification refers to a three-digit code that uniquely identifies the country of the mobile network operator within the PLMN ID.

[0027] The expression ‘Mobile Network Code (MNC)’ used hereinafter in the specification refers to a two-or three-digit code identifying the specific mobile network within a country, used together with the MCC to form the PLMN ID.

[0028] The expression ‘AMF-UE-NGAP-ID’ used hereinafter in the specification refers to a unique identifier allocated by the Access and Mobility Management Function (AMF) to identify the UE-associated NGAP signalling connection on the N2 interface.

[0029] The expression ‘RAN-UE-NGAP-ID’ used hereinafter in the specification refers to a unique identifier assigned by the gNB to identify the UE- associated NGAP signalling connection at the RAN side.

[0030] The expression ‘Subscription Permanent Identifier (SUPI)’ used hereinafter in the specification refers to a globally unique and permanent identifier allocated to a subscriber, typically derived from the IMSI, and used for subscriber identification in 5G systems.

[0031] The expression ‘Mobile Subscriber Identification Number (MSIN)’ used hereinafter in the specification refers to the part of the IMSI that uniquely identifies a subscriber within a mobile network, excluding the MCC and MNC.

[0032] The expression ‘Next Generation Application Protocol (NGAP)’ used hereinafter in the specification refers to the signalling protocol used between the gNB and the AMF over the N2 interface in a 5G network, responsible for carrying UE and control plane -related signalling.

[0033] The expression ‘unique trace identifier’ used hereinafter in the specification refers to the combination of trace reference (TR) and trace recording session reference (TRSR), uniquely identifying a specific trace session for a subscriber in the network.

[0034] The expression ‘N2 interface’ used hereinafter in the specification refers to the reference point between the Radio Access Network (RAN), such as the gNB, and the Access and Mobility Management Function (AMF) in the 5G core network, responsible for carrying control plane signalling related to mobility management and session management.

[0035] The expression ‘N12 interface’ used hereinafter in the specification refers to the reference point between the Access and Mobility Management Function (AMF) and the Authentication Server Function (AUSF) in the 5G core network, used for carrying authentication-related signalling during user equipment registration or access procedures.

[0036] The expression ‘N13 interface’ used hereinafter in the specification refers to the reference point between the Authentication Server Function (AUSF) and the Unified Data Management (UDM) function in the 5G core network, used for retrieving subscription data and authentication credentials of the user.

[0037] The expression ‘International Mobile Subscriber Identity (IMSI)’ used hereinafter in the specification refers to a globally unique identifier assigned to a mobile subscriber, composed of the Mobile Country Code (MCC), Mobile Network Code (MNC), and Mobile Subscriber Identification Number (MSIN), and primarily used in legacy systems for identifying the user for authentication and mobility purposes.

[0038] The expression ‘Authentication Server Function (AUSF)’ used hereinafter in the specification refers to a network function in the 5G core network responsible for performing authentication procedures of user equipment (UE), by interacting with the Access and Mobility Management Function (AMF) over the N12 interface and with the Unified Data Management (UDM) over the N13 interface to validate subscription credentials and generate authentication vectors.

[0039] These definitions are in addition to those expressed in the art.BACKGROUND OF DISCLOSURE

[0040] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.

[0041] With the evolution of mobile networks toward fifth generation (5G) and beyond, there is an ever-increasing demand for high data rates, low latency, and support for a wide range of use cases such as enhanced mobile broadband (eMBB), massive machine-type communications (mMTC), and ultra-reliable low-latency communications (URLLC). To meet these demands and ensure service quality, network operators require comprehensive, real-time visibility into an end-to-end customer experience across different services and network domains.

[0042] The real-time visibility is enabled by software-based trace solutions, which provide agile, scalable, and real-time analytics related to subscriber behavior, network performance, and service health. These trace solutions rely on detailed signalling records collected from different network elements. In the context of 5G, a cell trace architecture mandates that a 5G new radio (NR) gnodeB (gNB) generates trace records containing standardized signalling information and, in some cases, vendor-specific message content. These trace records are collected andprocessed by a centralized trace control entity (TCE), which is responsible for subscriber session debugging, network troubleshooting, and analytics.

[0043] A fundamental requirement for effective trace-based analytics is accurate subscriber identity awareness in the trace records. However, due to stringent privacy protections in 5G networks, such as the introduction of a subscriber concealed identifier (SUCI), direct access to a subscription permanent identifier (SUPI), which is equivalent to an international mobile subscriber identity (IMSI) in fourth generation (4G), is limited. In 5G, the SUCI is used to conceal the SUPI using asymmetric encryption and only a home network is capable of decrypting the SUCI to recover the SUPI. As a result, the 5G NR gNB is not aware of the SUPI and cannot embed this identifier in the trace records it generates. Access and mobility management function (AMF) decodes the SUCI and retrieves the SUPI during an initial registration process, but this information is not propagated to a trace control entity (TCE) through standard trace procedures.

[0044] This lack of SUPI in gNB-generated trace records results in trace data that is subscriber-anonymous. Consequently, the TCE is unable to associate the trace records with specific subscriber sessions, thereby limiting the effectiveness of trace-based diagnostics, user-centric analytics, and network optimization. Current standard-based approaches attempt to solve this by introducing additional signalling steps where the gNB triggers the AMF to fetch and forward the SUPI to the TCE. However, this introduces complexity and processing overhead at both AMF and gNB nodes, which are critical control-plane functions in the 5G core. This overhead includes additional transaction processing, user equipment (UE) context fetching, and inter-node signalling.

[0045] There is, therefore, a need in the art to overcome the deficiencies of the prior arts.OBJECTIVES OF THE PRESENT DISCLOSURE

[0046] Some of the objectives of the present disclosure, which at least one embodiment herein satisfies, are as listed below.

[0047] An objective of the present disclosure is to provide a system and method for managing subscriber identity in a network by enriching a Subscription Permanent Identifier (SUPI) in trace records received from a 5G New Radio (NR) Next Generation Node B (gNB), without introducing any additional overhead at the 5G Core Network (CN) Access and Mobility Management Function (AMF) or at the gNB itself. This is achieved by utilizing SUCI information received during UE registration and correlates it with AMF interface data (N2, N12, N13) at the Trace Control Entity (TCE), rather than requiring modifications at the gNB or AMF. Thus, trace records from gNB are enriched with SUPI at TCE transparently, without impacting existing gNB or AMF workloads.

[0048] Another objective of the present disclosure is to eliminate the need for additional signalling triggers and context lookups at the AMF for enriching subscriber identity, thereby reducing processing overhead on critical core functions and improving overall system efficiency. This is achieved because the enrichment logic resides entirely in the TCE, where the algorithm taps AMF interfaces passively, extracts the required mapping between SUCI and SUPI, and enriches the gNB trace records. Therefore, no extra signalling is generated toward the AMF, and no context lookups are imposed on AMF, preserving its processing resources for control plane functions.

[0049] Yet another objective of the present disclosure is to enable SUPI enrichment at a Trace Control Entity (TCE) by tapping only N2, N12, and N13 interfaces at the AMF and executing correlation logic at the TCE, thereby avoiding any impact on session signalling, user-plane procedures, or ongoing service delivery in the 5G network. This is achieved because the solution monitors already existing AMF interfaces that carry registration and session management information, and correlates SUCI with SUPI at the TCE without introducing new message exchanges or interfering with user-plane data flow. Hence, service delivery in the 5G network continues unaffected while SUPI awareness is added in trace records.

[0050] Yet another objective of the present disclosure is to simplify and accelerate the integration of new Radio Access Network (RAN) vendors into a 5G network by providing a vendor-agnostic SUPI enrichment algorithm, thereby eliminating the need for trace record format alignment or SUPI enrichment development at the RAN node. This is achieved because the enrichment is entirely performed at the TCE, independent of gNB implementation or vendor-specific trace record formats. Since gNB only provides standard trace data, the TCE enrichment process automatically inserts SUPI information, ensuring that new gNB vendors can be integrated without requiring changes to their trace record generation process.

[0051] Yet another objective of the present disclosure is to reduce capital expenditure (CAPEX) by limiting data tapping requirements to a single network function, such as the AMF, thereby minimizing both infrastructure and operational costs associated with deploying a trace enrichment solution. This is achieved because the present disclosure requires tapping only the AMF interfaces (N2, N12, N13) to extract the SUCI-to-SUPI mapping. There is no need to deploy additional probes at multiple network functions (SMF, UPF, or gNB), thereby simplifying deployment, reducing hardware / software resource consumption, and lowering the cost of ownership.

[0052] Yet another objective of the present disclosure is to provide a lightweight, scalable, and future-ready trace record enhancement technique that does not require changes to existing 5G Core Network signalling or architecture, while supporting real-time subscriber traceability for monitoring, debugging, and analytics purposes. This is achieved because the enrichment logic is implemented at the TCE, which can scale elastically with network growth and adapt to future 5G use cases. Since it does not alter 5G core signalling or architecture, it integrates seamlessly with existing deployments and provides real-time SUPI-aware trace records, thereby enabling accurate subscriber session debugging, customer experience monitoring, and network analytics.

[0053] Other objectives and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.SUMMARY

[0054] In an exemplary embodiment, the present invention discloses a method for managing a subscriber identity in a network. The method includes capturing, by a trace control entity (TCE), a plurality of mapping parameters based on signalling information associated with at least one subscriber session. The method further includes receiving, by the TCE, a plurality of trace records associated with the at least one subscriber session from a network node. The method further includes correlating, by the TCE, the plurality of captured mapping parameters and the plurality of received trace records to obtain a set of correlation parameters associated with the subscriber identity. The method further includes mapping, by the TCE, the set of obtained correlation parameters to a trace record of the plurality of received trace records for managing the subscriber identity within the network.

[0055] In some embodiments, the at least one subscriber session includes at least one of a registration session, and an authentication session.

[0056] In some embodiments, the signalling information is obtained based on a tapping mechanism implemented on at least one network interface used for communication between network entities.

[0057] In some embodiments, the plurality of mapping parameters associated with the at least one subscriber session includes at least four of a new radio cell global identity (NCGI), a subscription permanent identifier (SUPI), an access and mobility management function user equipment next generation application protocol identifier (AMF-UE-NGAP-ID), and a radio access network user equipment next generation application protocol identifier (RAN-UE-NGAP-ID).

[0058] In some embodiments, the plurality of trace records associated with the at least one subscriber session includes at least four of a new radio cell globalidentity (NCGI), an access and mobility management function user equipment next generation application protocol identifier (AMF-UE-NGAP-ID), a radio access network user equipment next generation application protocol identifier (RAN-UE- NGAP-ID), and a unique trace identifier.

[0059] In some embodiments, the set of correlation parameters associated with the subscriber identity includes both a unique trace identifier, and a subscription permanent identifier (SUPI).

[0060] In an exemplary embodiment, a system for managing a subscriber identity in a network is disclosed. The system includes a trace control entity (TCE). The TCE includes a parameter capturing module configured to capture a plurality of mapping parameters based on signalling information associated with at least one subscriber session. The TCE further includes a receiving module configured to receive a plurality of trace records associated with the at least one subscriber session from a network node. The TCE further includes a correlation module configured to correlate the plurality of captured mapping parameters and the plurality of received trace records to obtain a set of correlation parameters associated with the subscriber identity. The TCE further includes a mapping module configured to map the set of obtained correlation parameters to a trace record of the plurality of received trace records for managing the subscriber identity within the network.

[0061] In an exemplary embodiment, a user equipment (UE) communicatively coupled with a network is disclosed. The coupling includes receiving, by the network, a connection request from the UE. The coupling further includes sending, by the network, an acknowledgment of the connection request to the UE. The coupling further includes transmitting a plurality of signals in response to the connection request. A subscriber identity in the network is managed by a method. The method includes capturing, by a trace control entity (TCE), a plurality of mapping parameters based on signalling information associated with at least one subscriber session. The method further includes receiving, by the TCE, a plurality of trace records associated with the at least one subscriber session from a networknode. The method further includes correlating, by the TCE, the plurality of captured mapping parameters and the plurality of received trace records to obtain a set of correlation parameters associated with the subscriber identity. The method further includes mapping, by the TCE, the set of obtained correlation parameters to a trace record of the plurality of received trace records for managing the subscriber identity within the network.

[0062] In an exemplary embodiment, a computer program product including a non-transitory computer-readable medium including instructions that, when executed by one or more processors, cause the one or more processors to execute a method for managing a subscriber identity in a network. The method includes capturing, by a trace control entity (TCE), a plurality of mapping parameters based on signalling information associated with at least one subscriber session. The method further includes receiving, by the TCE, a plurality of trace records associated with the at least one subscriber session from a network node. The method further includes correlating, by the TCE, the plurality of captured mapping parameters and the plurality of received trace records to obtain a set of correlation parameters associated with the subscriber identity. The method further includes mapping, by the TCE, the set of obtained correlation parameters to a trace record of the plurality of received trace records for managing the subscriber identity within the network.

[0063] The foregoing general description of the illustrative embodiments and the following detailed description thereof are merely exemplary aspects of the teachings of this disclosure and are not restrictive.BRIEF DESCRIPTION OF DRAWINGS

[0064] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating theprinciples of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes the disclosure of electrical components, electronic components or circuitry commonly used to implement such components.

[0065] FIG. 1 illustrates an exemplary network architecture for implementing a system to manage a subscriber identity in a network, in accordance with embodiments of the present disclosure.

[0066] FIG. 2 illustrates an exemplary block diagram of the system for managing the subscriber identity in the network, in accordance with embodiments of the present disclosure.

[0067] FIG. 3A illustrates an exemplary system architecture for managing trace records generated by a network node, in accordance with embodiments of the present disclosure.

[0068] FIG. 3B illustrates another exemplary system architecture for managing the trace records generated by the network node, in accordance with embodiments of the present disclosure.

[0069] FIG. 4A illustrates an exemplary signalling flow for registration and authentication monitoring performed by a trace control entity (TCE), in accordance with embodiments of the present disclosure.

[0070] FIG. 4B illustrates another exemplary signalling flow for registration and authentication monitoring performed by the TCE, in accordance with embodiments of the present disclosure.

[0071] FIG. 5 illustrates an exemplary process flow for integrating subscriber identity information within the trace records, in accordance with embodiments of the present disclosure.

[0072] FIG. 6 illustrates an exemplary flowchart of a method for managing the subscriber identity in the network, in accordance with embodiments of the present disclosure.

[0073] FIG. 7 illustrates an exemplary computer system in which or with which the system and method may be implemented, in accordance with embodiments of the present disclosure.

[0074] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100 - Network Architecture102 - System104-1, 104-2. . . 104-N - Plurality of User Equipments (UEs)106-1, 106-2... 106-N - Plurality of Users108 - Network200 - Block Diagram202 - Processor(s)204 - Memory206 - Interface(s)208 - Processing Engine210 - Database212 - Parameter Capturing Module214 - Receiving Module216 - Correlation Module- Mapping Module A, 300B - System Architecture - gNodeB - Access And Mobility Management Function (AMF) - Authentication Server Function (AUSF) - Trace Control Entity (TCE) - N2 Interface - N 12 Interface - Unified Data Management (UDM) - N13 Interface A, 400B - Signalling Flow - Process Flow -Flowchart - Computer System - External Storage Device - Bus - Main Memory - Read-Only Memory - Mass Storage Device - Communication Ports - ProcessorDETAILED DESCRIPTION OF DISCLOSURE

[0075] In the following description, for the purposes of explanation, various specific details are set forth to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address any of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein. Example embodiments of the present disclosure are described below, as illustrated in various drawings in which like reference numerals refer to the same parts throughout the different drawings.

[0076] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.

[0077] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail to avoid obscuring the embodiments.

[0078] Also, it is noted that individual embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, astructure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.

[0079] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive like the term “comprising” as an open transition word without precluding any additional or other elements.

[0080] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0081] The terminology used herein is to describe embodiments only and is not intended to be limiting the disclosure. As used herein, the singular forms “a” “an”,and “the” are intended to include the plural forms as well, unless the context indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any combinations of one or more of the associated listed items. It should be noted that the terms “mobile device”, “user equipment”, “user device”, “communication device”, “device” and similar terms are used interchangeably for the purpose of describing the invention. These terms are not intended to limit the scope of the invention or imply any specific functionality or limitations on the described embodiments. The use of these terms is solely for convenience and clarity of description. The invention is not limited to any device or equipment, and it should be understood that other equivalent terms or variations thereof may be used interchangeably without departing from the scope of the invention as defined herein.

[0082] As used herein, an “electronic device” or “portable electronic device” or “user device” or “communication device” or “user equipment” or “device” refers to any electrical, electronic, electromechanical, and computing device. The user device can receive and / or transmitting one or parameters, performing fimction / s, communicating with other user devices, and transmitting data to the other user devices. The user equipment may have a processor, a display, a memory, a battery, and an input-means such as a hard keypad and / or a soft keypad. The user equipment may be capable of operating on any radio access technology including but not limited to IP-enabled communication, Zig Bee, Bluetooth, Bluetooth Low Energy, Near Field Communication, Z-Wave, Wi-Fi, Wi-Fi direct, etc. For instance, the user equipment may include, but not limited to, a mobile phone, smartphone, virtual reality (VR) devices, augmented reality (AR) devices, laptop, a general-purpose computer, desktop, personal digital assistant, tablet computer,mainframe computer, or any other device as may be obvious to a person skilled in the art for implementation of the features of the present disclosure.

[0083] Further, the user device may also comprise a “processor” or “processing unit” includes processing unit, wherein processor refers to any logic circuitry for processing instructions. The processor may be a general-purpose processor, a special purpose processor, a conventional processor, a digital signal processor, a plurality of microprocessors, one or more microprocessors in association with a DSP core, a controller, a microcontroller, Application Specific Integrated Circuits, Field Programmable Gate Array circuits, any other type of integrated circuits, etc. The processor may perform signal coding data processing, input / output processing, and / or any other functionality that enables the working of the system according to the present disclosure. More specifically, the processor is a hardware processor.

[0084] Aspects of this disclosure are directed to a system and method for enabling subscriber-aware traceability in a 5G communication network using enhanced trace correlation at a trace control entity (TCE). In existing cell trace architectures, trace records generated by gNB lack a subscription permanent identifier (SUPI) of a user equipment (UE), as the subscription permanent identifier (SUPI) is protected and not visible to the gNB. The trace records sent to the TCE include signalling and diagnostic information but are devoid of explicit subscriber identity, making it challenging to perform user-specific debugging, analytics, or lawful interception. This lack of correlation results in the trace records that are disjointed from subscriber sessions, thereby limiting the effectiveness of trace solutions in modem 5G deployments.

[0085] To overcome this limitation, the present disclosure introduces a system and method for enriching the trace records with subscriber identity information by employing the TCE that performs passive tapping of signalling interfaces such as N2, N 12, and N13. The TCE extracts a set of correlation parameters, and aligns the set of correlation parameters with trace sessions uniquely identified by trace reference (TR) and trace recording session reference (TRSR) received from thegNB. The system maps the SUPI to each trace record associated with a common TR+TRSR, thereby achieving end-to-end correlation of subscriber sessions with their respective trace logs. This disclosure enables real-time, non-intrusive, and standards-compliant subscriber-level analytics, enhances network observability, and provides robust support for operations, troubleshooting, and compliance in 5G networks.

[0086] The various embodiments throughout the disclosure will be explained in more detail with reference to FIG. 1- FIG. 7.

[0087] FIG. 1 illustrates an exemplary network architecture (100) for implementing a system (102) to manage a subscriber identity in a network (108), in accordance with embodiments of the present disclosure.

[0088] Referring to FIG. 1, the network architecture (100) may include one or more user equipment (UEs) (104-1, 104-2... 104-N) that may be associated with one or more users (106-1, 106-2... 106-N) and the system (102) in an environment. In an embodiment, the one or more UEs (104-1, 104-2... 104-N) may be communicated to the system (102) through the network (108). A person of ordinary skill in the art will understand that the one or more UEs (104-1, 104-2... 104-N) may be individually referred to as the UE (104) and collectively referred to as the UEs (104). A person of ordinary skill in the art will appreciate that the terms “computing device(s)” and “UE” may be used interchangeably throughout the disclosure. Although three UEs (104) are depicted in the FIG. 1, however any number of the UE (104) may be included without departing from the scope of the ongoing description. Similarly, a person of ordinary skill in the art will understand that the one or more users (106-1, 106-2... 106-N) may be individually referred to as the user (106) and collectively referred to as the users (106).

[0089] In an embodiment, the UE (104) may include smart devices operating in a smart environment, for example, an Internet of Things (loT) system. In such embodiment, the UE (104) may include, but is not limited to, smartphones, smart watches, smart sensors (e.g., mechanical, thermal, electrical, magnetic, etc.),networked appliances, networked peripheral devices, networked lighting systems, communication devices, networked vehicle accessories, networked vehicular devices, smart accessories, tablets, smart television (TV), computers, a smart security system, a smart home system, other devices for monitoring or interacting with or for the users (106) and / or entities, or any combination thereof. A person of ordinary skill in the art will appreciate that the UE (104) may include, but not be limited to, intelligent multi-sensing, network-connected devices that can integrate seamlessly with each other and / or with a central server or a cloud-computing system or any other device that is network-connected.

[0090] In an embodiment, the UE (104) may include but is not limited to, a handheld wireless communication device (e.g., a mobile phone, a smartphone, a phablet device, and so on), a wearable computer device (e.g., a head-mounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a global positioning system (GPS) device, a laptop, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, and / or any other type of computer device with wireless communication capabilities, and the like.

[0091] In an embodiment, the UE (104) may include, but is not limited to, any electrical, electronic, electro-mechanical, or equipment, or a combination of one or more of the above devices, such as virtual reality (VR) devices, augmented reality (AR) devices, a general-purpose computer, a desktop, a personal digital assistant, a mainframe computer, or any other computing device. In another embodiment, the UE (104) may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as a camera, an audio aid, a microphone, a keyboard, and input devices for receiving input from the user (106) or the entity such as a touchpad, a touch -enabled screen, an electronic pen, and the like. A person of ordinary skill in the art will appreciate that the UE (104) may not be restricted to the mentioned devices and various other devices may be used.

[0092] Referring to FIG. 1, the UE (104) may operate based on a set of executable instructions residing within its operating system. The executable instructions are configured to correlate mapping parameters and trace records to obtain a corresponding subscription permanent identifier (SUPI) for each trace record, without requiring direct signalling or lookup from an access and mobility management function (AMF) or a next generation node B (gNB), thereby reducing processing overhead and simplifying trace data enrichment.

[0093] In an embodiment, the UE (104) may communicate with the system (102) through the network (108) for sending or receiving various types of data. In an embodiment, the network (108) may include at least one of a 5G network, a 6G network, or the like. The network (108) may enable the UE (104) to communicate with other devices in the network architecture (100) and / or with the system (102). The network (108) may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network (108) may be implemented as, or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a virtual private network (VPN), the Internet or the like.

[0094] In an embodiment, the network (108) may include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth. The network (108) may also include, by way of example but not limitation, one or more of a radio access network (RAN), a wireless network, a wired network, the internet, the intranet, a public network, a private network, a packet-switched network, a circuit- switched network, an ad hoc network, an infrastructure network, a public-switched telephone network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof. In an embodiment, the system (102) may be connected to backend servers (not shown).

[0095] Although the FIG. 1 shows exemplary components of the network architecture (100), in other embodiments, the network architecture (100) may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, or alternatively, one or more components of the network architecture (100) may perform functions described as being performed by one or more other components of the network architecture (100).

[0096] FIG. 2 illustrates an exemplary block diagram of the system (102) for managing the subscriber identity in the network (108), in accordance with embodiments of the present disclosure. FIG. 2 with reference to FIG. 1, illustrates the system (102), that includes one or more processor(s) (202), a memory (204), an interface(s) (206), a processing engine (208), and a database (210).

[0097] The one or more processor(s) (202) may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuitries, and / or any devices that process data based on operational instructions. Among other capabilities, the one or more processor(s) (202) may be configured to fetch and execute computer-readable instructions stored in the memory (204) of the system (102). The memory (204) may be configured to store one or more computer-readable instructions or routines in a non-transitory computer-readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory (204) may include any non-transitory storage device, including, for example, volatile memory such as random-access memory (RAM), or non-volatile memory such as erasable programmable read-only memory (EPROM), flash memory, and the like.

[0098] In an embodiment, the interface(s) (206) may comprise a variety of interfaces, for example, interfaces for data input and output devices (RO), storage devices, and the like. The interface(s) (206) may facilitate communication through the system (102). The interface(s) (206) may also provide a communication pathway for one or more components of the system (102). Examples of suchcomponents include, but are not limited to, the processing engine (208) and the database (210).

[0099] In an embodiment, the processing engine (208) may be implemented as a combination of hardware and programming, for example, programmable instructions, to implement one or more functionalities of the processing engine (208). In examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing engine (208) may be processor-executable instructions stored on a non-transitory machine -readable storage medium, and the hardware for the processing engine (208) may comprise a processing resource, for example, one or more processors, to execute such instructions. In the present examples, the machine-readable storage medium may store instructions that, when executed by the processing resource, implement the processing engine (208). In such examples, the system (102) may comprise the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system (102) and the processing resource. In other examples, the processing engine (208) may be implemented by electronic circuitry.

[0100] In an embodiment, the database (210) may include data that may be either stored or generated as a result of functionalities implemented by any of the components of the processor (202) or the processing engine (208). In an embodiment, the database (210) may be separate from the system (102). In an embodiment, the database (210) may store data that may be generated as a result of functionalities implemented by any of the components of the processor (202) or the processing engine (208). In an embodiment, the database (210) may be indicative of including, but not limited to, a relational database, a distributed database, a cloudbased database, or the like. In an exemplary embodiment, the processing engine (208) may include one or more units having functions that may include, but are not limited to, testing, storage, and peripheral functions, such as a wireless communication unit for remote operation and the like.

[0101] In an embodiment, the processing engine (208) may be implemented as a standalone unit that is communicatively coupled to a trace control entity (TCE) (not shown). In another embodiment, the processing engine (208) may be integrated within the TCE, sharing processing and storage resources for efficient trace record enrichment. In an embodiment, the processing engine (208) may include a plurality of functional modules that enable the TCE to perform one or more operations for managing the subscriber identity in the network (108). The functional modules may include, but are not limited to, a parameter capturing module (212), a receiving module (214), a correlation module (216), and a mapping module (218).

[0102] The parameter capturing module (212) is configured to capture signalling information associated with a subscriber session by monitoring one or more network interfaces in the network (108). The subscriber session includes at least one of a registration session and an authentication session. In an embodiment, the registration session refers to a signalling procedure initiated by the UE (104) to establish its presence within a mobile network, after initial power-on, movement into anew tracking area, or following a network-initiated deregistration. As defined in registration management procedures, the UE needs to register with the network to be authorized for receiving services, to enable mobility tracking, and to ensure reachability. Depending on the scenario, the UE may initiate different types of registration, including initial registration to the 5GS, mobility registration update when moving to a new tracking area or when updating capabilities, periodic registration update after a predefined time of inactivity, emergency registration, disaster roaming registration, or Standalone Non-Public Network (SNPN) onboarding registration. The registration session includes an exchange of signalling messages between the UE (104), a network node (i.e., gNB), and anetwork function (i.e., AMF). The exchange includes a transmission of a registration request from the UE (104), carrying a concealed user identifier such as a subscriber concealed identifier (SUCI) or alternatively a Fifth-Generation Globally Unique Temporary Identifier (5G-GUTI) or Permanent Equipment Identifier (PEI), which is forwarded by the gNB to the AMF.

[0103] In cases where the UE has no established Non-Access Stratum (NAS) security context, the Registration Request may include certain cleartext Information Elements (IEs) such as the registration type, SUCI or 5G-GUTI or PEI, security parameters, indication of EPS mobility, Public Land Mobile Network (PLMN) with disaster condition, or the Network Identifier (NID) for SNPN-based registration. As specified in the standard, the Registration Request may carry multiple IEs, including registration type, last visited Tracking Area Identity (TAI), security parameters, Requested Network Slice Selection Assistance Information (NS SAI), UE radio capability information, Policy Support Information (PSI) container, paging -related parameters, and disaster roaming indications. During the initial registration, the AMF may retrieve the PEI, perform validation checks, and update subscription information with other core functions such as the Unified Data Management (UDM), Session Management Function (SMF), and Policy Control Function (PCF), thereby ensuring synchronization of the subscriber profile across the core network. The AMF may further provide the UE with Steering of Roaming (SoR) information from the Home PLMN (HPLMN), including a list of preferred PLMN and access technology combinations, prioritized SNPNs, or guidance on network selection behavior, with acknowledgement procedures managed between the AMF and the UE.

[0104] Further, during initial registration or disaster roaming registration, the UE shall indicate its identity in a decreasing order of preference: (i) a 5G-GUTI mapped from a valid Evolved Packet System Globally Unique Temporary Identifier (EPS-GUTI), (ii) a native 5G-GUTI assigned by the target Public Land Mobile Network (PLMN), (iii) a native 5G-GUTI from an equivalent PLMN, (iv) a native 5G-GUTI from any other PLMN, and (v) if none of the foregoing is available, the SUCI.

[0105] The Registration Request is forwarded by the gNB to the AMF, which may retrieve the PEI, validate the subscriber identity, and update subscription information with other core functions such as the Unified Data Management (UDM), Session Management Function (SMF), and Policy Control Function (PCF).The AMF also provides Steering of Roaming (SoR) information from the Home Public Land Mobile Network (HPLMN) and associates radio-layer identifiers such as the New Radio Cell Global Identity (NCGI) and Radio Access Network User Equipment Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) with core identifiers such as the AMF User Equipment Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID) to complete the registration context. The purpose of the registration session is to enable the UE (104) to obtain network access, support mobility management, ensure continuous reachability, and facilitate subsequent service establishment.

[0106] The authentication session refers to a security procedure performed to verify a legitimacy and credentials of the UE (104) attempting to access the network (108). This procedure is initiated upon receipt of the SUCI in the registration request by the AMF, which then forwards an authentication request to the network function (i.e., an authentication server function (AUSF)) to obtain an authentication vector for the subscriber. The authentication session includes a sequence of challenge response exchanges between the AMF, AUSF, and UE (104), where the AMF delivers authentication challenges to the UE (104) and collects a corresponding response (e.g., RES*) for verification. According to the standard, the initiation of primary authentication involves the Security Anchor Function (SEAF) invoking the Nausf_UEAuthentication service whenever the UE attempts registration using either the SUCI or a 5G Globally Unique Temporary Identifier (5G-GUTI). The Nausf_UEAuthentication_Authenticate Request is sent to the AUSF, including the SUCI or the Subscription Permanent Identifier (SUPI) along with the serving network name. If the SUCI is received, the Subscription Identifier De-concealing Function (SIDF) de-conceals it to obtain the SUPI, after which the Unified Data Management (UDM) in conjunction with the Authentication credential Repository and Processing Function (ARPF) selects the authentication method.

[0107] In the case of a 5G Authentication and Key Agreement (5G AKA) procedure, the UDM / ARPF generates a 5G Home Environment Authentication Vector (5G HE AV) by deriving a key (KAUSF), computing the expected response(XRES), and assembling a random challenge (RAND), an authentication token (AUTN), XRES, and KAUSF. This 5G HE AV is returned to the AUSF in a Nudm UEAuthentication Get Response, possibly including the SUPI (if SUCI was used), and additional indicators such as AKMA or routing information. The AUSF stores XRES, computes a hash of XRES (HXRES), and derives a session key (KSEAF), then prepares a 5G Serving Environment Authentication Vector (5G SE AV) consisting of RAND, AUTN, and HXRES, which is sent to the SEAF. The SEAF then issues an Authentication Request containing RAND, AUTN, a NAS key set identifier (ngKSI), and an Additional Binding parameter (ABBA) to the UE. The UE verifies AUTN freshness using its USIM, computes a response (RES), cipher key (CK), integrity key (IK), and derives RES, KAUSF, and KSEAF, before sending RES back in an Authentication Response. The SEAF computes HRES from the received RES* and compares it with HXRES to confirm authenticity at the serving network level. Subsequently, RES is forwarded to the AUSF, which compares it with the stored XRES to confirm authentication at the home network level. Upon successful verification, the AUSF sends a Nausf_UEAuthentication_Authenticate Response to the SEAF including the result, KSEAF, and possibly the SUPI. The SEAF then derives an Access and Mobility Management Function key (KAMF) from KSEAF, ABBA, and SUPI, passes ngKSI and KAMF to the AMF, and the AMF establishes the Non-Access Stratum (NAS) security context via a Security Mode Command.

[0108] The successful conclusion of the authentication session establishes a secure, trusted relationship between the subscriber and the network (108), confirming that the subscriber possesses valid credentials associated with a subscription permanent identifier (SUPI) and authorizing network service access.

[0109] In an embodiment, the monitoring of the network interfaces is performed by implementing a tapping mechanism on at least one of the network interfaces used for communication between the network entities. As used herein, the tapping mechanism refers to a passive method or an active method of intercepting and duplicating control-plane traffic flowing over the network interfacesuch as, but not limited to, N2, N12, or N13 without interrupting or altering an ongoing communication. For example, a mirror port or a switched port analyzer (SPAN) on a switch / router may be configured to replicate packets exchanged between the AMF and a session management function (SMF), and forward the packets to a monitoring system where the parameter capturing module (212) is deployed. In other embodiments, the parameter capturing module (212) may utilize one or more of the following mechanisms for monitoring the network interfaces, such as but not limited to, inline probes, interface-level packet sniffing, traffic replication via network function virtualization (NFV), and so forth. To ensure data integrity and confidentiality, the tapping mechanism may be secured using cryptographic protocols, such as, but not limited to, a transport layer security (TLS) or other competent mechanisms compliant with network security standards. This enables the parameter capturing module (212) to safely and accurately extract the signalling information, such as those exchanged between the gNB and AMF over the N2 interface, between the AMF and AUSF over the N12 interface, or between the AUSF and a unified data management (UDM) over the N13 interface for subsequent processing, session reconstruction, and analysis.

[0110] As used herein, the signalling information refers to control-plane data exchanged between the network entities and / or between UE and a core or access network, which is used to establish, manage, authenticate, and release communication sessions. In the network (108), the signalling information may include, but not limited to, registration messages, authentication request / response messages, and so forth. The registration messages may include, but are not limited to, the SUCI, the NCGI, the AMF-UE-NGAP-ID, the RAN-UE-NGAP-ID, and so forth. The authentication request / response messages may include, but not limited to, the SUPI, the AMF-UE-NGAP-ID, and so forth.

[0111] In one example implementation, the signalling information may be associated with a registration and authentication flow of the UE (104) within a 5G network. For instance, during an initial registration procedure, the UE (104) may transmit the registration request message containing the SUCI towards the AMF.Along a signalling path, the gNB allocates the RAN-UE-NGAP-ID, and a serving cell identity is provided in the form of the NCGI. The AMF, upon receiving the registration request, allocates the AMF-UE-NGAP-ID to maintain session context. Subsequently, the AMF interacts with the AUSF to initiate an authentication process, during which the SUPI may be derived or returned in response messages. These exchanged control-plane messages and associated identifiers, such as the SUCI, NCGI, RAN-UE-NGAP-ID, AMF-UE-NGAP-ID, and SUPI, constitute examples of the signalling information captured by the parameter capturing module (212) for managing and correlating subscriber session data across the network (108).

[0112] Further, as used herein, the term “subscriber session” refers to a logical communication context established between the UE (104) and the network (108) to support data and / or control plane communication, including but not limited to registration, authentication, mobility management, and session management functions.

[0113] As used herein, the term “network entities” refer to functional components or logical nodes within the network, such as 5GC or access network, that participate in control or user plane operations for managing connectivity, mobility, session, and authentication of the UE. The network entities include, but not limited to, the network functions and network nodes. In an embodiment, the network functions may be, but not limited to, the AMF, the SMF, a user plane function (UPF), the AUSF, the UDM, and so forth. In an embodiment, the network nodes may be radio access network (RAN) nodes such as the gNB nodes. In an embodiment, the network entities communicate with one another via the network interfaces to exchange the signalling information.

[0114] The network interface refers to a defined point of interaction between the network entities (e.g., between the gNB and the AMF, or between the AMF and AUSF), over which the signalling messages are exchanged as part of control plane operations. The network interfaces may be, but not limited to, NG-C, Nl, N8, N10,and so forth. In a preferred embodiment, the network interfaces may be N2, N12 and N13.

[0115] In the network (108), the network entities may be interconnected through the network interfaces to support subscriber registration, authentication, session establishment, policy enforcement, and data transfer. For instance, when the UE (104) initiates connectivity, the network node (i.e., gNB) communicates with the network function (i.e., AMF) via the N2 interface, which carries the signalling messages such as registration requests. The AMF, acting as a core mobility anchor, then interacts with the network function (i.e., AUSF) using the N12 interface to authenticate the subscriber based on the SUCI or SUPI. For retrieving subscription-related policies and authentication vectors, the AUSF may further engage with the UDM over the N13 interface.

[0116] These interfaces such as N2 between the gNB and AMF, N12 between the AMF and AUSF, and N13 between the AUSF and UDM are integral to the exchange of signalling information required for access control and session establishment. Each network interface supports standardized protocols and message formats (e.g., next generation application protocol (NGAP), hypertext transfer protocol version 2 (HTTP / 2)) to ensure interoperability between different network functions. The overall coordination across these network interfaces enables seamless end-to-end communication services for the UE (104).

[0117] Further, as used herein, the term “SUCI” refers to a privacy-preserving identifier generated by the UE to protect a permanent identity of the subscriber, such as the SUPI, during transmission over the access network. The SUCI is derived by encrypting the SUPI using a public key of a home network. For example, the UE (104) with a SUPI of imsi-001010123456789 may generate a corresponding SUCI such as suci-0-001-01-0-0-0-alb2c3d4e5f6, where 0 is the SUCI type, 001 is a mobile country code (MCC), 01 is a mobile network code (MNC), and a trailing encrypted string represents a concealed SUPI using an operator’s public key. TheSUCI is included in initial registration messages sent by the UE (104) to the AMF to initiate secure identification and authentication without revealing the SUPI.

[0118] Further, as used herein, the NCGI refers to a globally unique identifier for a cell in the 5G NR access network. The NCGI is composed of a public land mobile network (PLMN) ID and an NR cell identity (NCI). The PLMN ID includes the MCC and MNC, while the NCI is a unique identifier assigned to the NR cell. For example, the NCGI may be represented as 001-01-0xABC123, where 001 is the MCC (e.g., India), 01 is the MNC (e.g., Jio), and 0xABC123 is a 36-bit NR cell identity in a hexadecimal format.

[0119] As used herein, the AMF-UE-NGAP-ID refers to a unique identifier assigned by the AMF to identify a UE-associated signalling context. This identifier is used within a next generation application protocol (NGAP) messages exchanged between the AMF and the gNB over the N2 interface. For example, when the UE (104) initiates the registration request, the AMF assigns the AMF-UE-NGAP-ID, such as 109876543, and includes it in all subsequent messages associated with that UE context. As used herein, the term “RAN-UE-NGAP-ID” refers to a unique identifier allocated by the gNB to distinguish UEs over the N2 interface. The RAN- UE-NGAP-ID is a locally unique within the gNB and is used in NGAP signalling to identify UE-associated contexts from a RAN side.

[0120] For example, when the UE (104) connects to the gNB, the gNB may assign the RAN-UE-NGAP-ID, such as 56789, which is later included in NGAP messages along with the AMF-UE-NGAP-ID to maintain UE-specific context.

[0121] As used herein, the SUPI refers to a globally unique and permanent identifier allocated to the subscriber by the home network operator. The SUPI is used to uniquely identify a subscription within the 5G core network and is stored in the UE (104) and the UDM function of the core network. In 3GPP systems, a most common format of the SUPI is based on the IMSI. The IMSI-based SUPI consists of the MCC, the MNC, and a mobile subscriber identification number (MSIN). For example, the SUPI in IMSI format may appear as 001019876543210, where 001 isthe MCC (e.g., test network or India), 01 is the MNC (e.g., Jio or Vodafone), 9876543210 is the MSIN identifying the individual subscription.

[0122] The parameter capturing module (212) is configured to capture a plurality of mapping parameters based on the signalling information associated with the subscriber session. The mapping parameters includes at least four of the NCGI, the SUPI, the AMF-UE-NGAP-ID, the RAN-UE-NGAP-ID, and so forth. In one embodiment, the mapping parameters may be generated by logically correlating the registration messages and authentication request / response messages that are captured during the subscriber session. The parameter capturing module (212) may be configured to observe the signalling messages exchanged during the registration procedure (e.g., Initial UE Message, Registration Request) and the authentication procedure (e.g., Authentication Request, Authentication Response) across the one or more network interfaces. In an embodiment, the parameter capturing module (212) may be configured to observe the signalling information exchanged across the network interfaces such as N2 (between gNB and AMF) and N 12 (between AMF and AUSF). In another embodiment, the parameter capturing module (212) may be configured to observe the signalling information exchanged across the network interfaces such as N2 (between gNB and AMF) and N13 (between AUSF and UDM).

[0123] During the registration phase, the parameter capturing module (212) extracts the RAN-UE-NGAP-ID, assigned by the gNB and included in the initial UE Message; the NCGI, included in a user location information within NGAP signalling; the SUCI, included in a non-access stratum (NAS) registration request payload (encapsulated in NGAP signalling).

[0124] During the authentication phase, the parameter capturing module (212) captures the SUPI, which is derived by de-concealing the SUCI after authentication (by the AUSF or UDM); and the AMF-UE-NGAP-ID, which is assigned by the AMF and appears in messages such as an initial context setup request. In anembodiment, to generate the mapping parameters, the parameter capturing module (212) performs the following correlations.

[0125] The parameter capturing module (212) maps the RAN-UE-NGAP-ID (used by the gNB) with the AMF-UE-NGAP-ID (used by the AMF) by identifying the NGAP messages that carry both identifiers together (e.g., initial context setup request, UE context release messages). To associate the SUCI with the SUPI, the parameter capturing module (212) uses an authentication message received from the AUSF, which includes the SUPI corresponding to the earlier SUCI transmitted in the authentication request. This correlation is established using a common session context, such as a transaction ID or temporary identifier. Further, the parameter capturing module (212) links the NCGI (cell ID) with the RAN-UE- NGAP-ID based on a same registration transaction, where the cell ID is included in the initial registration signalling sent via the gNB. By maintaining contextual integrity across these signalling procedures, the parameter capturing module (212) constructs a unique mapping that links: a physical access point (NCGI), the session identifiers used by the gNB and AMF (RAN-UE-NGAP-ID and AMF-UE-NGAP- ID), and the subscriber identity (SUPI).

[0126] For example, consider the UE (104) initiating a registration procedure by sending a registration request from a specific cell. The registration request is forwarded by the gNB to the AMF over the N2 interface, and includes the RAN- UE-NGAP-ID (e.g., “0xA23B”) and the NCGI (e.g., “001-01-23-4567”, identifying the serving cell). The AMF responds by generating the AMF-UE- NGAP-ID (e.g., “0xlD7F”) and uses it in subsequent NGAP messages such as the initial context setup request, which are observed on the same N2 interface.

[0127] Simultaneously, the registration request carries the SUCI (e.g., “suci-0- 001-01-0-0- l-abcdefl234567890”) that is forwarded by the AMF to the AUSF over the N12 interface as part of the authentication request. The AUSF processes the authentication request and returns the corresponding SUPI (e.g., “imsi- 001010123456789”) in the authentication response.

[0128] The parameter capturing module (212), by monitoring both the N2 and N 12 interfaces, records the mapping between RAN-UE-NGAP-ID (“0xA23B”) and AMF-UE-NGAP-ID (“0xlD7F”) from the NGAP messages, the association between SUCI and SUPI from the authentication exchange, and the link between NCGI and RAN-UE-NGAP-ID from the initial registration message. By correlating these data points, the parameter capturing module (212) establishes a consolidated mapping: such as: NCGI: “001-01-23-4567”, RAN-UE-NGAP-ID: “0xA23B”, AMF-UE-NGAP-ID: “0xlD7F”, and SUPI: “imsi-001010123456789”.

[0129] In another example, when the UE (104) initiates a registration procedure, a registration request containing the SUCI (e.g., “suci-0-001-01-0-0-1- abcdef9876543210”) is transmitted by the gNB to the AMF via the N2 interface, along with identifiers such as NCGI (e.g., “001-01-10-5678”) and RAN-UE- NGAP-ID (e.g., “0xC45E”). Upon receiving the request, the AMF generates a unique AMF-UE-NGAP-ID (e.g., “0x239A”) and sends this unique AMF-UE- NGAP-ID in subsequent NGAP messages, such as the initial context setup request and UE context release command.

[0130] As part of the authentication and registration handling, the AMF forwards the SUCI to the AUSF on the N12 interface, which in turn queries the UDM function over the N13 interface to resolve the SUPI and retrieve associated subscriber data (e.g., subscription profile, network access restrictions, service authorization, etc.).

[0131] The parameter capturing module (212) monitors: the N2 interface, capturing the RAN-UE-NGAP-ID, NCGI, and AMF-UE-NGAP-ID from the NGAP messages, the N12 interface, capturing the forwarding of SUCI from AMF to AUSF, and the N13 interface, observing the query and response between AUSF and UDM, which includes the SUPI (e.g., “imsi-001010765432109”). Based on this observed signalling, the parameter capturing module (212) correlates: RAN-UE- NGAP-ID (“0xC45E”) and AMF-UE-NGAP-ID (“0x239A”) from N2 signalling, SUCI to SUPI mapping from N12 / N13 signalling involving AUSF and UDM,NCGI from the initial registration message. From this correlation, the parameter capturing module (212) constructs a mapping such as: NCGI: “001-01-10-5678”, RAN-UE-NGAP-ID: “0xC45E”, AMF-UE-NGAP-ID: “0x239A”, and SUPI: “imsi-001010765432109”.

[0132] In parallel, the receiving module (214) may be configured to receive the trace records associated with the subscriber session from the network node. The trace records include, but not limited to, the NCGI, the AMF-UE-NGAP-ID, the RAN-UE-NGAP-ID, and a unique trace identifier. The unique trace identifier is a data construct used to identify and correlate the trace records associated with the specific subscriber session or network trace operation.

[0133] In an embodiment, the unique trace identifier may include a trace correlation identifier (TCI) that may be employed to correlate the trace records across multiple interfaces (e.g., N2, N3, N4) and network layers. In other embodiments, the unique trace identifier may include a slice-aware trace identifier (SATI) that may be employed to include network slice context (e.g., S-NSSAI) within the trace record. In a preferred embodiment, the unique trace identifier includes a combination of a trace reference (TR), and a trace recording session reference (TRSR).

[0134] In an embodiment, the receiving module (214) is configured to listen for or actively collect the trace records generated by the network node participating in the subscriber session. For example, in the context of the 5G network, the gNB which serves as the radio access network node, may be configured to generate the trace records.

[0135] In an embodiment, the trace records are generated and transmitted upon activation of trace functionality for a specific subscriber or network element. In an embodiment, the trace functionality may be activated by the TCE or by configuration profiles provisioned via operations, administration, and maintenance (0AM) layer. When the trace functionality is active, the gNB generates the tracerecords during specific events such as, but not limited to, UE registration, authentication, handovers, or session establishment.

[0136] In an embodiment, the generated trace records may be transmitted over standardized interfaces, such as, but not limited to, Interface Type-Network (Itf-N) (interface between network element and element management system) or through protocols (file transfer protocol (FTP), HTTP, or secure (FTP)) when offline trace record transfer is used. The receiving module (214) may be configured either to periodically poll or request the trace records from a trace repository maintained by the gNB, or to passively receive real-time trace data streams if the gNB is configured to forward the trace records as the trace records are generated. Upon receiving the trace records, the receiving module (214) extracts and decodes relevant fields from the trace records, including the NCGI, RAN-UE-NGAP-ID and AMF-UE-NGAP-ID, and unique trace identifiers (TR, TRSR). As used herein, the term “TR” refers to a unique identifier allocated per trace session, representing a trace configuration instance. The TR helps associate a particular trace record with a trace configuration (e.g., “trace profile 01 enabled for UE IMSI 12345”). Also, as used herein, the term “TRSR” represents a unique session-specific ID used to correlate the trace records collected during the same trace recording session. The TRSR helps in grouping the trace records that were logged during the same active session, even across multiple nodes (e.g., gNB, AMF, SMF), thus enabling end-to- end session traceability. For example, when a trace session is activated for the UE (104) having IMSI 123456789012345, the TCE assigns the TR “TR-UE123” corresponding to a trace profile configured for the corresponding UE. Additionally, the TRSR “TRSR-7890” is generated to uniquely identify an active trace session.

[0137] As the UE (104) undergoes registration and authentication procedures, the gNB and AMF each generate corresponding trace records. These trace records embed both the TR and TRSR identifiers, allowing the receiving module (214) to correlate and reconstruct a full signalling flow associated with the UE’s session. This enables end-to-end traceability across the RAN and core signalling layers for the corresponding subscriber session.

[0138] The correlation module (216) is configured to correlate the captured mapping parameters and the received trace records to obtain a set of correlation parameters associated with the subscriber identity. The set of correlation parameters include both the unique trace identifier and the SUPI. In an exemplary embodiment, the correlation module (216) is configured to correlate the captured mapping parameters and the received trace records by matching one or more common identifiers, such as the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and the NCGI. Upon identifying matching values across the signalling-derived mapping parameters and the trace records received from the network node, the correlation module (216) associates the SUPI obtained from the signalling interface with the unique trace identifier obtained from the trace record. This association results in the set of correlation parameters that enable tracing or subscriber identity resolution in a secure and accurate manner. For instance, if the signalling message captures a SUPI value of 001010123456789 and includes RAN-UE-NGAP-ID 0x1001 and AMF-UE-NGAP-ID 0xA301, and the corresponding trace record includes the same identifiers along with TR 0x3210 and TRSR OxAABB, then the correlation module (216) correlates the SUPI with the unique trace identifier. The resulting correlation parameters may then be used to link subscriber identity with trace data for lawful monitoring, auditing, or diagnostics.

[0139] The mapping module (218) is configured to map the set of obtained correlation parameters to a trace record of the plurality of received trace records for managing the subscriber identity within the network (108). In an embodiment, once the TCE identifies the SUPI corresponding to a specific UE trace session using the parameters (e.g., from registration or authentication messages), the mapping module (218) associates that SUPI with a unique combination of trace identifiers: the TR and the TRSR.

[0140] In operation, the TCE scans all received trace records having the same TR and TRSR pair, which uniquely define the trace session. By using this TR and TRSR combination as a correlation anchor, the mapping module (218) populates the SUPI field for all such trace records that lack direct SUPI information but arecontextually part of the same session. This mapping enables consistent and accurate attribution of all trace records to a specific subscriber, even when the SUPI is present in only a subset of records. As a result, complete subscriber-level traceability is achieved across both the RAN and core nodes participating in the same trace session.

[0141] For example, consider a scenario where a trace session is initiated for a subscriber with SUPI “001011234567890”. The TCE provisions the trace profile and assigns a TR value of “TR-102” and a TRSR value of “TRSR-5678”. As the subscriber’s UE undergoes various procedures, such as registration, and authentication, the gNB and AMF generate individual trace records corresponding to each event.

[0142] Among these trace records, some contain the SUPI explicitly (e.g., during registration), while others only include RAN-UE-NGAP-ID, AMF-UE- NGAP-ID, or NCGI values. The mapping module (218) identifies the trace record that includes both the SUPI and the unique trace identifier. Using the unique trace identifier as unique session keys, the mapping module (218) links all other trace records with the same TR and TRSR to the identified SUPI. Consequently, even the trace records that do not directly contain the SUPI are implicitly associated with the same subscriber identity, enabling comprehensive, session-wide traceability and subscriber-specific analytics.

[0143] FIG. 3A illustrates an exemplary system architecture (300A) for managing the trace records (318) generated by the network node, in accordance with embodiments of the present disclosure. FIG. 3A, with reference to FIG. 1 and FIG. 2, illustrates the first system architecture (300A) that includes a gNB (302), an AMF (304), an AUSF (306) and TCE (308).

[0144] As shown in FIG. 3 A, the gNB (302) is configured to communicate with the AMF (304) over an N2 interface (310) for exchanging 5G signalling messages associated with the subscriber session. The signalling messages between the gNB (302) and the AMF (304) over the N2 interface (310) include, but are not limitedto, a registration request conveying an SUCI, subsequent NAS authentication requests and responses exchanged with a UE, and context-related signalling referencing RAN-UE-NGAP-ID and AMF-UE-NGAP-ID identifiers.

[0145] The AMF (304) further communicates with the AUSF (306) over an N12 interface (312) for performing authentication-related signalling procedures. The first system architecture (300A) further includes a tapping mechanism, configured to tap messages exchanged on the N2 interface (310) and the N 12 interface (312), and forward the N2 tapped messages (314) and N12 tapped messages (316) to the TCE (308). The authentication-related signalling procedures between the AMF (304) and the AUSF (306) over the N12 interface (312) include transmission of an authentication request with the SUCI, an authentication response containing authentication vectors and an authentication context ID, a confirmation request maintaining the same authentication context ID, and a final confirmation response providing the SUPI upon successful authentication. In parallel, the gNB (302) is configured to stream trace records (318) associated with the subscriber session directly to the TCE (308).

[0146] The TCE (308) is configured to receive the trace records (318) streamed from the gNB (302) and the tapped messages (314, 316) from the N2 and N12 interfaces (310, 312). In an embodiment, the TCE (308) receives the N2 tapped messages (314) communicated between the gNB (302) and the AMF (304) via the N2 interface (310). Further, in an embodiment, the TCE (308) receives the N12 tapped messages (316) communicated between the AMF (304) and the AUSF (306) via the N 12 interface (312).

[0147] Based on the received trace records (318) and the tapped messages (314, 316), the TCE (308) derives a unique subscriber identifier, such as the SUPI, for correlating the subscriber identity within the network (108). The TCE (308) may use parameters such as the NCGI, AMF-UE-NGAP-ID, RAN-UE-NGAP-ID, and the unique trace identifier to perform this correlation.

[0148] FIG. 3B illustrates another exemplary second system architecture (300B) for managing the trace records (318) generated by the network node, in accordance with embodiments of the present disclosure. FIG. 3B, with reference to FIG. 1 and FIG. 2, illustrates the second system architecture (300B) that includes a gNB (302), an AMF (304), an AUSF (306), a TCE (308) and a UDM (320).

[0149] As shown in FIG. 3B, the gNB (302) is configured to communicate with the AMF (304) over an N2 interface (310) for exchanging 5G signalling messages associated with a subscriber registration, authentication, and session establishment. The AMF (304) is further configured to communicate with the AUSF (306) over an N12 interface (312) for performing subscriber authentication procedures. The AUSF (306) communicates with the UDM (320) over an N13 interface (322) for subscriber data management, including retrieval of authentication vectors, SUPI resolution, and policy-related information.

[0150] The second system architecture (300B) further includes a tapping mechanism configured to tap messages exchanged on the N2 interface (310) and the N13 interface (322), and forward N2 tapped messages (314) and N13 tapped messages (324) to the TCE (308). The N2 tapped messages (314) on the N2 interface (310) may include a registration request carrying a SUCI, NAS authentication messages, and UE context messages referencing the AMF-UE- NGAP-ID and RAN-UE-NGAP-ID. The tapped signalling messages on the N13 interface (322) may include an authentication data request referencing the SUCI, an authentication data response conveying authentication vectors, and a SUPI discovery response message including the SUPI.

[0151] In parallel, the gNB (302) is configured to stream trace records (318) associated with the subscriber session directly to the TCE (308). The TCE (308) is configured to receive the streamed trace records (318) from the gNB (302) along with the tapped messages (314, 324) from the N2 and N13 interfaces (310, 322).

[0152] Based on the received trace records (318) and the tapped messages (314, 324), the TCE (308) derives the unique subscriber identifier, such as the SUPI,for performing correlation of the subscriber identity with the trace records (318). The TCE (308) may leverage parameters including, but not limited to, the NCGI, AMF-UE-NGAP-ID, RAN-UE-NGAP-ID, the authentication context ID, and the unique trace identifier, to reliably associate the trace records (318) with the SUPI in compliance with traceability or lawful interception requirements.

[0153] FIG. 4A illustrates an exemplary signalling flow (400A) for registration and authentication monitoring performed by the TCE (308), in accordance with embodiments of the present disclosure. FIG. 4A, with reference to FIG. 1, FIG. 2 and FIG. 3A, illustrates the first signalling flow (400A) for the registration and authentication monitoring performed by the TCE (308).

[0154] At step (402), UE (not shown) initiates a registration request towards the gNB (302). The registration request includes the SUCI as the user identity. The registration request is forwarded by the gNB (302) over the N2 interface (310) to the AMF (304), along with the NCGI, RAN-UE-NGAP-ID, and other relevant access context information.

[0155] At step (404), the AMF (304) receives and checks parameters such as SUCI, the NCGI, and the RAN-UE-NGAP-ID from the registration request, maintaining an association of a radio-layer context with the core network identity. The TCE (308) passively monitors this message flow on the N2 interface (310) to capture these parameters for correlation.

[0156] At step (406), the AMF (304) transmits an initial authentication request including the SUCI to the AUSF (306) over the N12 interface (312) to request an authentication vector for the subscriber. The TCE (308) observes the N12 interface (312) (i.e., authentication request) to log the SUCI and any included identifiers for correlation.

[0157] At step (408), the AUSF (306) responds with the authentication response, which the AMF (304) receives over the N12 interface (312). The TCE (308) records the authentication response by tapping the N12 interface (312),including an authentication context identifier (authentication context ID) corresponding to the SUCI.

[0158] At step (410), the AMF (304) initiates NAS-level authentication by sending the authentication request containing challenge parameters to the UE via the gNB (302) over the N2 interface (310).

[0159] At step (412), the AMF (304) then checks the AMF-UE-NGAP-ID in association with the NCGI and RAN-UE-NGAP-ID to maintain the correct UE context for this authentication procedure.

[0160] At step (414), in response to the authentication request, the UE processes the authentication request and returns a NAS authentication response to the AMF (304) through the same N2 interface (310) via the gNB (302).

[0161] At step (416), the AMF (304) transmits an authentication result confirmation request to the AUSF (306) over the N12 interface (312), indicating the received NAS authentication response and referencing the authentication context ID established in step (408), for the purpose of confirming that the UE is connected to the correct network and has been successfully authenticated. The TCE (308) also monitors this authentication confirmation request on the N 12 interface (312) for correlation purposes.

[0162] At step (418), the AUSF (306), in response to the authentication confirmation request, returns a message containing the SUPI, such as an IMSI to the AMF (304) over the N12 interface (312) upon successful authentication. The TCE (308) records this SUPI for establishing a correlation to user’s permanent identity.

[0163] As a result of the above monitoring, the TCE (308) establishes a mapping between the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and the SUPI of the subscriber, thereby enabling unique identification and session correlation of the UE across the radio and core network domains.

[0164] FIG. 4B illustrates another exemplary second signalling flow (400B) for registration and authentication monitoring performed by the TCE (308), in accordance with embodiments of the present disclosure. FIG. 4B, with reference to FIG. 1, FIG. 2 and FIG. 3B, illustrates the second signalling flow (400B).

[0165] At step (420), UE (not shown) initiates a registration request towards the gNB (302). The registration request includes the SUCI as the user identity. The registration request is forwarded by the gNB (302) over the N2 interface (310) to the AMF (304), along with the NCGI, RAN-UE-NGAP-ID, and other relevant access context information. Further, at step (418), upon receiving the registration request, the AMF (304) checks whether the NCGI, the RAN-UE-NGAP-ID, and the SUCI is received through the registration request. In an embodiment, the registration request including the NCGI, the RAN-UE-NGAP-ID, and the SUCI is streamed in form of the tapped messages to the TCE (308) via the N2 interface (310). Further, the TCE (308) stores the NCGI, the RAN-UE-NGAP-ID, and the SUCI for further processing.

[0166] At step (422), the AMF (304) transmits an initial authentication request including the SUCI to the AUSF (306) over the N12 interface (312) to request an authentication vector for the subscriber.

[0167] At step (424), upon receiving the authentication request, the AUSF (306) forwards the authentication request with same SUCI to the UDM (320) over the N13 interface (322). Further, the UDM (320) is configured to decrypt the SUPI corresponding to the SUCI received with the authentication request.

[0168] At step (426), upon decrypting the SUPI, the UDM (320) transmits the SUPI in a form of a response message to the AUSF (306). In an embodiment, the response message containing the SUPI corresponding to the SUCI is streamed to the TCE (308) in the form of the tapped messages via the N13 interface (322).

[0169] At step (428), the AUSF (306) transmits an authentication context identifier (ID) received in the authentication response message to the AMF (304). The authentication context ID is crucial for subsequent steps in the authenticationprocess. In an embodiment, the authentication context ID may be received after generation of the SUPI.

[0170] At step (430), the AMF (304) forwards a NAS-level authentication request towards the UE via the gNB (302) over the N2 interface (310), carrying the authentication challenge parameters to the UE. The UE transmits a NAS authentication response towards the AMF (304) via the gNB (302).

[0171] At step (432), the AMF (304) checks the AMF-UE-NGAP-ID corresponding to the NCGI and RAN-UE-NGAP-ID. In an embodiment, the AMF- UE-NGAP-ID corresponding to the NCGI and RAN-UE-NGAP-ID is streamed in the form of the tapped messages to the TCE (308) via the N2 interface (310). In an embodiment, the TCE (308) stores the AMF-UE-NGAP-ID for further processing.

[0172] At step (434), the UE transmits a NAS authentication response towards the AMF (304) via the gNB (302) in response to the NAS-level authentication request.

[0173] As a result of the above monitoring, the TCE (308) establishes a mapping between the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and the SUPI of the user, thereby enabling unique identification and session correlation of the UE across the radio and core network domains.

[0174] FIG. 5 illustrates an exemplary process flow (500) for integrating the subscriber identity information within trace records, in accordance with embodiments of the present disclosure. FIG. 5 is explained in conjunction with FIG. 1, FIG. 2, FIG. 3A, FIG. 3B FIG. 4A and FIG. 4B.

[0175] In an embodiment, the process flow (500) depicted in FIG. 5 is a parallel flow with respect to the signalling flow (400A) or (400B) depicted in FIG. 4A or 4B. In other words, the signalling flow (400A) or (400B) and the process flow (500) may be executed parallelly. The process flow (500) of FIG. 5 depicts streaming of 5G NR trace records (i.e., the at least one trace record) towards the TCE (308) during each subscriber session.

[0176] At step (502), the UE (104) transmits a radio resource control (RRC) session establishment request to the gNB (302). The RRC session establishment request is initiated by the UE (104) upon initial access to the network (108) and includes parameters such as, but not limited to, UE identity, capabilities, and request cause.

[0177] At step (504), upon receiving the RRC session establishment request, the gNB (302) transmits the registration request to the AMF (304), as shown via the step (402) of FIG. 4A or the step (418) of FIG. 4B. Further, the steps (404) to steps (416) or steps (418) to (430) are executed parallelly. In addition, at step (504), the gNB (302) may start streaming the trace records for the subscriber associated with the UE (104) towards the TCE (308).

[0178] At step (506), the TCE (308) receives the trace records from the gNB (302). In an embodiment, each trace record may include the combination of TR and the TRSR (i.e., the at least one unique trace identifier) which identifies a unique subscriber trace session in the RAN (i.e., the network (108)).

[0179] In an embodiment, the at least one trace record may include the UE context details such as NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, along with the TR and the TRSR.

[0180] Further, the TCE (308) may correlate the mapping of the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and the SUPI, and the mapping of the NCGI, the AMF-UE-NGAP-ID, the RAN-UE-NGAP-ID, the TR, and the TRSR. Furthermore, based on the correlation, the TCE (308) may derive mapping of the TR, the TRSR, and the SUPI. Thereafter, the TCE (308) may map the SUPI in all the trace records for the subscriber (UE) using the TR and the TRSR.

[0181] FIG. 6 illustrates an exemplary flowchart of a method (600) for managing the subscriber identity in the network (108), in accordance with embodiments of the present disclosure. FIG. 6, with reference to FIG. 1, FIG. 2, FIG. 3A / FIG. 3B, FIG. 4A / FIG. 4B and FIG. 5, illustrates the method (600) formanaging the subscriber identity by using the processing engine (208) of the system (102).

[0182] At step (602), the method (600) includes capturing, by the TCE (308), the mapping parameters based on the signalling information associated with at least one subscriber session. The at least one subscriber session includes, but not limited to, the registration session, and the authentication session. The signalling information is obtained based on the tapping mechanism implemented on at least one network interface used for communication between the network entities. The network entities include the network functions (i.e., AMF (304), AUSF (306), UDM (320)) and the network node (i.e., gNB (302)). The mapping parameters associated with the at least one subscriber session includes at least four of the NCGI, the SUPI, the AMF-UE-NGAP-ID, and the RAN-UE-NGAP-ID.

[0183] At step (604), the method (600) includes receiving, by the TCE (308), the trace records (316) associated with the at least one subscriber session from the network node. The trace records (316) includes the NCGI, the AMF-UE-NGAP- ID, the RAN-UE-NGAP-ID, and the unique trace identifier. The unique trace identifier includes a combination of the TR and TRSR.

[0184] At step (606), the method (400) includes correlating, by the TCE (308), the captured mapping parameters and the received trace records (316) to obtain the set of correlation parameters associated with the subscriber identity. The set of correlation parameters associated with the subscriber identity includes both the unique trace identifier and the SUPI. In an exemplary embodiment, the correlation module (216) is configured to correlate the captured mapping parameters and the received trace records (316) by matching the common identifiers, such as the RAN- UE-NGAP-ID, the AMF-UE-NGAP-ID, and the NCGI. Upon identifying matching values across the signalling -derived mapping parameters and the trace records (316) received from the network node, the correlation module (216) associates the SUPI obtained from the signalling interface with the unique trace identifier obtained fromthe trace record. This association results in the set of correlation parameters that enable tracing or subscriber identity resolution in a secure and accurate manner.

[0185] At step (608), the method (600) includes mapping, by the TCE (308), the set of obtained correlation parameters to a trace record of the plurality of received trace records (316) for managing the subscriber identity within the network (108). In an embodiment, once the TCE (308) identifies the SUPI corresponding to a specific UE trace session using the parameters (e.g., from registration or authentication messages), the TCE (308) associates that SUPI with the unique combination of trace identifiers: the TR and the TRSR.

[0186] FIG. 7 illustrates an exemplary computer system (700) in which, or with which, the system (102) and the method (600) of the present disclosure may be implemented. As shown in FIG. 7, the computer system (700) may include an external storage device (710), a bus (720), a main memory (730), a read-only memory (740), a mass storage device (750), a communication port (760), and a processor (770). A person skilled in the art will appreciate that the computer system (700) may include more than one processor (770) and the communication ports (760). The processor (770) may include various modules associated with embodiments of the present disclosure.

[0187] In an embodiment, the external storage device (710) may be any device that is commonly known in the art, such as, but not limited to, a memory card, a memory stick, a solid-state drive, a hard disk drive (HDD), and so forth.

[0188] In an embodiment, the bus (720) may be communicatively coupled with the processor(s) (770) with the other memory, storage, and communication blocks. The bus (720) may be, e.g., a peripheral component interconnect (PCI) / PCI Extended (PCI-X) bus, a small computer system interface (SCSI), a universal serial bus (USB) or the like, for connecting expansion cards, drives and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor (770) to the computer system (700).

[0189] In an embodiment, the main memory (730) may be a random-access memory (RAM), or any other dynamic storage device commonly known in the art. The Read-only memory (740) may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chips for storing static information e.g., start-up or Basic Input / Output System (BIOS) instructions for the processor (770).

[0190] In an embodiment, the mass storage device (750) may be any current or future mass storage solution, which may be used to store information and / or instructions. Exemplary mass storage solutions include, but are not limited to, a parallel advanced technology attachment (PATA) or a serial advanced technology attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having universal serial bus (USB) and / or Firewire interfaces), one or more optical discs, redundant array of independent disks (RAID) storage, e.g., an array of disks (e.g., SATA arrays).

[0191] Further, the communication port (760) may be any of an RS-232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication port (760) may be chosen depending on the network (108), such a local area network (LAN), wide area network (WAN), or any network to which the computer system (700) connects.

[0192] Optionally, operator and administrative interfaces, e.g., a display, a keyboard, a joystick, and a cursor control device, may also be coupled to the bus (720) to support a direct operator interaction with the computer system (700). Other operator and administrative interfaces may be provided through network connections connected through the communication port (760). Components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system (700) limit the scope of the present disclosure.

[0193] The exemplary computer system (700) is configured to execute a computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method (600) for managing a subscriber identity in anetwork (108). The method (600) includes capturing, by atrace control entity (TCE) (308), a plurality of mapping parameters based on signalling information associated with at least one subscriber session. The method (600) further includes receiving, by the TCE (308), a plurality of trace records (316) associated with the at least one subscriber session from a network node. The method (600) further includes correlating, by the TCE (308), the plurality of captured mapping parameters and the plurality of received trace records (316) to obtain a set of correlation parameters associated with the subscriber identity. The method (600) further includes mapping, by the TCE (308), the set of obtained correlation parameters to a trace record of the plurality of received trace records (316) for managing the subscriber identity within the network (108).

[0194] In an exemplary embodiment, a user equipment (UE) (104) communicatively coupled with anetwork (108) is disclosed. The coupling includes receiving, by the network (108), a connection request from the UE (104). The coupling further includes sending, by the network (108), an acknowledgment of the connection request to the UE (104). The coupling further includes transmitting a plurality of signals in response to the connection request. A subscriber identity in the network (108) is managed by a method (600). The method (600) includes capturing, by a trace control entity (TCE) (308), a plurality of mapping parameters based on signalling information associated with at least one subscriber session. The method (600) further includes receiving, by the TCE (308), a plurality of trace records (316) associated with the at least one subscriber session from a network node. The method (600) further includes correlating, by the TCE (308), the plurality of captured mapping parameters and the plurality of received trace records (316) to obtain a set of correlation parameters associated with the subscriber identity. The method (600) further includes mapping, by the TCE (308), the set of obtainedcorrelation parameters to a trace record of the plurality of received trace records (316) for managing the subscriber identity within the network (108).

[0195] The present disclosure provides a technical advancement in the field of 5G network monitoring and subscriber identity correlation by introducing a physical tapping-based trace correlation approach that enables accurate mapping of SUPI to trace recording sessions without direct involvement of a subscriber or network modification. This advancement is achieved through a trace control entity (TCE) that passively taps signalling interfaces such as, N2 (between AMF and gNB), N12 (between AMF and AUSF), and N13 (between AUSF and UDM), to extract and correlate key session parameters. The TCE analyzes session initiation and authentication messages to derive correlation parameters including NCGI, RAN UE NGAP ID, AMF UE NGAP ID, and SUPI. In parallel, trace records received from gNB include TR and TRSR, which uniquely identify subscriber trace sessions. By aligning the parameters obtained from tapped interfaces with those present in the trace records, the TCE performs secure and accurate mapping of SUPI to a combination of TR and TRSR. This unified solution enables network operators to manage subscriber traceability with precision, facilitates lawful interception and analytics use cases, and overcomes existing limitations in correlating trace sessions with subscriber identities in next-generation mobile networks, all while maintaining a non-intrusive, standards-compliant monitoring framework.

[0196] While the foregoing describes various embodiments of the invention, other and further embodiments of the invention may be devised without departing from the basic scope thereof. The scope of the invention is determined by the claims that follow. The invention is not limited to the described embodiments, versions or examples, which are included to enable a person having ordinary skill in the art to make and use the invention when combined with information and knowledge available to the person having ordinary skill in the art.TECHNICAL ADVANTAGES OF THE PRESENT DISCLOSURE

[0197] As is evident from above, the present disclosure described herein above has several technical advantages including:• enabling Subscription Permanent Identifier (SUPI) enrichment in trace records without changes to the Access and Mobility Management Function (AMF) or the Next Generation NodeB (gNB), thereby reducing development effort and signalling overhead on critical core and Radio Access Network (RAN) nodes.• minimizing core network load by offloading SUPI mapping responsibilities to the Trace Collection Entity (TCE), thus preserving AMF processing resources for essential control plane functions.• accelerating time-to-market for new RAN vendor integration by providing a centralized and vendor-agnostic SUPI enrichment approach at the TCE.• ensuring network agility by eliminating the need to adapt SUPI mapping logic for each RAN vendor’s proprietary trace record format. • reducing solution deployment costs by limiting data tapping to a single network function (AMF), thereby lowering hardware, integration, and maintenance expenses.• improving traceability and monitoring accuracy across the network without impacting service performance or introducing service delays.

Claims

CLAIMS1. A method (600) for managing a subscriber identity in a network (108), the method (600) comprising steps of: capturing, by a trace control entity (TCE) (308), a plurality of mapping parameters based on signalling information associated with at least one subscriber session; receiving, by the TCE (308), a plurality of trace records (316) associated with the at least one subscriber session from a network node; correlating, by the TCE (308), the plurality of captured mapping parameters and the plurality of received trace records (316) to obtain a set of correlation parameters associated with the subscriber identity; and mapping, by the TCE (308), the set of obtained correlation parameters to a trace record of the plurality of received trace records (316) for managing the subscriber identity within the network (108).

2. The method (600) as claimed in claim 1, wherein the at least one subscriber session comprises at least one of a registration session, and an authentication session.

3. The method (600) as claimed in claim 1, wherein the signalling information is obtained based on a tapping mechanism implemented on at least one network interface used for communication between network entities.

4. The method (600) as claimed in claim 1, wherein the plurality of mapping parameters associated with the at least one subscriber session comprises at least four of a new radio cell global identity (NCGI), a subscription permanent identifier (SUPI), an access and mobility management function user equipment next generation application protocol identifier (AMF-UE- NGAP-ID), and a radio access network user equipment next generation application protocol identifier (RAN-UE-NGAP-ID).

5. The method (600) as claimed in claim 1, wherein the plurality of trace records (316) associated with the at least one subscriber session comprises at least four of a new radio cell global identity (NCGI), an access and mobility management function user equipment next generation application protocol identifier (AMF-UE-NGAP-ID), a radio access network user equipment next generation application protocol identifier (RAN-UE- NGAP-ID), and a unique trace identifier.

6. The method (600) as claimed in claim 1, wherein the set of correlation parameters associated with the subscriber identity comprises both a unique trace identifier, and a subscription permanent identifier (SUPI).

7. A system (102) for managing a subscriber identity in a network (108), the system (102) comprising: a trace control entity (TCE) (308) comprises: a parameter capturing module (212) configured to capture a plurality of mapping parameters based on signalling information associated with at least one subscriber session; a receiving module (214) configured to receive a plurality of trace records (316) associated with the at least one subscriber session from a network node; a correlation module (216) configured to correlate the plurality of captured mapping parameters and the plurality of received trace records (316) to obtain a set of correlation parameters associated with the subscriber identity; and a mapping module (218) configured to map the set of obtained correlation parameters to a trace record of the plurality of received trace records (316) for managing the subscriber identity within the network (108).

8. The system (102) as claimed in claim 7, wherein the at least one subscriber session comprises at least one of a registration session, and an authentication session.

9. The system (102) as claimed in claim 7, wherein the signalling information is obtained based on a tapping mechanism implemented on at least one network interface used for communication between network entities.

10. The system (102) as claimed in claim 7, wherein the plurality of mapping parameters associated with the at least one subscriber session comprises at least four of a new radio cell global identity (NCGI), a subscription permanent identifier (SUPI), an access and mobility management function user equipment next generation application protocol identifier (AMF-UE- NGAP-ID), and a radio access network user equipment next generation application protocol identifier (RAN-UE-NGAP-ID).

11. The system (102) as claimed in claim 7, wherein the plurality of trace records (316) associated with the at least one subscriber session comprises at least four of a new radio cell global identity (NCGI), an access and mobility management function user equipment next generation application protocol identifier (AMF-UE-NGAP-ID), a radio access network user equipment next generation application protocol identifier (RAN-UE- NGAP-ID), and a unique trace identifier.

12. The system (102) as claimed in claim 7, wherein the set of correlation parameters associated with the subscriber identity comprises both a unique trace identifier, and a subscription permanent identifier (SUPI).

13. A user equipment (UE) (104) communicatively coupled with a network (108), the coupling comprises steps of: receiving, by the network (108), a connection request from the UE(104);sending, by the network (108), an acknowledgment of the connection request to the UE (104); and transmitting a plurality of signals in response to the connection request, wherein a subscriber identity in the network (108) is managed by a method (600) as claimed in claim 1.

14. A computer program product comprising a non-transitory computer- readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute a method (600) for managing a subscriber identity in a network (108), the method (600) comprising steps of: capturing, by a trace control entity (TCE) (308), a plurality of mapping parameters based on signalling information associated with at least one subscriber session; receiving, by the TCE (308), a plurality of trace records (316) associated with the at least one subscriber session from a network node; correlating, by the TCE (308), the plurality of captured mapping parameters and the plurality of received trace records (316) to obtain a set of correlation parameters associated with the subscriber identity; and mapping, by the TCE (308), the set of obtained correlation parameters to a trace record of the plurality of received trace records (316) for managing the subscriber identity within the network (108).

Citation Information

Patent Citations

  • Technology for operating network nodes of a communication network

    US20150065083A1

  • Method of managing trace sessions in a network and trace session management system

    WO2012098129A2

  • User authentication in first network using subscriber identity module for second legacy network

    WO2019193107A1