Network Exposure Function for SUCI-Based 5G Service Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G mobile networks, the transmission of plaintext IMSIs for mobile device identification exposes devices to IMSI catching, leading to tracking risks, and existing service authorization processes incur high latency and signaling overhead due to multiple network elements and unauthorized access to UE identifying information.
Innovation Solution
Implementing a Network Exposure Function (NEF) for SUCI-based service authorization, which centralizes UE service request authorization, reducing signaling traffic and latency while securing UE identifying information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If plaintext IMSI is transmitted for mobile device identification, then device identification is achieved, but security is compromised due to IMSI catching risks
Solution Approach 1:
The patent introduces SUCI (Subscription Concealed Identifier) as an intermediary that masks the plaintext IMSI during transmission. The SUCI is generated by encrypting the IMSI using the home network's public key, so that even if intercepted, the identifier cannot be read without the corresponding private key. This resolves the security contradiction by maintaining identification functionality while preventing IMSI catching attacks.
Solution Approach 2:
The patent changes the parameter of device identification from plaintext IMSI to encrypted SUCI. By transforming the identifier format through cryptographic encryption, the system maintains the uniqueness and functionality of the identifier while fundamentally changing its security properties to resist interception and analysis.
2Reliability
If multiple network elements are involved in service authorization, then comprehensive authorization is achieved, but latency and signaling overhead increase
Solution Approach 1:
The patent merges the authorization check into the service request message itself by including the SUCI directly in the initial service request. Instead of separate authorization signaling between multiple network elements, the AMF can directly verify the SUCI format and routing information within the same message flow, significantly reducing latency and signaling overhead while maintaining authorization accuracy.
3Ease of operation
If UE identifying information is accessed for service authorization, then service access control is achieved, but unauthorized access risks increase
Solution Approach 1:
The patent uses SUCI as an intermediary that enables service access control without exposing the underlying UE identifying information. The SUCI contains sufficient information for the network to perform authorization checks (through encryption verification and routing information) while preventing unauthorized entities from accessing or misusing the actual subscriber identity.
Solution Approach 2:
The patent converts the potential harm of exposing UE identifying information into a benefit by using cryptographic encryption. The encryption process transforms sensitive plaintext identifiers into secure ciphertext forms that can still be verified and used for authorization, but cannot be misused by unauthorized parties even if intercepted.
Data Source
AI summary
A network device receives a network service request, for network service in a mobile network, from a user equipment device (UE), where the network service request includes a first service identifier (ID) and a subscription concealed ID (SUCI). The network device sends, to a Network Function (NF) in the mobile network, a SUCI deconcealment request that includes the SUCI. The network device receives, from the NF, a deconcealed Subscription Permanent Identifier (SUPI) decrypted from the SUCI. The network device verifies a validity of the first service ID for the deconcealed SUPI, and sends a service authorization response to the UE based on verification of the validity of the service ID from the UE.


