Network Specific Identifier Derivation for Non-Public Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication technologies, such as 5G NR and LTE, face challenges in improving authentication mechanisms for user equipment (UE) accessing non-public networks (NPNs), particularly in ensuring privacy and security while maintaining compatibility with existing infrastructure.

Innovation Solution

The method involves deriving a network-specific identifier (NSI) in a network access identifier (NAI) format, which includes a network identifier (NID) stored at the UE, and generating a subscription concealed identifier (SUCI) for authentication with a non-public network (NPN), ensuring privacy by encrypting sensitive information and allowing seamless integration with existing authentication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication mechanisms are used for UE accessing NPNs, then compatibility with existing infrastructure is maintained, but authentication security and privacy are insufficient

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the authentication identifier from a plain IMSI format to a SUCI format by applying encryption parameters. The IMSI is encrypted using the home network's public key to generate SUCI, changing the parameter state from plaintext to ciphertext while maintaining the underlying authentication structure. This resolves the contradiction by enhancing security through parameter transformation without fundamentally changing the authentication mechanism.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The SUCI acts as an intermediary between the UE and the authentication server. Instead of directly transmitting the IMSI, the SUCI serves as a concealed identifier that mediates the authentication process. The network entity decrypts the SUCI to obtain the IMSI for verification, thus protecting privacy while maintaining authentication functionality. This intermediary approach enhances security without requiring complete redesign of the authentication system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If sensitive authentication information is transmitted in plaintext, then authentication process is simple, but privacy and security are compromised

Engineering Contradiction:
Improveprivacy protectionVSAvoididentifier generation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies encryption to transform the IMSI parameter into a SUCI parameter. The encryption process uses the home network's public key to convert the plaintext IMSI into ciphertext SUCI, thereby protecting privacy. The parameter change from plaintext to encrypted format prevents information loss or unauthorized access while maintaining the ability to authenticate through decryption.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The encryption of IMSI to generate SUCI is performed in advance before transmission to the network. This preliminary action of concealing the identifier before transmission prevents exposure of sensitive information during the authentication process. The UE prepares the SUCI beforehand, ensuring privacy protection is built into the authentication flow from the start rather than added as a subsequent measure.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a new authentication protocol is developed for NPNs, then authentication security is improved, but compatibility with existing systems decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The SUCI mechanism is designed to be universal and compatible with existing 5G authentication infrastructure. The same encryption and decryption processes used in public networks are applied to NPN authentication. The network entity can handle both SUCI and plain IMSI formats, allowing the system to serve multiple functions - protecting privacy in NPNs while maintaining compatibility with existing authentication workflows and infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of requiring the network to generate a new authentication protocol for NPNs, the patent inverts the approach by having the UE generate the concealed identifier (SUCI) before transmission. This inversion places the security function at the user equipment side rather than requiring network-side protocol changes, thereby improving security while maintaining compatibility with existing network infrastructure that can simply decrypt and process the SUCI as before.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP4035439B1Method for deriving a network specific identifier (NSI)
Publication Date: 2024.07.03 QUALCOMM INC
  • EP4035439B1 patent drawingFigure 1
  • EP4035439B1 patent drawingFigure 2
  • EP4035439B1 patent drawingFigure 3A

AI summary

Certain aspects provide a method for wireless communication. The method generally includes deriving a network specific identifier (NSI) in a network access identifier (NAI) format, the NSI including a network identifier (NID) stored at the UE, generating a subscription concealed identifier (SUCI) based on the NSI for authentication of the UE with a non-public network (NPN), and sending the SUCI to a network entity for the authentication of the UE with the NPN.