Non-3GPP Access Authentication via SUCI De-Concealment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional technical solutions for Non-3GPP access authentication in Evolved Packet Core (EPC) and 5G Core (5GC) coexistence face challenges in handling UE identity privacy and authentication credentials retrieval.
Innovation Solution
Implement mechanisms for retrieving authentication credentials based on privacy-protected subscriber identities, including standalone concealed identity de-concealment services, enhanced Diameter-based and UDICOM-based services, and UE-determined identity privacy activation, to support Non-3GPP access authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If UE identity privacy is activated using concealed identity (SUCI), then subscriber identity privacy is protected, but authentication credentials retrieval becomes complex requiring de-concealment services
Solution Approach 1:
The patent introduces an intermediary entity (AAA server or authentication entity) that performs de-concealment of the SUCI to retrieve the original subscriber identity. This intermediary handles the complexity of de-concealment operations, allowing the UE to simply use SUCI for authentication while the intermediary resolves the concealed identity to fetch authentication credentials from the subscription database.
Solution Approach 2:
The system performs preliminary de-concealment of the SUCI before authentication credential retrieval. The concealed identity is decoded in advance to obtain the original subscriber identity, which is then used to query the subscription database for authentication credentials. This preliminary action simplifies the overall authentication flow by preparing the identity information beforehand.
2Adaptability or versatility
If Non-3GPP access authentication supports concealed identity, then 5GC compatibility is improved, but existing EPC authentication procedures become complex
Solution Approach 1:
The patent creates a universal authentication mechanism that works with both 5GC and EPC networks. The system can handle concealed identities (SUCI) required by 5GC while maintaining compatibility with existing EPC procedures. The AAA server or authentication entity performs de-concealment to make the identity usable in both network architectures, providing multi-functionality across different network types.
Solution Approach 2:
An intermediary authentication entity serves as a bridge between 5GC and EPC networks. This intermediary handles the conversion and adaptation of authentication procedures, performing de-concealment of SUCI when needed and interfacing with both 5GC subscription databases and EPC authentication mechanisms, thereby simplifying the complexity for individual network implementations.
3Ease of operation
If UE determines identity privacy activation autonomously, then authentication flexibility is improved, but network coordination requirements increase
Solution Approach 1:
The UE autonomously determines whether to activate identity privacy based on its own policies, preferences, or local configurations. The UE can independently decide to use SUCI instead of plain IMSI for authentication requests without requiring real-time network approval, enabling self-service authentication flexibility while the network processes the request accordingly.
Solution Approach 2:
The network provides feedback mechanisms (such as network information elements or policy indicators) that inform the UE about network-supported authentication methods and privacy options. The UE uses this feedback to make informed decisions about identity privacy activation, ensuring that autonomous UE decisions align with network capabilities and policies.
Data Source
AI summary
The present disclosure provides methods, entities, and computer readable media for Non-3GPP access authentication. A method (500A) performed by an entity for AAA incudes: receiving (S501A), from a Non-3GPP access element, a request message for authentication including an identity of a UE to be authenticated, wherein the identity of the UE includes a concealed identity of the UE or a first identity of the UE; detecting (S503A) the identity of the UE from the received request message for authentication; and transmitting (S505A), to an interworking entity, a first request message for authentication credentials, which at least includes the detected identity of the UE.


