Network Specific Identifier Derivation for Non-Public Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication technologies, such as 5G NR and LTE, face challenges in improving authentication mechanisms for user equipment (UE) accessing non-public networks (NPNs), particularly in ensuring privacy and security while maintaining compatibility with existing infrastructure.
Innovation Solution
The method involves deriving a network-specific identifier (NSI) in a network access identifier (NAI) format, which includes a network identifier (NID) stored at the UE, and generating a subscription concealed identifier (SUCI) for authentication with a non-public network (NPN), ensuring privacy by encrypting sensitive information and allowing seamless integration with existing authentication protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication mechanisms are used for UE accessing NPNs, then compatibility with existing infrastructure is maintained, but authentication security and privacy are insufficient
Solution Approach 1:
The patent transforms the authentication identifier from a plain IMSI format to a SUCI format by applying encryption parameters. The IMSI is encrypted using the home network's public key to generate SUCI, changing the parameter state from plaintext to ciphertext while maintaining the underlying authentication structure. This resolves the contradiction by enhancing security through parameter transformation without fundamentally changing the authentication mechanism.
Solution Approach 2:
The SUCI acts as an intermediary between the UE and the authentication server. Instead of directly transmitting the IMSI, the SUCI serves as a concealed identifier that mediates the authentication process. The network entity decrypts the SUCI to obtain the IMSI for verification, thus protecting privacy while maintaining authentication functionality. This intermediary approach enhances security without requiring complete redesign of the authentication system.
2Loss of information
If sensitive authentication information is transmitted in plaintext, then authentication process is simple, but privacy and security are compromised
Solution Approach 1:
The patent applies encryption to transform the IMSI parameter into a SUCI parameter. The encryption process uses the home network's public key to convert the plaintext IMSI into ciphertext SUCI, thereby protecting privacy. The parameter change from plaintext to encrypted format prevents information loss or unauthorized access while maintaining the ability to authenticate through decryption.
Solution Approach 2:
The encryption of IMSI to generate SUCI is performed in advance before transmission to the network. This preliminary action of concealing the identifier before transmission prevents exposure of sensitive information during the authentication process. The UE prepares the SUCI beforehand, ensuring privacy protection is built into the authentication flow from the start rather than added as a subsequent measure.
3Reliability
If a new authentication protocol is developed for NPNs, then authentication security is improved, but compatibility with existing systems decreases
Solution Approach 1:
The SUCI mechanism is designed to be universal and compatible with existing 5G authentication infrastructure. The same encryption and decryption processes used in public networks are applied to NPN authentication. The network entity can handle both SUCI and plain IMSI formats, allowing the system to serve multiple functions - protecting privacy in NPNs while maintaining compatibility with existing authentication workflows and infrastructure.
Solution Approach 2:
Instead of requiring the network to generate a new authentication protocol for NPNs, the patent inverts the approach by having the UE generate the concealed identifier (SUCI) before transmission. This inversion places the security function at the user equipment side rather than requiring network-side protocol changes, thereby improving security while maintaining compatibility with existing network infrastructure that can simply decrypt and process the SUCI as before.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Certain aspects provide a method for wireless communication. The method generally includes deriving a network specific identifier (NSI) in a network access identifier (NAI) format, the NSI including a network identifier (NID) stored at the UE, generating a subscription concealed identifier (SUCI) based on the NSI for authentication of the UE with a non-public network (NPN), and sending the SUCI to a network entity for the authentication of the UE with the NPN.