5G Security Key Establishment for Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the 5G New Radio (NR) environment, ensuring privacy protection of the subscriber identity (SUPI) during roaming between telecommunications carriers is challenging, especially when the home PLMN (HPLMN) may not fully trust the visited PLMN (VPLMN), and lawful interception requires legitimacy verification without frequent SUPI verification.
Innovation Solution
A security establishment method that involves generating and sharing temporary keys (K ASME, K SEAF, and K AMF) between the user device (UE), UICC, HPLMN, and VPLMN, using the SUPI to establish secure communication, ensuring authentication and key agreement processes, and providing secure SUPI sharing only after successful authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the HPLMN provides the SUPI to the VPLMN for lawful interception, then the VPLMN can perform interception, but the privacy of the subscriber identity is compromised
Solution Approach 1:
The patent segments the SUPI into two parts: a concealed identifier (SUCI) that is encrypted and can be shared, and the actual SUPI that remains protected. The SUCI contains enough information for lawful interception purposes while the real subscriber identity remains hidden, thus enabling interception capability while preventing privacy violation.
Solution Approach 2:
The patent introduces an intermediary encryption mechanism using public-key cryptography. The HPLMN encrypts the SUPI to create a SUCI using the VPLMN's public key, acting as a mediator that allows the VPLMN to perform lawful interception on the encrypted identifier without exposing the actual subscriber identity, thus balancing interception needs with privacy protection.
2Reliability
If the HPLMN verifies the SUPI with the VPLMN for each lawful interception, then the security is maintained, but the operational efficiency decreases
Solution Approach 1:
The patent performs preliminary authentication and key agreement between the HPLMN and VPLMN before lawful interception operations. The security context including encryption keys is established in advance, allowing subsequent lawful interception operations to proceed without repeated verification, thus maintaining security while improving operational efficiency.
Solution Approach 2:
The patent creates a copy of the necessary security context (encrypted SUCI and associated keys) that can be used independently for lawful interception without requiring the original SUPI or repeated verification with the HPLMN, enabling efficient interception operations while maintaining security through the use of the copied encrypted data.
3Reliability
If the HPLMN does not trust the VPLMN, then security is compromised, but if the HPLMN trusts the VPLMN completely, then privacy protection is weakened
Solution Approach 1:
The patent changes the parameter of the subscriber identifier from plaintext SUPI to encrypted SUCI. This parameter transformation allows the VPLMN to handle and intercept data without having access to or knowledge of the actual subscriber identity, thus enabling operational trust while maintaining privacy protection through the changed identifier format.
Solution Approach 2:
The patent uses cryptographic encryption as an intermediary layer between the HPLMN and VPLMN. The encrypted SUCI acts as a mediator that allows the VPLMN to perform lawful interception functions without directly accessing or trusting the actual subscriber identity, thus enabling cooperation while maintaining privacy through the intermediary encryption mechanism.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A security establishment method includes generating a pair of keys via mutual authentication between a terminal device (110) and a serving network, and the terminal device (110) and the serving network sharing KASME by using the generated pair of keys (Steps S50 and S100), the terminal device (110) and a roaming destination network of the terminal device (110) generating, by using the KASME, KSEAF mapped with SEAF (50) (Steps S140 and S150), and the terminal device (110) and the roaming destination network generating, by using at least the KSEAF and SUPI used to recognize a subscriber in the serving network, KAMF mapped with AMF (60) (Steps S140 and S150).