Mobile Network Authentication Concealed Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods in 3GPP networks expose 5G UEs to bidding down attacks by sending secret subscriber identities in clear text during non-3GPP access, violating 5G security requirements by not concealing the permanent subscriber identity, especially when redirecting to EPC networks.
Innovation Solution
Implementing a method where 5G capable UEs use concealed identifiers, such as SUCI, instead of IMSI, during the initial authentication message, and network functions like AAA servers and HSSs de-conceal these identifiers to retrieve permanent identities, ensuring secure authentication through EAP-AKA/EAP-AKA′ authentication with 5GC networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If 5G UEs send secret subscriber identities in clear text during non-3GPP access authentication, then authentication compatibility with legacy networks is maintained, but security is compromised due to exposure of permanent subscriber identities
Solution Approach 1:
The patent segments the authentication process into two distinct phases: identity concealment phase where SUCI is sent in the first authentication message, and identity retrieval phase where the network function de-conceals the SUCI to obtain the permanent subscriber identity. This segmentation allows the system to maintain both security (through SUCI) and compatibility (through eventual IMSI retrieval) without exposing the permanent identity in clear text during transmission
Solution Approach 2:
The patent introduces an intermediary de-concealment function within the network function that acts as a mediator between the concealed SUCI and the permanent subscriber identity. This intermediary mechanism allows the network to handle both concealed identities (for security) and permanent identities (for legacy compatibility) without directly exposing the permanent identity during the authentication exchange
2Reliability
If 5G UEs use concealed identifiers like SUCI during authentication, then security requirements are met by preventing identity exposure, but network function complexity increases due to de-concealment requirements
Solution Approach 1:
The patent extracts the de-concealment functionality from the core network function and implements it as a separate, dedicated de-concealment function. This extraction allows the main network function to remain relatively simple while the complex de-concealment operation is handled by a specialized component, reducing the overall system complexity burden on the primary authentication function
Solution Approach 2:
The de-concealment function is designed to autonomously handle the conversion from SUCI to permanent subscriber identity without requiring manual intervention or complex external coordination. The function self-manages the cryptographic operations and identity mapping, reducing the operational complexity burden on the broader network system
3Reliability
If authentication messages include concealed identifiers instead of permanent identities, then security against bidding down attacks is improved, but message processing time increases due to de-concealment operations
Solution Approach 1:
The patent performs the de-concealment operation as a preliminary action during the authentication exchange, specifically when the network function receives the first authentication message containing the SUCI. By handling the de-concealment early in the process rather than later, the system minimizes the overall authentication time while still maintaining the security benefits of concealed identity transmission
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for supporting authentication with a mobile core network using a concealed identity. One apparatus includes a processor that sends a first authentication message that includes a concealed identifier to a network function to authenticate with a mobile communication network via a non-3GPP access network. The processor receives a second authentication message from the network function in response to the first authentication message. The second authentication message comprises an authentication response based on the concealed identifier. The processor completes authentication with the mobile communication network in response to the authentication response comprising a challenge packet. The processor receives configuration information for accessing the mobile communication network in response to successful authentication with the mobile communication network.


