AUSF Node Maps Anonymous SUCI to SUPI for 5G Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G communication systems, the use of anonymous SUCI (Subscription Concelled Identifier) during initial registration can lead to authentication failures, as the UDM (Unified Data Management) node may not be able to locate the UE's subscription or provide the proper SUPI (Subscription Permanent Identifier) back to the AUSF (Authentication Server Function) node.
Innovation Solution
The AUSF node maps the information conveyed over EAP TLS to a second SUCI or SUPI, allowing it to fetch the UE's authentication subscription data and genuine SUPI from the UDM, even when an anonymous SUCI is used.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If anonymous SUCI is used during initial registration, then subscriber privacy is protected, but authentication fails because UDM cannot locate the UE's subscription or provide the proper SUPI back to AUSF
Solution Approach 1:
The AUSF node performs preliminary mapping of the anonymous SUCI to a permanent identifier (SUPI or second SUCI) before the authentication procedure. This preliminary action enables the UDM to locate the subscriber's authentication data in advance, preventing authentication failure while maintaining privacy during the registration process.
Solution Approach 2:
The AUSF node acts as an intermediary between the UDM and the anonymous SUCI. It maps the anonymous identifier to a resolvable identifier (SUPI or second SUCI) that the UDM can use to locate subscription data, thereby bridging the gap between privacy protection and authentication functionality.
2Adaptability or versatility
If anonymous SUCI is used, then devices can register without 5G capabilities, but the network cannot retrieve subscription data using the anonymous identifier
Solution Approach 1:
The AUSF node performs preliminary mapping of the anonymous SUCI to a permanent identifier (SUPI or second SUCI) before the authentication procedure. This preliminary action enables the UDM to locate the subscriber's authentication data in advance, preventing authentication failure while maintaining privacy during the registration process.
Solution Approach 2:
The AUSF node acts as an intermediary between the UDM and the anonymous SUCI. It maps the anonymous identifier to a resolvable identifier (SUPI or second SUCI) that the UDM can use to locate subscription data, thereby bridging the gap between privacy protection and authentication functionality.
Data Source
AI summary
A first network node operating in a telecommunications network can receive an authentication request associated with a communication device requesting registration with the telecommunications network. The authentication request can include first subscriber information. The first network node can determine that the first subscriber information includes an anonymous identifier. Responsive to determining that the first subscriber information includes the anonymous identifier, the network node can determine an authentication procedure to be performed. The network node can receive information associated with the communication device as part of the authentication procedure. The network node can generate second subscriber information based on the information associated with the communication device.


