Mobile Network Authentication Concealed Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in 3GPP networks expose 5G UEs to bidding down attacks by sending secret subscriber identities in clear text during non-3GPP access, violating 5G security requirements by not concealing the permanent subscriber identity, especially when redirecting to EPC networks.

Innovation Solution

Implementing a method where 5G capable UEs use concealed identifiers, such as SUCI, instead of IMSI, during the initial authentication message, and network functions like AAA servers and HSSs de-conceal these identifiers to retrieve permanent identities, ensuring secure authentication through EAP-AKA/EAP-AKA′ authentication with 5GC networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If 5G UEs send secret subscriber identities in clear text during non-3GPP access authentication, then authentication compatibility with legacy networks is maintained, but security is compromised due to exposure of permanent subscriber identities

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication message structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into two distinct phases: identity concealment phase where SUCI is sent in the first authentication message, and identity retrieval phase where the network function de-conceals the SUCI to obtain the permanent subscriber identity. This segmentation allows the system to maintain both security (through SUCI) and compatibility (through eventual IMSI retrieval) without exposing the permanent identity in clear text during transmission

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary de-concealment function within the network function that acts as a mediator between the concealed SUCI and the permanent subscriber identity. This intermediary mechanism allows the network to handle both concealed identities (for security) and permanent identities (for legacy compatibility) without directly exposing the permanent identity during the authentication exchange

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If 5G UEs use concealed identifiers like SUCI during authentication, then security requirements are met by preventing identity exposure, but network function complexity increases due to de-concealment requirements

Engineering Contradiction:
Improvesubscriber identity protectionVSAvoidnetwork function processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the de-concealment functionality from the core network function and implements it as a separate, dedicated de-concealment function. This extraction allows the main network function to remain relatively simple while the complex de-concealment operation is handled by a specialized component, reducing the overall system complexity burden on the primary authentication function

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The de-concealment function is designed to autonomously handle the conversion from SUCI to permanent subscriber identity without requiring manual intervention or complex external coordination. The function self-manages the cryptographic operations and identity mapping, reducing the operational complexity burden on the broader network system

Inventive Principle:
Principle #25Self-service

3Reliability

If authentication messages include concealed identifiers instead of permanent identities, then security against bidding down attacks is improved, but message processing time increases due to de-concealment operations

Engineering Contradiction:
Improveresistance to bidding down attacksVSAvoidauthentication completion time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs the de-concealment operation as a preliminary action during the authentication exchange, specifically when the network function receives the first authentication message containing the SUCI. By handling the de-concealment early in the process rather than later, the system minimizes the overall authentication time while still maintaining the security benefits of concealed identity transmission

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230262463A1Mobile network authentication using a concealed identity
Publication Date: 2023.08.17 LENOVO (SINGAPORE) PTE LTD
  • US20230262463A1 patent drawing
  • US20230262463A1 patent drawing
  • US20230262463A1 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for supporting authentication with a mobile core network using a concealed identity. One apparatus includes a processor that sends a first authentication message that includes a concealed identifier to a network function to authenticate with a mobile communication network via a non-3GPP access network. The processor receives a second authentication message from the network function in response to the first authentication message. The second authentication message comprises an authentication response based on the concealed identifier. The processor completes authentication with the mobile communication network in response to the authentication response comprising a challenge packet. The processor receives configuration information for accessing the mobile communication network in response to successful authentication with the mobile communication network.