System and method for maintaining a relationship between identifiers of user equipment in network

WO2026202974A1PCT designated stage Publication Date: 2026-10-01JIO PLATFORMS LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/IN2026/050581
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-03-30
Publication Date
2026-10-01

Smart Images

  • Figure IN2026050581_01102026_PF_FP_ABST
    Figure IN2026050581_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure describes system (300) and method (500) for maintaining relationship between identifiers of User Equipment (UE) (104) in network (106) The method includes obtaining registration parameters including Globally Unique Temporary Identifier (GUTI), New Radio Cell Global Identity (NCGI), and Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) from registration request over first interface. The method (500) includes obtaining Subscription Permanent Identifier (SUPI) from authentication request and authentication parameters including Authentication Token (AUTN) and Random Number (RAND) from authentication response over second interface, and establishing first mapping among SUPI, AUTN, and RAND. The IP (208) obtains NAS authentication parameters from NAS authentication request, establishes second mapping by matching AUTN and RAND across interfaces to maintain a relationship between GUTI and SUPI, and identifies SUPI in response to query from Trace Collection Entity (TCE) (212).
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEM AND METHOD FOR MAINTAINING A RELATIONSHIP BETWEEN IDENTIFIERS OF USER EQUIPMENT IN NETWORKRESERVATION OF RIGHTS

[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to Jio Platforms Limited (JPL) or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.TECHNICAL FIELD

[0002] The present disclosure relates to a field of telecommunications network. In particular, the present disclosure relates to a method and a system for maintaining a relationship between identifiers of User Equipment (UE) in a network.DEFINITION

[0003] As used in the present disclosure, the following terms are intended to have the meaning as set forth below, except to the extent that the context in which they are used to indicate otherwise.

[0004] The term “5GCN” as used herein may refers to a fifth generation (5G) core network. The 5GCN provides connectivity and services to end-users (such as mobile devices and loT devices). It is designed to support higher data rates, lower latency, and massive connectivity compared to previous generations (e.g., 4G / LTE).

[0005] The term “Probing solution” as used herein may refers to a passive monitoring and analysis mechanism that extracts real-time network data without modifying or interfering with live traffic. The probing solution is used for network analytics, security monitoring, subscriber tracking, and troubleshooting.

[0006] The term “Trace records” as used herein may refer to detailed logs and data records that capture activities and interactions within the network. These records are essential for monitoring, troubleshooting, and analysing network performance.

[0007] The term “Access and Mobility Management Function (AMF)” as used herein may refer to a network function that is responsible for managing network access and mobility for user equipments (UEs) in 5G network.

[0008] The term “Trace Collection Entity (TCE)” used herein may refer to a network component responsible for collecting and correlating trace records from various network nodes to monitor, analyse, and manage network activities and subscriber sessions.

[0009] The term “Authentication Server Function (AUSF)” used herein may refer to a network component responsible for handling authentication requests and responses, ensuring the security and verification of user identities in the 5G network.

[0010] The term “Intelligence Probe (IP)” used herein may refer to a network monitoring and analytics tool used in telecommunications to collect, analyse, and interpret data traffic in real-time. The IP is commonly deployed in 5G and Long Term Evolution (LTE) networks to enhance network security, optimize performance, and detect anomalies.

[0011] The term “N2 interface” as used herein may refer to a communication interface in the 5G network that connects the AMF with the gNodeB (gNB), facilitating the exchange of signalling messages related to user registration, mobility management, and connection management.

[0012] The term “N12 interface” as used herein may refer to a communication interface in the 5G network that connects the AMF with the AUSF. It enables the exchange of authentication-related messages and information necessary for verifying user identities and managing authentication processes.

[0013] The term “Subscription Concealed Identifier (SUCI)” as used herein may refer to a temporary, encrypted identifier used in 5G networks to protect the subscriber's permanent identity during registration and authentication processes.

[0014] The term “Subscription Permanent Identifier (SUPI)” as used herein may refer to a permanent, unique identifier assigned to a subscriber in 5G networks. It is used to identify the subscriber across various network operations and services.

[0015] The term “Radio Access Network (RAN)” as used herein may refer to a mobile network that connects user equipment (UE) to the core network throughradio frequencies, encompassing base stations and other infrastructure responsible for managing wireless communication.

[0016] The term “New Radio Cell Global Identity (NCGI)” as used herein may refer to a unique identifier used in 5G networks to specify and differentiate individual cells within the New Radio (NR) network.

[0017] The term “Next-Generation Application Protocol (NGAP)” as used herein may refer to a signalling protocol used in 5G networks, specifically on N2 interface between the base station (gNB) and the AMF, facilitating communication between the core network and the RAN.

[0018] The term “Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID)” as used herein may refer to a unique identifier assigned to a User Equipment (UE) by the RAN in the NGAP layer. It is used to manage and distinguish individual UE connections within the RAN.

[0019] The term “Access and Mobility Management Function -User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID)” as used herein may refer to a unique identifier assigned by the AMF to a UE in the NGAP layer for managing and tracking UE connections in the 5G core network.

[0020] The term “Trace Recording Session Reference (TRSR)” as used herein may refer to a unique identifier used to track and manage tracing of a specific user session in a network. The TRSR allows for the collection and analysis of detailed subscriber or network activity data.

[0021] The term “Trace Reference (TR)” as used herein may refer to a unique identifier used to specify and distinguish a trace session in the network. It enables accurate tracking and analysis of network events or subscriber activities.

[0022] The term “International Mobile Subscriber Identity (IMSI)” as used herein may refer to a unique identifier assigned to each mobile subscriber, used to securely identify and authenticate the subscriber within the mobile network.

[0023] These definitions are in addition to those expressed in the art.BACKGROUND

[0024] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the presentdisclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.

[0025] The increasing adoption of Fifth Generation (5G) network has introduced advancements in network performance, security, and user experience. However, the use of temporary identifiers such as the Globally Unique Temporary Identifier (GUTI) presents a challenge in tracking subscribers across multiple registrations. In the 5G network, a User Equipment (UE) initially registers using a Subscription Concealed Identifier (SUCI), which is later replaced by a GUTI for subsequent registrations. While this enhances security by preventing unauthorized access to Subscription Permanent Identifier (SUPI), it inadvertently creates a blind spot in subscriber tracking after the initial registration.

[0026] A major problem with the 5G networks is that trace records generated by a 5G base station (gNB) lack subscriber information such as the SUPI and the International Mobile Subscriber Identity (IMSI) because the subscriber information is sent in an encrypted Non-Access Stratum (NAS) container, preventing the gNB from accessing subscriber details. Similarly, the gNB is not aware of the GUTI because the GUTI is also sent transparently in encrypted NAS container. As a result, subsequent network registrations using GUTI do not provide sufficient subscriber information in trace records, which hinders effective session analytics and subscriber tracking. Thus, creating difficulties in network debugging, fraud detection, and lawful interception efforts, as it becomes impossible to correlate multiple sessions to the same subscriber identity.

[0027] Existing solutions to address the challenge rely on trace collection mechanisms, such as the Trace Collection Entity (TCE), which gathers trace records from the Radio Access Network (RAN) and Core Network elements. However, the trace records do not inherently contain the subscriber’s SUPI, making it difficult to maintain continuous session awareness. Some existing solutions involve manual correlation techniques, where operators attempt to map GUTI to SUPI using historical registration data, but the existing solution is inefficient and lacks realtime tracking capabilities. Another alternative involves modifying the network architecture to expose additional subscriber details, contradicting the 5G security principle of keeping SUPI concealed over the air interface.

[0028] There is, therefore, a need in the art to provide a method and a system that can mitigate the disadvantages of the prior art.SUMMARY OF THE DISCLOSURE

[0029] In an embodiment, a method for maintaining a relationship between identifiers of a User Equipment (UE) in a network is described. The method includes obtaining a plurality of registration parameters including a Globally Unique Temporary Identifier (GUTI ), a New Radio Cell Global Identity (NCGI), and a Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) from a registration request via a first interface. Further, the method further include obtaining a Subscription Permanent Identifier (SUPI) from an authentication request, and authentication parameters including an Authentication Token (AUTN) and a Random Number (RAND) from an authentication response via a second interface. The method includes establishing a first mapping between the SUPI, and the AUTN and the RAND. Further, the method further include obtaining a plurality of Non-Access Stratum (NAS) authentication parameters including an AMF-User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, the AUTN, and the RAND from a NAS authentication request via the first interface. Further, the method further include establishing a second mapping among the plurality of NAS authentication parameters, the plurality of registration parameters, and the first mapping by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request, to maintain a relationship between the GUTI and the SUPI of the UE. The method includes identifying the SUPI corresponding to the UE from the second mapping upon receiving a query from a Trace Collection Entity (TCE), wherein the query includes at least one of the plurality of NAS authentication parameters, the plurality of registration parameters, and the authentication parameters.

[0030] In an embodiment, the first interface is an N2 interface between an Access and Mobility Management Function (AMF) and a base station and the second interface is an N12 interface between the AMF and an Authentication Server Function (AUSF), and the IP monitors the N2 interface and the N12 interface before an assignment of the GUTI to the UE.

[0031] In another embodiment, if the IP monitors the N2 interface and the N12 interface after the assignment of the GUTI to the UE, the method includes establishing the relationship between the GUTI and the SUPI during a subsequent authentication event by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request.

[0032] In another embodiment, establishing the second mapping, the method includes forming a combined session reference based on the NCGI and the RAN-UE-NGAP-ID to uniquely identify the UE session across a plurality of base stations of the network.

[0033] In another embodiment, the method includes transmitting the SUPI along with the registration parameters, the authentication parameters, and the NAS authentication parameters to the TCE in a push mode, upon establishing the second mapping.

[0034] In another embodiment, the method includes one or more trace records comprising at least a Trace Reference (TR), a Trace Recording Session Reference (TRSR) from the base station, wherein the one or more received trace records further comprises the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID. Further, the method includes retrieving the SUPI associated with the UE session corresponding to the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and a timestamp based on the second mapping. The method includes enriching the one or more trace records with the retrieved SUPI to enable continuous subscriber-aware network analytics.

[0035] In another exemplary embodiment, a system for maintaining a relationship between identifiers of a User Equipment (UE) in a network is described. The system includes an Intelligence Probe (IP) configured to obtain a plurality of registration parameters including a Globally Unique Temporary Identifier (GUTI ), a New Radio Cell Global Identity (NCGI), and a Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) from a registration request via a first interface. The IP is configured to obtain a Subscription Permanent Identifier (SUPI) from an authentication request, and authentication parameters including an Authentication Token (AUTN) and a Random Number (RAND) from an authentication response via a second interface.Further, the IP is configured to establish a first mapping between the SUPI, and the AUTN and the RAND. The IP is configured to obtain a plurality of Non-Access Stratum (NAS) authentication parameters including an AMF-User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, the AUTN, and the RAND from a NAS authentication request via the first interface. Further, the IP is configured to establish a second mapping among the plurality of NAS authentication parameters, the plurality of registration parameters, and the first mapping by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request, to maintain a relationship between the GUTI and the SUPI. The IP is configured to identify the SUPI corresponding to the UE from the second mapping upon receiving a query from a Trace Collection Entity (TCE), wherein the query comprises at least one of the plurality of NAS authentication parameters, the plurality of registration parameters, and the authentication parameters.

[0036] In another exemplary embodiment, a system for maintaining a relationship between identifiers of a User Equipment (UE) in a network is described. The system includes a Trace Collection Entity (TCE) configured to receive one or more trace records including at least a Trace Reference (TR), a Trace Recording Session Reference (TRSR) from the base station. The one or more received trace records further comprises the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID. The TCE is configured to extract UE context information including the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID from the one or more trace records. Further, the TCE is configured to transmit a query to an Intelligence Probe (IP), the query includes the UE context information and a timestamp. The TCE is configured to receive a Subscription Permanent Identifier (SUPI) associated with a UE session corresponding to the UE context information from the IP. Further, the TCE is configured to enrich the one or more trace records with the received SUPI to enable subscriber-aware network analytics.

[0037] In yet another embodiment, a computer program product including a non-transitory computer-readable medium including instructions that, when executed by one or more processors, cause the one or more processors to execute a method for maintaining a relationship between identifiers of a User Equipment (UE) in anetwork is disclosed. The method includes obtaining a plurality of registration parameters including a Globally Unique Temporary Identifier (GUTI ), a New Radio Cell Global Identity (NCGI), and a Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) from a registration request via a first interface. Further, the method further include obtaining a Subscription Permanent Identifier (SUPI) from an authentication request, and authentication parameters including an Authentication Token (AUTN) and a Random Number (RAND) from an authentication response via a second interface. The method includes establishing a first mapping between the SUPI, and the AUTN and the RAND. Further, the method further include obtaining a plurality of Non-Access Stratum (NAS) authentication parameters including an AMF-User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, the AUTN, and the RAND from a NAS authentication request via the first interface. Further, the method further include establishing a second mapping among the plurality of NAS authentication parameters, the plurality of registration parameters, and the first mapping by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request, to maintain a relationship between the GUTI and the SUPI of the UE. The method includes identifying the SUPI corresponding to the UE from the second mapping upon receiving a query from a Trace Collection Entity (TCE), wherein the query includes at least one of the plurality of NAS authentication parameters, the plurality of registration parameters, and the authentication parameters.OBJECTIVES OF THE PRESENT DISCLOSURE

[0038] Some of the objectives of the present disclosure, which at least one embodiment herein satisfies, are as follows:

[0039] An objective of the present disclosure is to provide a method and a system to maintain subscriber awareness beyond the initial Subscriber Concealed Identifier (SUCI)-based registration by enabling continuous mapping of subscriber identities throughout the session lifecycle.

[0040] Another objective of the present disclosure is to provide a method and a system for developing a mechanism for deriving a Subscription Permanent Identifier (SUPI) from Fifth Generation (5G) — Globally Unique TemporaryIdentifier (GUTI) and enriching it in trace records, thereby eliminating blind spots in subscriber tracking during subsequent registrations.

[0041] Another objective of the present disclosure is to provide a method and a system to enhance trace collection by incorporating the SUPI into trace records, improving network analytics, debugging, and troubleshooting capabilities.

[0042] Another objective of the present disclosure is to provide a method and a system that introduces an Intelligent Probe (IP) that probes N2 and N12 interfaces to observe authentication flows, ensuring seamless correlation between temporary and permanent subscriber identities.

[0043] Another objective of the present disclosure is to provide a method and a system to allow GUTI-SUPI mapping even if probing begins after GUTI assignment, ensuring no loss of subscriber tracking data.

[0044] Other objects and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.BRIEF DESCRIPTION OF THE DRAWINGS

[0045] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes the disclosure of electrical components, electronic components or circuitry commonly used to implement such components.

[0046] FIG. 1 illustrates an exemplary network architecture for maintaining a relationship between identifiers of a User Equipment (UE) in a network, in accordance with an embodiment of the present disclosure.

[0047] FIG. 2 illustrates an exemplary block diagram of a system configured for maintaining a relationship between identifiers of the UE in the network, in accordance with an embodiment of the present disclosure.

[0048] FIG. 3 illustrates an exemplary system architecture for maintaining therelationship between identifiers of the UE in the network, in accordance with an embodiment of the present disclosure.

[0049] FIGS. 4 A - 4C illustrate exemplary process flows for maintaining the relationship between identifiers of the UE in the network, in accordance with an embodiment of the present disclosure.

[0050] FIG. 5 illustrate a method for maintaining the relationship between identifiers of the UE in the network, in accordance with an embodiment of the present disclosure.

[0051] FIG. 6 illustrates an exemplary computer system in which or with which the embodiments of the present disclosure may be implemented.

[0052] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100 - Network architecture102 -User(s)104 - User Equipments (UEs)106 - Network108 - System200 - Block diagram202 - Processor(s)204 - Memory206 -Interface(s)208 - Intelligence Probe (IP)210 - Database212 - Trace Collection Entity (TCE)300 - System Architecture302 - Base station (gNB / eNB)304 - Access and Mobility Management Function (AMF)306 - Authentication Server Function (AUSF)400A - 400C - Flow Diagrams500 - Method600 - Computer system610 - External Storage Device620 - Bus630 - Main Memory640 - Read Only Memory650 - Mass Storage Device660 - Communication Port670 - ProcessorDETAILED DESCRIPTION

[0053] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address any of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein. Example embodiments of the present disclosure are described below, as illustrated in various drawings in which like reference numerals refer to the same parts throughout the different drawings.

[0054] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.

[0055] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown withoutunnecessary detail in order to avoid obscuring the embodiments.

[0056] Also, it is noted that individual embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.

[0057] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive like the term “comprising” as an open transition word without precluding any additional or other elements.

[0058] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0059] The terminology used herein is to describe particular embodiments only and is not intended to be limiting the disclosure. As used herein, the singular forms “a”, “an”, and “the” are intended to include the plural forms as well, unless the contextindicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any combinations of one or more of the associated listed items. It should be noted that the terms “mobile device”, “user equipment”, “user device”, “communication device”, “device” and similar terms are used interchangeably for the purpose of describing the invention. These terms are not intended to limit the scope of the invention or imply any specific functionality or limitations on the described embodiments. The use of these terms is solely for convenience and clarity of description. The invention is not limited to any particular type of device or equipment, and it should be understood that other equivalent terms or variations thereof may be used interchangeably without departing from the scope of the invention as defined herein.

[0060] As used herein, an “electronic device”, or “portable electronic device”, or “user device” or “communication device” or “user equipment” or “device” refers to any electrical, electronic, electromechanical, and computing device. The user device is capable of receiving and / or transmitting one or parameters, performing function / s, communicating with other user devices, and transmitting data to the other user devices. The user equipment may have a processor, a display, a memory, a battery, and an input-means such as a hard keypad and / or a soft keypad. The user equipment may be capable of operating on any radio access technology including but not limited to IP-enabled communication, Zig Bee, Bluetooth, Bluetooth Low Energy, Near Field Communication, Z-Wave, Wi-Fi, Wi-Fi direct, etc. For instance, the user equipment may include, but not limited to, a mobile phone, smartphone, virtual reality (VR) devices, augmented reality (AR) devices, laptop, a general -purpose computer, desktop, personal digital assistant, tablet computer, mainframe computer, or any other device as may be obvious to a person skilled in the art for implementation of the features of the present disclosure.

[0061] Further, the user device may also comprise a “processor” or “processing unit” includes processing unit, wherein processor refers to any logic circuitry for processing instructions. The processor may be a general -purpose processor, aspecial purpose processor, a conventional processor, a digital signal processor, a plurality of microprocessors, one or more microprocessors in association with a Digital Signalling Processing (DSP) core, a controller, a microcontroller, Application Specific Integrated Circuits, Field Programmable Gate Array circuits, any other type of integrated circuits, etc. The processor may perform signal coding data processing, input / output processing, and / or any other functionality that enables the working of the system according to the present disclosure. More specifically, the processor is a hardware processor.

[0062] While considerable emphasis has been placed herein on the components and component parts of the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiment, as well as other embodiments of the disclosure, will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be interpreted merely as illustrative of the disclosure and not as a limitation.

[0063] The evolution of 5G networks has brought significant improvements in security and efficiency, including mechanisms to conceal subscriber identities from unauthorized access. One such measure involves replacing a Subscription Permanent Identifier (SUPI) with a Globally Unique Temporary (GUTI) during reregistrations, preventing the exposure of permanent identifiers over the air interface. While this enhances security, it also limits the ability of network operators to track subscribers consistently across multiple sessions. Since, the GUTI is transmitted in an encrypted Non-Access Stratum (NAS) container, the GUTI remains inaccessible to a base station (gNB) and a Trace Collection Entity (TCE), which are responsible for generating and analysing network trace records. The lack of access results in incomplete trace data, restricting the effectiveness of subscriber session monitoring and network analytics.

[0064] A critical challenge in the 5G networks arises from the inability to maintain continuous subscriber awareness after an initial registration process. Once a user device transitions from using a Subscriber Concealed Identifier (SUCI) to the GUTI, trace records generated by the gNB lack the SUPI, creating a blind spot in session analysis. Without a method to map the GUTI to the SUPI in trace records,network operators face difficulties in debugging subscriber sessions, analysing connectivity patterns, and enforcing security protocols. The absence of a standardized approach to address the issue means that subscriber visibility is lost beyond the first registration, limiting the accuracy of analytics and affecting the overall efficiency of network management.

[0065] Conventional approaches to subscriber tracking in 5G networks present several limitations. One method involves relying on an Access and Mobility Management Function (AMF) logs, which retain the mapping between the GUTI and the SUPI. However, the information is not accessible to external trace collection systems, making real-time analytics impractical. Another approach involves modifying gNB to capture the SUPI directly, which conflicts with security policies prohibiting exposing subscriber identities over the interface. Some operators have attempted to use external correlation systems to bridge the gap. Still, the solutions are ineffective in cases where the correlation process starts after the assignment of the GUTI. As a result, conventional approaches either compromise security, require significant changes to network elements or fail to provide complete and continuous subscriber tracking.

[0066] To address the above-mentioned issues, the present disclosure introduces an Intelligent Probing (IP) Platform that passively monitors the 5G network interfaces to establish a secure and reliable correlation between the GUTI and the SUPI. By leveraging authentication parameters such as an Authentication Number (AUTN) and a Random Number (RAND) from standard 5G authentication procedures, the present disclosure enables continuous subscriber tracking without modifying existing network infrastructure. Further, the present disclosure allows for retroactive subscriber identity mapping, ensuring that even if monitoring begins after the GUTI assignment, the correlation between the GUTI and the SUPI will still be established during the next authentication event.

[0067] Further, a key advantage of the present disclosure is the ability to operate independently of vendor-specific implementations, making it compatible with any 5G network infrastructure. Additionally, since the present disclosure passively probes into network interfaces without modifying core network functions, the present disclosure introduces no processing or capacity overhead. By enriching trace records with subscriber identity information, the present disclosure enhancesnetwork analytics, security enforcement, and performance monitoring. Crucially, the present disclosure remains fully compliant with existing 5G security standards, as it does not expose plaintext SUPI over the air interface. Further, the present disclosure effectively addresses the existing blind spot in subscriber tracking, enabling comprehensive session analytics and improving overall network efficiency.

[0068] Hereinafter, exemplary embodiments of the present disclosure will be described with reference to the accompanying drawings. The various embodiments throughout the disclosure will be explained in more detail with reference to FIG. 1-FIG. 6.

[0069] FIG. 1 illustrates an exemplary network architecture 100 for maintaining a relationship between identifiers of a User Equipment (UE) 104 in a network 106, in accordance with an embodiment of the present disclosure. The different identifiers may include temporary identifiers such as Globally Unique Temporary Identifier (GUTI) and permanent identifiers such as Subscription Permanent Identifier (SUPI). As illustrated in FIG. 1, the network architecture 100 may include one or more UEs 104-1, 104-2... 104-N associated with one or more users 102-1, 102-2... 102-N in an environment. A person of ordinary skill in the art will understand that one or more users 102-1, 102-2... 102-N may be collectively referred to as the users 102. Similarly, a person of ordinary skill in the art will understand that one or more UEs 104-1, 104-2... 104-N may be collectively referred to as the UE 104, the UEs 104. Although only three UE 104 are depicted in FIG. 1, however, any number of the UE 104 may be included without departing from the scope of the ongoing description.

[0070] In an embodiment, the UE 104 may include smart devices operating in a smart environment, for example, an Internet of Things (loT) system. In such an embodiment, the UE 104 may include, but are not limited to, smartphones, smart watches, smart sensors (e.g., a mechanical, a thermal, an electrical, a magnetic, etc.), networked appliances, networked peripheral devices, networked lighting system, communication devices, networked vehicle accessories, networked vehicular devices, smart accessories, tablets, a smart television (TV), computers, a smart security system, a smart home system, other devices for monitoring or interacting with or for the users 102 and / or entities, or any combination thereof. Aperson of ordinary skill in the art will appreciate that the UE 104 may include, but not limited to, intelligent, multi-sensing, network-connected devices, that may integrate seamlessly with each other and / or with a central server or a cloudcomputing system or any other device that is network-connected.

[0071] Additionally, in some embodiments, the UE 104 may include, but not limited to, a handheld wireless communication device (e.g., a mobile phone, a smartphone, a phablet device, and so on), a wearable computer device (e.g., a headmounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a Global Positioning System (GPS) device, a laptop computer, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, a router, an outdoor device, and / or any other type of computer device with wireless communication capabilities, and the like. In an embodiment, the UE 104 may include, but are not limited to, any electrical, electronic, electromechanical, or equipment, or a combination of one or more of the above devices, such as virtual reality (VR) devices, augmented reality (AR) devices, a laptop, a general -purpose computer, a desktop, a personal digital assistant, a tablet computer, a mainframe computer, or any other computing device. Further, the UE 104 may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as a camera, an audio aid, a microphone, a keyboard, and input devices for receiving input from the user 102 or an entity such as a touchpad, a touch-enabled screen, an electronic pen, and the like. A person of ordinary skill in the art will appreciate that the UE 104 may not be restricted to the mentioned devices and various other devices may be used.

[0072] In FIG. 1, the UE 104 may communicate with the system 108 through the network 106 for sending or receiving various types of data. In an embodiment, the network 106 may include at least one of a 5G network, a 6G network, or the like. The network 106 may enable the UE 104 to communicate with other devices in the network architecture 100 and / or with the system 108. The network 106 may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network 106 may be implemented as, or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobilenetwork, a Virtual Private Network (VPN), the Internet, the Public Switched Telephone Network (PSTN), or the like.

[0073] In an embodiment, the network 106 may include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth. The network 106 may also include, by way of example but not limitation, one or more of the Radio Access Network (RAN), a wireless network, a wired network, an internet, an intranet, a public network, a private network, a packet-switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public-Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.

[0074] In an embodiment, the UE 104 is communicatively coupled with the network 106. The network 106 may receive a connection request from the UE 104. The network 106 may send an acknowledgment of the connection request to the UE 104. The UE 104 may transmit a plurality of signals in response to the connection request.

[0075] In an embodiment, the system 108 is responsible for maintaining relationship between the temporary identifier and the permanent identifier in the network 106. The system 108 may obtain a plurality of registration parameters including a Globally Unique Temporary Identifier (GUTI ), a New Radio Cell Global Identity (NCGI), and a Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) from a registration request via a first interface. Further, the system 108 may obtain a Subscription Permanent Identifier (SUPI) from an authentication request, and authentication parameters including an Authentication Token (AUTN) and a Random Number (RAND) from an authentication response via a second interface. The system 108 may further establish a first mapping between the SUPI, and the AUTN and the RAND. Further, the system 108 may obtain a plurality of Non-Access Stratum (NAS) authentication parameters including an AMF-User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, the AUTN, and the RAND from a NASauthentication request via the first interface. The plurality of NAS authentication parameters is received corresponding to a NAS authentication request. Further, the system 108 may establish a second mapping among the plurality of NAS authentication parameters, the plurality of registration parameters, and the first mapping by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request, to maintain a relationship between the GUTI and the SUPI. Further, the system 108 may identify the SUPI corresponding to the UE from the second mapping upon receiving a query from a Trace Collection Entity (TCE). The query includes at least one of the plurality of NAS authentication parameters, the plurality of registration parameters, and the authentication parameters.

[0076] In some embodiments, the system 108 may receive one or more trace records including at least a Trace Reference (TR), a Trace Recording Session Reference (TRSR) from the base station. The one or more received trace records further includes the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID. Further, the system 108 may extract UE context information including the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID from the one or more trace records. The system 108 may transmit a query to an Intelligence Probe (IP), the query including the UE context information and a timestamp. Further, the system 108 may receive a Subscription Permanent Identifier (SUPI) associated with a UE session corresponding to the UE context information from the IP. The system 108 may enrich the one or more trace records with the received SUPI to enable subscriber-aware network analytics.

[0077] Although FIG. 1 shows exemplary components of the network architecture 100, in other embodiments, the network architecture 100 may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, or alternatively, one or more components of the network architecture 100 may perform functions described as being performed by one or more other components of the network architecture 100.

[0078] FIG. 2 illustrates an exemplary block diagram 200 of the system 108 configured for maintaining a relationship between identifiers of the UE 104 in the network 106, in accordance with an embodiment of the disclosure. FIG. 2 isexplained in conjunction with the FIG. 1.

[0079] In an embodiment, the system 108 may include one or more processor(s) 202. The one or more processor(s) 202 may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuitries, and / or any devices that process data based on operational instructions. Among other capabilities, the one or more processor(s) 202 may be configured to fetch and execute computer-readable instructions stored in a memory 204 of the system 108. The memory 204 may be configured to store one or more computer-readable instructions or routines in a non-transitory computer readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory 204 may include any non-transitory storage device including, for example, volatile memory such as a Random-Access Memory (RAM), or a non-volatile memory such as an Erasable Programmable Read Only Memory (EPROM), a flash memory, and the like.

[0080] In an embodiment, the system 108 may include an interface(s) 206. The interface(s) 206 may include a variety of interfaces, for example, interfaces for data input and output devices (VO), storage devices, and the like. The interface(s) 206 may facilitate communication through the system 108. The interface(s) 206 may also provide a communication pathway for one or more components of the system 108. Examples of such components include, but are not limited to, a Intelligence probe (IP) 208, a database 210 and a Trace Collection Entity (TCE) 212.

[0081] In an embodiment, the system 108 may include the IP 208 and the TCE 212 that may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the IP 208 and the TCE 212. In examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the IP 208 and the TCE 212may be processorexecutable instructions stored on a non-transitory machine-readable storage medium and the hardware for the IP 208 and the TCE 212 may comprise a processing resource (for example, one or more processors), to execute such instructions. In the present examples, the machine-readable storage medium may store instructions that, when executed by the processing resource, implement the IP 208 and the TCE 212. In such examples, the system 108 may comprise the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system 108 and the processing resource. In other examples, the IP 208 and the TCE 212 may be implemented by electronic circuitry.

[0082] In an embodiment, the IP 208 may be configured to obtain a plurality of registration parameters including a Globally Unique Temporary Identifier (GUTI ), a New Radio Cell Global Identity (NCGI), and a Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) from a registration request via a first interface. The first interface is an N2 interface between an Access and Mobility Management Function (AMF) and a base station. In an embodiment, the UE 104 may initiate a registration request along with the GUTI to a base station (gNB) of the network 106 over a N2 interface. Further, the gNB forwards the registration request to an Access and Mobility Management Function (AMF) to register the UE 104 with the network 106. In an embodiment, the IP 208 may probe the N2 interface and capture the registration request. Further, the IP 208 may extract and store the NCGI, RAN-UE-NGAP-ID, and the GUTI from a registration response message. It should be noted that the NCGI is required to make a unique concatenation of the NCGI and the RAN-UE-NGAP-ID across the gNBs of the network 106.

[0083] Further, the IP 208 may be configured to obtain a Subscription Permanent Identifier (SUPI) from an authentication request, and authentication parameters including an Authentication Token (AUTN) and a Random Number (RAND) from an authentication response via a second interface. The second interface is an N12 interface between the AMF and an Authentication Server Function (AUSF). In an embodiment, the AMF may send the authentication request containing the SUPI to an Authentication Server Function (AUSF) over an N12 interface. The IP 208 may probe the N12 interface to capture the authentication request. Further, the IP 208 extracts the SUPI from the captured authentication request. Further, the AUSF may respond to the AMF with an authentication response corresponding to the authentication request. The IP 208 may also capture the authentication response from the N12 interface. Further, the IP 208 extracts the AUTN and the RAND from the captured authentication response.

[0084] In an embodiment, the IP 208 may be configured to establish a first mappingbetween the SUPI, and the AUTN and the RAND. Further, the IP 208 stores the mapping of the plurality of authentication parameters and the permanent identifier for further correlation. In an embodiment, the IP 208 maintains a correlation repository for storing authentication-event-specific correlation entries. Upon obtaining the SUPI from the authentication request over the second interface and obtaining the AUTN and the RAND from the corresponding authentication response over the second interface, the IP 208 generates a first mapping entry by associating the SUPI with the AUTN and the RAND captured for the same authentication procedure. The IP 208 stores the first mapping entry together with a session context and / or a time context so that the AUTN and the RAND subsequently observed in a NAS authentication request over the first interface can be matched with the stored first mapping entry. Accordingly, the first mapping acts as an intermediate authentication-event correlation record that bridges the permanent subscriber identity obtained over the second interface with temporary and session-related identifiers obtained over the first interface. The first mapping is stored as an intermediate correlation record and is later used for matching the AUTN and the RAND observed in the NAS authentication request, enabling establishment of the second mapping between the GUTI and the SUPI.

[0085] Further, the IP 208 may be configured to obtain a plurality of Non-Access Stratum (NAS) authentication parameters including an AMF-User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, the AUTN, and the RAND from a NAS authentication request via the first interface.

[0086] In an embodiment, the IP 208 may be configured to establish a second mapping among the plurality of NAS authentication parameters, the plurality of registration parameters, and the first mapping by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request, to maintain a relationship between the GUTI and the SUPI. Further, the IP 208 correlates the extracted parameters with the NCGI, and the RAN-UE-NGAP-ID extracted from the registration request. Based on the extracted parameters, the IP 208 may create a mapping containing the SUPI (permanent identifier), the GUTI (temporary identifier), the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, the AUTN, the RAND, and a timestamp.

[0087] In an embodiment, upon obtaining the NAS authentication parameters from the NAS authentication request over the first interface, the IP 208 compares the AUTN and the RAND included in the NAS authentication request with the AUTN and the RAND stored in the first mapping established for the corresponding authentication procedure over the second interface. When the AUTN and the RAND obtained from the NAS authentication request match the AUTN and the RAND stored in the first mapping, the IP associates the SUPI of the first mapping with the registration parameters and the NAS authentication parameters corresponding to the same UE session. Based on such association, the IP 208 generates the second mapping that correlates the GUTI, the SUPI, the NCGI, the RAN-UE-NGAP-ID, and the AMF-UE-NGAP-ID for the UE. Accordingly, the second mapping extends the authentication-event-specific association of the first mapping into a session-level correlation between the temporary identifier and the permanent identifier of the UE 104.

[0088] Upon establishing a second mapping, the SUPI along with the registration parameters, the authentication parameters, and the NAS authentication parameters are transmitted to the TCE in a push mode. The push mode may be selectively enabled based on an operator configuration or deployment preference, such that the IP 208 transmits the correlation information to the TCE 212 without awaiting a separate lookup query from the TCE 212. Accordingly, the TCE 212 may receive pre-correlated subscriber identity information for subsequent enrichment of trace records associated with the UE session.

[0089] Further, the IP 208 may be configured to identify the SUPI corresponding to the UE from the second mapping upon receiving a query from a Trace Collection Entity (TCE). The query includes at least one of the plurality of NAS authentication parameters, the plurality of registration parameters, and the authentication parameters. When the TCE 212 requires subscriber identification for a trace record or session context, the TCE 212 transmits a query to the IP 208. Upon receiving the query, the IP 208 searches the second mapping using the queried parameters, identifies the SUPI corresponding to the UE 104, and provides the identified SUPI for trace enrichment, subscriber-aware analytics, troubleshooting, or session-level network investigation.

[0090] If the IP 208 monitors the N2 interface and the N12 interface after theassignment of the GUTI to the UE 104, the relationship between the GUTI and the SUPI during a subsequent authentication event by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request is established. In an embodiment, when monitoring by the IP 208 begins after assignment of the GUTI to the UE 104, the relationship between the GUTI and the SUPI is established during a subsequent authentication event. In an embodiment, the IP 208 may not have observed the initial GUTI assignment procedure, but continues to monitor the N2 interface and the N12 interface for a later authentication session associated with the same UE 104. During the subsequent authentication event, the IP 208 obtains the SUPI from the authentication request over the N12 interface and obtains the AUTN and the RAND from the corresponding authentication response over the N12 interface. The IP further obtains from a NAS authentication request over the N2 interface, the AMF-UE-NGAP-ID, the NCGI, the RAN-UE-NGAP-ID, and the AUTN and RAND associated with the UE session. Upon determining that the AUTN and the RAND obtained from the authentication response match the AUTN and the RAND obtained from the NAS authentication request, the IP 208 associates the SUPI with the registration and NAS authentication context corresponding to the UE session, thereby establishing the relationship between the already-assigned GUTI and the SUPI.

[0091] In some embodiments, the TCE 212 may be configured to receive one or more trace records including at least a Trace Reference (TR), a Trace Recording Session Reference (TRSR) from the base station. The one or more received trace records further includes the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID. The trace records received by the TCE 212 correspond to signalling and session events generated at the base station during handling of a UE session, such as mobility procedures, registration-related procedures, authentication-related procedures, or trace-triggered measurements. Each trace record may represent a particular event instance, while the TR may enable identification of a trace invocation and the TRSR may enable grouping of multiple event records belonging to a common tracing session.

[0092] Further, the TCE 212 may be configured to extract UE context information including the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID from the one ormore trace records. The TCE 212 parses the received trace records to isolate UE-specific context elements that may serve as correlation inputs for subscriber resolution. The extraction may be performed record-by-record or across a set of records associated with a common TRSR, such that fragmented context distributed across multiple trace records may be consolidated before query generation. The RAN-UE-NGAP-ID may represent the UE context from the radio access side, and the AMF-UE-NGAP-ID may represent the corresponding UE context maintained toward the core network side.

[0093] In some embodiments, the TCE 212 may be configured to transmit a query to an Intelligence Probe (IP). The query including the UE context information and a timestamp. After extracting the UE context information, the TCE 212 generates a query message directed to the IP 208 for subscriber identity resolution. The timestamp included in the query may correspond to a capture time, trace generation time, event occurrence time, or a session-relative time associated with the relevant trace record or group of trace records.

[0094] Further, the TCE 212 may be configured to receive a Subscription Permanent Identifier (SUPI) associated with a UE session corresponding to the UE context information from the IP. Upon receipt of the query from the TCE 212, the IP 208 searches the second mapping to determine the subscriber identity corresponding to the queried UE session. Because the second mapping has already linked the SUPI with the radio-side and authentication-related context of the UE session, the IP 208 may resolve the permanent identifier without requiring the TCE 212 to inspect N12 or NAS authentication signalling directly. The returned SUPI represents the permanent subscriber identity associated with the same session for which the trace records were generated.

[0095] In some embodiments, the TCE 212 may be configured to enrich the one or more trace records with the received SUPI to enable subscriber-aware network analytics. The TCE 212 inserts the received SUPI into the corresponding trace records or associates the SUPI with the trace records in an indexed trace repository, so that subsequent analytics operations may be performed on a subscriber-aware basis. The enrichment allows events collected from different sessions, cells, or time intervals to be linked back to the same subscriber identity even where only temporary or session-specific identifiers were originally present in the trace data.As a result, network operators may perform troubleshooting, mobility analysis, service continuity verification, authentication-flow investigation, and behavioural analytics with improved continuity and granularity. The enriched trace records may also support cross-domain correlation between radio events and core-network events, since the SUPI provides a stable subscriber anchor across multiple signalling procedures.

[0096] In an embodiment, the system 108 may include a database 210 that includes data (e.g., session related to UE 104, subscriber details, Subscription Permanent Identifier (SUPI), subscription details, authentication parameters, mapping of the parameters, etc.) that may be either stored or generated as a result of functionalities implemented by any of the components of the processor 202 or the IP 208 and the TCE 212.

[0097] FIG. 3 illustrates an exemplary system architecture 300 for maintaining the relationship between identifiers of the UE 104 in the network 106, in accordance with an embodiment of the present disclosure. FIG. 3 is explained in conjunction with the FIGS. 1 and 2. The system architecture 300 enables seamless subscriber tracking by correlating temporary identifiers, such as the GUTI, with permanent subscriber identities, such as the SUPI or an International Mobile Subscriber Identity (IMSI). The correlation enhances network traceability, security, and analytics while ensuring compliance with 5G security standards.

[0098] In an embodiment, the system architecture 300 may include a base station (gNB) 302, an Access and Mobility management Function (AMF) 304, an Authentication Server Function (AUSF) 306, an Intelligence Probe (IP) 208 and a Trace Collection Entity (TCE) 212. In some embodiments, the IP 208 receives N2 probed messages communicated between the gNB 302 and the AMF 304 via the N2 interface. In an embodiment, the IP 208 may receive probed messages communicated between the AMF 304 and the AUSF 306 via the N12 interface. In an embodiment, the TCE 212 receives the trace records streamed from the gNB 302.

[0099] In an embodiment, the gNB 302 serves as the radio access point, handling initial user registration and mobility management within the network 106. The gNB 302 communicates with the AMF 304 via the N2 interface, transmitting signalling messages related to user authentication and session establishment. The AMF 304plays a crucial role in subscriber identity management by assigning a GUTI during user registration and storing the mapping between the GUTI and the SUPI within the core network. However, the mapping is not readily accessible to external trace collection entities, leading to challenges in subscriber tracking beyond the initial registration phase.

[0100] Further, the AUSF 306 is engaged with the AMF 304 through the N12 interface to perform authentication functions. During authentication, the AUSF 306 generates authentication vectors, including an Authentication Number (AUTN) and a Random Number (RAND), which are used to verify subscriber legitimacy. The authentication parameters serve as a key input to the IP 208, which passively monitors network traffic to extract relevant authentication data.

[0101] In an embodiment, the IP 208 act as a correlation engine, leveraging authentication parameters to establish a relationship between the GUTI and the SUPI (or IMSI). The IP 208 may be physically connected to probe the N2 and N12 interfaces of AMF 304. By passively analysing signalling exchanges between network components, the IP 208 derives enriched subscriber identity information without modifying existing network infrastructure. The enrichment process enables the generation of augmented trace records, which include both the temporary and permanent subscriber identifiers. It should be noted that the IP 208 may be a service hosted as part of the TCE Platform 212 for ease of deployment.

[0102] The TCE 212 serves as a centralized platform for network analytics, troubleshooting, and security monitoring. The TCE 212 aggregates trace records from multiple sources, providing network operators with a comprehensive view of subscriber sessions across different mobility states. The enrichment process ensures that subscriber sessions remain traceable even after re-registration using GUTI, thus mitigating the visibility gap in standard 5G networks. The IP 208 and the TCE 212 may have a communication link for SUPI lookup queries.

[0103] The system architecture 300 enhances network visibility while maintaining compliance with security policies that prohibit the transmission of plaintext IMSI over the air interface. Since the correlation is performed passively and relies on standard authentication procedures, the system 300 remains vendor-agnostic and may be deployed in any 5G network without requiring modifications to core network functions. By enabling seamless subscriber tracking and identitycorrelation, the system 300 significantly improves network security, operational efficiency, and subscriber experience.

[0104] FIGS. 4A - 4C illustrate exemplary process flow 400A-400C for maintaining the relationship between different identifiers in the probing solution in the network 106, in accordance with an embodiment of the present disclosure. FIGS. 4A - 4C is explained in conjunction with FIGS. 1, 2, and 3.

[0105] Referring to FIG. 4A, the method 400A may be implemented by the gNB 302, the AMF 304, and the AUSF 306 of the network 106 over the N2 and the N12 interface.

[0106] The method 400 A may start when a User Equipment (UE) 104 sends a registration request containing a Globally Unique Temporary Identifier (GUTI) to the gNB 302. At step 402, the gNB 302 forwards the registration request to the AMF 304 over the N2 interface. Since the GUTI is a temporary identifier assigned to a subscriber during a previous session, the AMF 304 must verify and correlate it with the permanent identifier (SUP I).

[0107] Upon receiving the registration request, at step 404, the AMF 304 verifies key parameters, including a Next Generation Cell Identity (NGCI), Radio Access Network User Equipment NGAP Identifier (RAN-UE-NGAP-ID), and the GUTI. The parameters are checked to determine whether the UE 104 is recognized in the network and to proceed with the authentication process.

[0108] To authenticate the UE, at step 406, the AMF 304 forwards an authentication request to the AUSF 306 over the N12 interface. The authentication request contains the SUPI of the subscriber. The SUPI is the unique identity of the subscriber stored within a Unified Data Management (UDM) and is used for authentication and identity validation.

[0109] At step 408, the AUSF 306 processes the authentication request and may generate authentication parameters. The authentication parameters may include an Authentication Number (AUTN) and a Random Number (RAND). The AUTN may be used to authenticate the UE within the network 106. Further, the RAND may be a randomly generated value used in the authentication process. Further, the RAND and the AUTN are returned to the AMF 304 in an authentication response.

[0110] Upon receiving the authentication response, at step 410, the AMF 304 maintains a first mapping between the SUPI and the authentication parameters(AUTN and RAND). The mapping is crucial for future correlation and traceability of subscriber identity across different network transactions.[OHl] At step 412, the AMF 304 sends a Non-Access Stratum (NAS) authentication request to the UE 104. The AMF 304 may verify the mapping of AMF-UE-NGAP-ID with the authentication parameters (AUTN and RAND). The AMF 304 may also reference other stored identifiers, including RAN-UE-NGAP-ID and NGCI, noted earlier in step 404. Further, the AMF 304 establishes a second mapping which may include the GUTI, the NGCI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID and the RAND and the AUTN.

[0112] By correlating the mappings, at step 414, the AMF 304 derives a complete relationship between the SUPI and various temporary identifiers (the GUTI, the NGCI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID). The correlation ensures that the network, such as the network 106 may track subscriber identities securely and efficiently across different network events, while preventing unauthorized exposure of permanent identifiers.

[0113] Referring to FIG. 4B, the method 400B may be implemented by the UE 104, the gNB 302, and the TCE 212. The primary purpose of the method 400B is to enable the collection and monitoring of Trace Records containing Trace Reference (TR) and Trace Record Session References (TRSR) for network analysis, troubleshooting, and lawful interception purposes.

[0114] At step 416, the UE 104 may establish a Radio Resource Control (RRC) session with the gNB 302 for registration, ensuring that the UE 104 may communicate with the network and proceed with the necessary registration and authentication procedures.

[0115] After the RRC session is established, at step 418, the gNB 302 forwards the registration request to the AMF 304 as explained in FIG. 4A to initiate authentication and session setup. Simultaneously, the gNB 302 begins streaming trace records corresponding to user signalling messages towards the TCE 212 for monitoring and analysis.

[0116] At step 420, the gNB 302 generates the trace records containing details about the ongoing registration session and transmits it to the TCE 212. The trace records may help in tracking and analysing the UE 104 activity in the network 106, aiding in performance monitoring and security enforcement.

[0117] At step 422, the TCE 212 may continuously receive the trace records containing the TR and the TRSR for the subscriber. The trace records may include various network session details, ensuring comprehensive tracking of the UE's 104 activity. In an embodiment, the trace records may include UE 104 context details, such as the RAN-UE-NGAP-ID identifier and the AMF-UE-NGAP-ID identifier. The identifiers are crucial for maintaining the correlation between temporary and permanent subscriber identities and ensuring proper network management.

[0118] At step 424, the gNB 302 may continue to transmit the trace records corresponding to ongoing user session to the TCE 212.

[0119] Referring to FIG. 4C, the method 400C may be implemented by the TCE 212 and the IP 208, enabling correlation between temporary and permanent subscriber identifiers within the network 106. The method 400C is crucial for tracking, monitoring, and identifying subscribers based on the trace records while maintaining security and compliance.

[0120] At step 426, the TCE 212 initiates a request to obtain the SUPI by sending a query to the IP 208. The query may include key parameters such as the NCGI, the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and the timestamp. In an embodiment, the parameters help locate and retrieve the correct SUPI corresponding to a particular UE session. The timestamp ensures accurate correlation with the recorded trace data.

[0121] Upon receiving the query, at step 428, the IP 208 processes the query by checking the second mapping stored in the database. The IP 208 may crossreference the received NCGI, RAN-UE-NGAP-ID, AMF-UE-NGAP-ID, and timestamp with previously stored authentication and session data. Based on the cross-reference, the SUPI associated with the given session may be identified.

[0122] Upon successfully retrieving the SUPI, the IP 208 may send the corresponding SUPI back to the TCE 212. The TCE 212 may correlate the SUPI with previously collected trace records, ensuring proper identification and monitoring of subscriber activity.

[0123] In an exemplary embodiment, consider a scenario where a government agency is investigating a suspected cybercriminal who frequently changes locations and devices to evade detection. The suspect uses multiple User Equipment (UE), such as smartphones and tablets, to connect to the 5G network via different basestations (gNBs / eNBs). Since 5G networks employ temporary identifiers, such as GUTI, instead of permanent identifiers like SUPI for privacy protection, it becomes challenging to track the suspect’ s movements over time. In such cases, the disclosed system and method provide a solution by establishing a correlation between the temporary and permanent identifiers using network trace records. When the suspect's device connects to a gNB and initiates a registration request using the GUTI, the AMF processes the registration request to assign the temporary identifier (GUTI) to the suspect’s device. Simultaneously, the AUSF authenticates the UE using the SUPI, which is a permanent identifier linked to the suspect's SIM card. As the suspect moves across different network cells, trace records are continuously generated and forwarded to the TCE. The TCE collects and correlates these records to maintain a mapping between the temporary identifiers (GUTI, NGAP IDs) and the permanent identifier (SUPI). By querying the Intelligence Probe (IP), the law enforcement agency may retrieve the suspect’ s actual subscriber identity, regardless of the temporary changes in identifiers.

[0124] FIG. 5 illustrate a method for maintaining the relationship between identifiers of the UE 104 in the network 106, in accordance with an embodiment of the present disclosure. FIG. 5 is explained in conjunction with FIGS. 1, 2, 3 and 4.

[0125] At step 502, a plurality of registration parameters including a Globally Unique Temporary Identifier (GUTI ), a New Radio Cell Global Identity (NCGI), and a Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) are obtained from a registration request via a first interface. The first interface is an N2 interface between an Access and Mobility Management Function (AMF) and a base station. In an exemplary embodiment, when the UE initiates a registration procedure in the network through a serving base station, the Intelligence Probe (IP) monitors the N2 interface and captures a registration request exchanged between the base station and the AMF. From the registration request, the IP extracts the GUTI associated with the UE, the NCGI indicating the serving radio cell, and the RAN-UE-NGAP-ID that identifies the UE context on the radio access side. The registration parameters provide an initial temporary and session-level context for subsequently correlating the UE 104 across interfaces.

[0126] At step 504, a Subscription Permanent Identifier (SUPI) from an authentication request, and authentication parameters including an Authentication Token (AUTN) and a Random Number (RAND) from an authentication response via a second interface are obtained. The second interface is an N12 interface between the AMF and an Authentication Server Function (AUSF), and the IP monitors the N2 interface and the N12 interface before an assignment of the GUTI to the UE. In an exemplary embodiment, during an authentication procedure triggered for the UE, the IP monitors signalling over the N 12 interface between the AMF and the AUSF. The IP obtains the SUPI from an authentication request that identifies the subscriber being authenticated and further obtains the AUTN and the RAND from a corresponding authentication response returned by the AUSF. Since the SUPI is available over the authentication signalling while the temporary radioside identifiers are available over the N2 signalling, the IP captures the parameters before completion of identifier transitions, thereby preparing a basis for associating the permanent subscriber identity with temporary and session-related identifiers of the UE 104.

[0127] At step 506, a first mapping between the SUPI, and the AUTN and the RAND is established. In an exemplary embodiment, after obtaining the SUPI, AUTN, and RAND from the N12-side signalling, the IP creates and stores a first mapping entry that associates the permanent subscriber identity of the UE 104 with the corresponding authentication parameters. Th first mapping acts as an intermediate correlation record that preserves the linkage between the SUPI and the specific authentication challenge-response context. The first mapping is maintained in a correlation repository of the IP so that the same AUTN and RAND values may later be used to connect the permanent subscriber identity with parameters captured from the NAS-side authentication signalling.

[0128] At step 508, a plurality of Non-Access Stratum (NAS) authentication parameters including an AMF-User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, the AUTN, and the RAND are obtained from a NAS authentication request via the first interface. In an exemplary embodiment, during delivery of NAS authentication signalling toward the UE 104, the IP further monitors the first interface and captures a NAS authentication request transmitted through the base station and the AMF.From this NAS authentication request, the IP obtains the AMF-UE-NGAP-ID that identifies the UE context at the core-network side, along with the NCGI, the RAN-UE-NGAP-ID, and the AUTN and RAND carried in the NAS signalling. The NAS authentication parameters provide the radio-side and AMF-side UE context corresponding to the same authentication event previously observed on the N12 interface.

[0129] At step 510, a second mapping is established among the plurality of NAS authentication parameters, the plurality of registration parameters, and the first mapping by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request, to maintain a relationship between the GUTI and the SUPI of the UE. A combined session reference is formed based on the NCGI and the RAN-UE-NGAP-ID to uniquely identify the UE session across a plurality of base stations of the network. In an exemplary embodiment, the IP compares the AUTN and RAND captured from the N12 authentication response with the AUTN and RAND captured from the NAS authentication request on the first interface. Upon determining a match, the IP correlates the first mapping with the registration parameters and the NAS authentication parameters to generate a second mapping that links the GUTI, SUPI, NCGI, RAN-UE-NGAP-ID, and AMF-UE-NGAP-ID to a common UE session and authentication event. Further, the IP forms a combined session reference using the NCGI and the RAN-UE-NGAP-ID so that the UE session can be uniquely distinguished even in deployments where multiple base stations or cell transitions are involved. As a result, the permanent subscriber identity remains traceable with respect to the temporary identifiers used in radio and core signalling.

[0130] The SUPI along with the registration parameters, the authentication parameters, and the NAS authentication parameters are transmitted to the TCE in a push mode, upon establishing the second mapping. In an exemplary embodiment, once the second mapping is successfully established, the IP proactively transmits the SUPI together with the correlated registration parameters, authentication parameters, and NAS authentication parameters to the Trace Collection Entity (TCE) without waiting for a separate lookup request. The push-based transmission enables the TCE to receive already-correlated subscriber and session context for the UE 104 in near real time. Such an arrangement reduces subsequent lookup latencyand allows the TCE to immediately enrich collected trace information with subscriber-aware context.

[0131] At step 512, the SUPI corresponding to the UE is identified from the second mapping upon receiving a query from a Trace Collection Entity (TCE). The query includes at least one of the plurality of NAS authentication parameters, the plurality of registration parameters, and the authentication parameters. In an exemplary embodiment, when the TCE receives trace information associated with the UE 104 and requires permanent subscriber identification, the TCE sends a query to the IP containing one or more available identifiers or parameters, such as the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, the NCGI, the AUTN, the RAND, or another parameter maintained in the second mapping. The IP searches the second mapping using the queried information and identifies the SUPI corresponding to the UE session. The identified SUPI is then returned to the TCE, thereby enabling the TCE to associate the trace data with the correct subscriber.

[0132] In some embodiments, if the IP monitors the N2 interface and the N12 interface after the assignment of the GUTI to the UE, the relationship between the GUTI and the SUPI is established during a subsequent authentication event by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request. In an exemplary embodiment, even if monitoring by the IP begins after the UE has already been assigned the GUTI, the IP can still establish the relationship between the GUTI and the SUPI during a later authentication cycle. In such a case, the IP captures AUTN and RAND from a subsequent N12 authentication response and again captures the corresponding AUTN and RAND from the NAS authentication request conveyed on the first interface. By matching the parameters across the two interfaces, the IP reconstructs the association between the already-assigned temporary identifier and the permanent subscriber identity of the UE.

[0133] In an embodiment, one or more trace records including at least a Trace Reference (TR), a Trace Recording Session Reference (TRSR) are received from the base station. The one or more received trace records further includes the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID. The SUPI associated with the UE session corresponding to the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and a timestamp is retrieved based on the second mapping. The one or more trace recordsare enriched with the retrieved SUPI to enable continuous subscriber-aware network analytics. In an exemplary embodiment, the TCE receives one or more trace records generated by the base station for the UE 104, where each trace record includes at least the TR, the TRSR, the RAN-UE-NGAP-ID, and the AMF-UE-NGAP-ID. The TCE uses these parameters, optionally along with a timestamp associated with the trace record, to query the IP or to access correlation information derived from the second mapping. Based on the second mapping, the SUPI corresponding to the UE session is retrieved and inserted into the trace records. The enriched trace records enabling analytics platforms to perform subscriber-aware troubleshooting, service assurance, mobility investigation, and session-level behavioural analysis across radio and core network events.

[0134] FIG. 6 illustrates an exemplary computer system 600 in which or with which embodiments of the present disclosure may be implemented. As shown in FIG. 6, the computer system 600 may include an external storage device 610, a bus 620, a main memory 630, a read-only memory 640, a mass storage device 650, communication port(s) 660, and a processor 670. A person skilled in the art will appreciate that the computer system 600 may include more than one processor and communication ports. The processor 670 may include various modules associated with embodiments of the present disclosure. The communication port(s) 660 may be any of an RS-232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication port(s) 660 may be chosen depending on a network, such a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system 600 connects.

[0135] The main memory 630 may be a Random Access Memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory 640 may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chips for storing static information e.g., start-up or Basic Input / Output System (BIOS) instructions for the processor 670. The mass storage device 650 may be any current or future mass storage solution, which can be used to store information and / or instructions. Exemplary mass storage device 650 includes, but is not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives orsolid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces), one or more optical discs, Redundant Array of Independent Disks (RAID) storage, e.g. an array of disks.

[0136] The bus 620 communicatively couples the processor 670 with the other memory, storage, and communication blocks. The bus 620 may be, e.g. a Peripheral Component Interconnect (PCI) / PCI Extended (PCI-X) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor 670 to the computer system 600.

[0137] Optionally, operator and administrative interfaces, e.g. a display, keyboard, joystick, and a cursor control device, may also be coupled to the bus 620 to support direct operator interaction with the computer system. Other operator and administrative interfaces can be provided through network connections connected through the communication port(s) 660. Components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system 600 limit the scope of the present disclosure.

[0138] In an embodiment, the present disclosure provides a system and a method of using Intelligent Probing Platform (used for probing 5G interface such as N2 and N12) for establishing a relationship between a temporary identifier (GUTI) and a permanent identifier (SUPI). In some embodiments, the UE initiates a Registration Request with GUTI to gNB over N2 interface and the request is then forwarded to AMF. The IP captures this request and extracts and stores the NCGI (NR Cell Global Identity), RAN-UE-NGAP-ID, and GUTI from this message. Further, the AMF sends an Authentication Request containing SUPI to AUSF over N12 interface. The IP probes the N12 interface, captures this request and extracts SUPI information from this message. Further, the AUSF responds to AMF with Authentication Response. The IP captures this response over the N12 interface and extracts and stores the AUTN and RAND authentication parameters. Further, the IP creates an initial mapping between SUPI and the authentication parameters [AUTN and RAND] which is stored for correlation. Further, the AMF sends a NAS Authentication Request to UE (via gNB) over N2 interface such that the request contains AMF-UE-NGAP-ID, NCGI, RAN-UE-NGAP-ID, RAND and AUTN parameters, which are then extracted by the IP. Further, the IP correlates this withthe NCGI, RAN-UE-NGAP-ID. The IP then derives a complete correlation mapping of SUPI-GUTI-NCGI-RAN-UE-NGAP-ID-AMF-UE-NGAP-ID. Finally, the IP looks up for the corresponding SUPI using the correlation mapping based on the extracted NCGI, RAN-UE-NGAP-ID and AMF-UE-NGAP-ID.

[0139] In an embodiment, the present disclosure leverages authentication parameters (AUTN+RAND) to establish and maintain the relationship between temporary identifiers (GUTI) and permanent subscriber identities (SUPI) across session boundaries. The present disclosure introduces an Intelligent Probing Platform which probes N2 interface and N12 interface and an intelligent correlation mechanism that observes authentication flows across network interfaces to maintain subscriber identity continuity even when users reconnect using temporary identifiers (GUTI). By monitoring the authentication parameters that are unique to each subscriber session, the present disclosure may establish a reliable mapping between GUTI and SUPI without requiring modifications to standard network elements. In an embodiment, even if probing begins after GUTI assignment, the present disclosure may establish the GUTI-SUPI mapping during the next authentication event, ensuring complete subscriber visibility regardless of when monitoring began, solving a critical blind spot in 5G network analytics.

[0140] While the foregoing describes various embodiments of the invention, other and further embodiments of the invention may be devised without departing from the basic scope thereof. The scope of the invention is determined by the claims that follow. The invention is not limited to the described embodiments, versions or examples, which are included to enable a person having ordinary skill in the art to make and use the invention when combined with information and knowledge available to the person having ordinary skill in the art.

[0141] The method and system of the present disclosure may be implemented in a number of ways. For example, the methods and systems of the present disclosure may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order for the steps of the method is for illustration only, and the steps of the method of the present disclosure are not limited to the order specifically described above unless specifically stated otherwise. Further, in some embodiments, the present disclosure may also be embodied as programs recorded in a recording medium, the programs includingmachine-readable instructions for implementing the methods according to the present disclosure. Thus, the present disclosure also covers a recording medium storing a program for executing the method according to the present disclosure.

[0142] While considerable emphasis has been placed herein on the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be implemented merely as illustrative of the disclosure and not as a limitation.TECHNICAL ADVANCEMENTS

[0143] Continuous Subscriber Tracking: The present disclosure introduces a system and a method that ensures subscriber awareness beyond the initial registration throughout the entire lifecycle of a subscriber's connection, eliminating blind spots in subscriber trace records by mapping Globally Unique Temporary Identifier (GUTI) to Subscription Permanent Identifier (SUPI).

[0144] Retroactive Capability: The present disclosure introduces a system and a method that establishes GUTI-SUPI mapping even if network monitoring begins after GUTI assignment, ensuring no loss of subscriber context when tracing user sessions retroactively.

[0145] Zero Network Impact: The present disclosure introduces a system and a method that operates independently of user session signalling, ensuring no additional processing load on Fifth Generation (5G) core or radio network functions.

[0146] Enhanced Security and Compliance: The present disclosure introduces a system and a method that adheres to 5G security guidelines by never exposing plaintext International Mobile Subscriber Identity (IMSI) over the radio interface, ensuring privacy by leveraging authentication parameters (AUTN+RAND) instead of directly storing SUPI.

[0147] Complete Visibility into Subscriber Sessions: The present disclosure introduces a system and a method that prevents subscriber sessions from becoming "invisible" to analytics and troubleshooting tools, ensuring accurate trace recordenrichment, aiding in advanced network diagnostics and fraud detection.

[0148] Vendor-Agnostic Solution: The present disclosure introduces a system and a method that do not require modifications to 5GNew Radio (NR) or Core Network elements and fully compatible with any vendor's radio or core network infrastructure, enabling easy adoption.

Claims

CLAIMSWe Claim:

1. A method (500) for maintaining a relationship between identifiers of a User Equipment (UE) (104) in a network (106), the method (500) comprising:obtaining (502), by an Intelligence Probe (IP) (208), a plurality of registration parameters comprising a Globally Unique Temporary Identifier (GUTI), a New Radio Cell Global Identity (NCGI), and a Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) from a registration request via a first interface;obtaining (504), by the IP (208), a Subscription Permanent Identifier (SUP I) from an authentication request, and authentication parameters comprising an Authentication Token (AUTN) and a Random Number (RAND) from an authentication response via a second interface;establishing (506), by the IP (208), a first mapping between the SUPI, and the AUTN and the RAND;obtaining (508), by the IP (208), a plurality of Non-Access Stratum (NAS) authentication parameters comprising an AMF-User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, the AUTN, and the RAND from a NAS authentication request via the first interface;establishing (510), by the IP (208), a second mapping among the plurality of NAS authentication parameters, the plurality of registration parameters, and the first mapping by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request, to maintain a relationship between the GUTI and the SUPI of the UE (104); andidentifying (512), by the IP (208), the SUPI corresponding to the UE from the second mapping upon receiving a query from a Trace Collection Entity (TCE) (212), wherein the query comprises at least one of the plurality of NASauthentication parameters, the plurality of registration parameters, and the authentication parameters.

2. The method (500) as claimed in claim 1, wherein the first interface is an N2 interface between an Access and Mobility Management Function (AMF) (304) and a base station (302) and the second interface is an N12 interface between the AMF (304) and an Authentication Server Function (AUSF) (306), and wherein the IP (208) monitors the N2 interface and the N12 interface before an assignment of the GUTI to the UE (104).

3. The method (500) as claimed in claim 2, wherein if the IP (208) monitors the N2 interface and the N12 interface after the assignment of the GUTI to the UE (104), further comprising:establishing, by the IP (208), the relationship between the GUTI and the SUPI during a subsequent authentication event by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request.

4. The method (500) as claimed in claim 1, wherein establishing the second mapping, further comprising:forming, by the IP (208), a combined session reference based on the NCGI and the RAN-UE-NGAP-ID to uniquely identify the UE session across a plurality of base stations of the network (106).

5. The method (500) as claimed in claim 1, further comprising:transmitting, by the IP (208), the SUPI along with the registration parameters, the authentication parameters, and the NAS authentication parameters to the TCE (212) in a push mode, upon establishing the second mapping.

6. The method (500) as claimed in claim 1, further comprising:receiving, by the TCE (212), one or more trace records comprising at least a Trace Reference (TR), a Trace Recording Session Reference (TRSR) from thebase station, wherein the one or more received trace records further comprises the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID;retrieving, by the TCE (212), the SUPI associated with the UE session corresponding to the RAN-UE-NGAP-ID, the AMF-UE-NGAP-ID, and a timestamp based on the second mapping; andenriching, by the TCE (212), the one or more trace records with the retrieved SUPI to enable continuous subscriber-aware network analytics.

7. A system (108) for maintaining a relationship between identifiers of a User Equipment (UE) (104) in a network (106), the system (108) comprising:an Intelligence Probe (IP) (208) configured to:obtain a plurality of registration parameters comprising a Globally Unique Temporary Identifier (GUTI), a New Radio Cell Global Identity (NCGI), and a Radio Access Network -User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) from a registration request via a first interface;obtain a Subscription Permanent Identifier (SUPI) from an authentication request, and authentication parameters comprising an Authentication Token (AUTN) and a Random Number (RAND) from an authentication response via a second interface;establish a first mapping between the SUPI, and the AUTN and the RAND;obtain a plurality of Non-Access Stratum (NAS) authentication parameters comprising an AMF-User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN- UE-NGAP-ID, the AUTN, and the RAND from a NAS authentication request via the first interface;establish a second mapping among the plurality of NAS authentication parameters, the plurality of registration parameters, and thefirst mapping by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request, to maintain a relationship between the GUTI and the SUPI; andidentify the SUPI corresponding to the UE (104) from the second mapping upon receiving a query from a Trace Collection Entity (TCE) (212), wherein the query comprises at least one of the plurality of NAS authentication parameters, the plurality of registration parameters, and the authentication parameters.

8. A system (108) for maintaining a relationship between identifiers of a User Equipment (UE) (104) in a network (106), the system (108) comprising:a Trace Collection Entity (TCE) (212) configured to:receive one or more trace records comprising at least a Trace Reference (TR), a Trace Recording Session Reference (TRSR) from the base station, wherein the one or more received trace records further comprises the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID;extract UE context information comprising the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID from the one or more trace records;transmit a query to an Intelligence Probe (IP) (208), the query comprising the UE context information and a timestamp;receive a Subscription Permanent Identifier (SUPI) associated with a UE session corresponding to the UE context information from the IP (208); andenrich the one or more trace records with the received SUPI to enable subscriber-aware network analytics.

9. The system (108) as claimed in claim 7, wherein the first interface is an N2 interface between an Access and Mobility Management Function (AMF) (304) and a base station (302) and the second interface is an N12 interface between the AMF(304) and an Authentication Server Function (AUSF) (306), and wherein the IP (208) probes the N2 interface and the N12 interface before an assignment of the GUTI to the UE (104).

10. The system (108) as claimed in claim 9, wherein if the IP (208) probes the N2 interface and the N12 interface after the assignment of the GUTI to the UE (104), the IP (208) is configured to establish the relationship between the GUTI and the SUPI during a subsequent authentication event by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request.

11. The system (108) as claimed in claim 7, wherein to establish the second mapping, the IP (208) is configured to form a combined session reference based on the NCGI and the RAN-UE-NGAP-ID to uniquely identify the UE session across a plurality of base stations of the network (106).

12. The system (108) as claimed in claim 7, the IP (208) is configured to transmit the SUPI along with the registration parameters, the authentication parameters, and the NAS authentication parameters to the TCE (212) in a push mode, upon establishing the second mapping.

13. A computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute a method (500) for maintaining the relationship between identifiers of the UE (104) in the network (106), the method (500) comprising:obtaining, by an Intelligence Probe (IP), a plurality of registration parameters comprising a Globally Unique Temporary Identifier (GUTI ), a New Radio Cell Global Identity (NCGI), and a Radio Access Network-User Equipment-Next Generation Application Protocol Identifier (RAN-UE-NGAP-ID) from a registration request via a first interface;obtaining, by the Intelligence Probe (IP), a Subscription Permanent Identifier (SUPI) from an authentication request, and authentication parameterscomprising an Authentication Token (AUTN) and a Random Number (RAND) from an authentication response via a second interface;establishing, by the Intelligence Probe (IP), a first mapping between the SUPI, and the AUTN and the RAND;obtaining, by the IP, a plurality of Non-Access Stratum (NAS) authentication parameters comprising an AMF-User Equipment-Next Generation Application Protocol Identifier (AMF-UE-NGAP-ID), the NCGI, the RAN-UE-NGAP-ID, the AUTN, and the RAND from a NAS authentication request via the first interface;establishing, by the Intelligence Probe (IP), a second mapping among the plurality of NAS authentication parameters, the plurality of registration parameters, and the first mapping by matching the AUTN and the RAND obtained from the authentication response with the AUTN and the RAND obtained from the NAS authentication request, to maintain a relationship between the GUTI and the SUPI of the UE; andidentifying, by the Intelligence Probe (IP), the SUPI corresponding to the UE from the second mapping upon receiving a query from a Trace Collection Entity (TCE), wherein the query comprises at least one of the plurality of NAS authentication parameters, the plurality of registration parameters, and the authentication parameters.