Network Exposure Function for SUCI-Based 5G Service Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G mobile networks, the transmission of plaintext IMSIs for mobile device identification exposes devices to IMSI catching, leading to tracking risks, and existing service authorization processes incur high latency and signaling overhead due to multiple network elements and unauthorized access to UE identifying information.

Innovation Solution

Implementing a Network Exposure Function (NEF) for SUCI-based service authorization, which centralizes UE service request authorization, reducing signaling traffic and latency while securing UE identifying information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If plaintext IMSI is transmitted for mobile device identification, then device identification is achieved, but security is compromised due to IMSI catching risks

Engineering Contradiction:
ImprovesecurityVSAvoidIMSI catching risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces SUCI (Subscription Concealed Identifier) as an intermediary that masks the plaintext IMSI during transmission. The SUCI is generated by encrypting the IMSI using the home network's public key, so that even if intercepted, the identifier cannot be read without the corresponding private key. This resolves the security contradiction by maintaining identification functionality while preventing IMSI catching attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of device identification from plaintext IMSI to encrypted SUCI. By transforming the identifier format through cryptographic encryption, the system maintains the uniqueness and functionality of the identifier while fundamentally changing its security properties to resist interception and analysis.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple network elements are involved in service authorization, then comprehensive authorization is achieved, but latency and signaling overhead increase

Engineering Contradiction:
Improveauthorization accuracyVSAvoidauthorization latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the authorization check into the service request message itself by including the SUCI directly in the initial service request. Instead of separate authorization signaling between multiple network elements, the AMF can directly verify the SUCI format and routing information within the same message flow, significantly reducing latency and signaling overhead while maintaining authorization accuracy.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If UE identifying information is accessed for service authorization, then service access control is achieved, but unauthorized access risks increase

Engineering Contradiction:
Improveservice access controlVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent uses SUCI as an intermediary that enables service access control without exposing the underlying UE identifying information. The SUCI contains sufficient information for the network to perform authorization checks (through encryption verification and routing information) while preventing unauthorized entities from accessing or misusing the actual subscriber identity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent converts the potential harm of exposing UE identifying information into a benefit by using cryptographic encryption. The encryption process transforms sensitive plaintext identifiers into secure ciphertext forms that can still be verified and used for authorization, but cannot be misused by unauthorized parties even if intercepted.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS12363076B2Network exposure function (NEF) for SUCI-based UE-initiated service authorization
Publication Date: 2025.07.15 VERIZON PATENT & LICENSING INC
  • US12363076B2 patent drawing
  • US12363076B2 patent drawing
  • US12363076B2 patent drawing

AI summary

A network device receives a network service request, for network service in a mobile network, from a user equipment device (UE), where the network service request includes a first service identifier (ID) and a subscription concealed ID (SUCI). The network device sends, to a Network Function (NF) in the mobile network, a SUCI deconcealment request that includes the SUCI. The network device receives, from the NF, a deconcealed Subscription Permanent Identifier (SUPI) decrypted from the SUCI. The network device verifies a validity of the first service ID for the deconcealed SUPI, and sends a service authorization response to the UE based on verification of the validity of the service ID from the UE.