Null-Scheme Access Authorization for 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In telecommunications, there is a need for enabling null-scheme access to a 5G network beyond emergency situations, particularly when a 5G device lacks a properly provisioned UICC or a 4G SIM card, or when a malicious actor impersonates a 5G subscriber, as existing systems restrict null-scheme access to emergency calls only.
Innovation Solution
An authorization system and process are implemented to determine whether a 5G user equipment device is authorized for non-emergency null-scheme access by creating a scheme authorization parameter, which checks if the device is permitted for such access, allowing authorized devices to register with the network using null-scheme access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If null-scheme access is restricted to emergency calls only, then network security is improved, but network accessibility deteriorates for legitimate devices that cannot generate SUCI
Solution Approach 1:
The patent changes the authorization parameter from a fixed emergency-only restriction to a dynamic parameter that can be set to different values (emergency only, non-emergency only, or both) based on network policy requirements. This allows the system to adapt between security and accessibility needs by modifying the parameter value in the authorization check.
Solution Approach 2:
The patent introduces dynamic authorization checking where the network device determines whether null-scheme access is authorized based on current network policies and device characteristics. The system transitions from a static emergency-only rule to a dynamic evaluation process that considers multiple factors including subscription data and network configuration.
2Adaptability or versatility
If null-scheme access is enabled for non-emergency situations, then network accessibility is improved for devices without SUCI capability, but network security deteriorates due to potential unauthorized access
Solution Approach 1:
The patent introduces an intermediary authorization checking mechanism between the null-scheme access request and network admission. The network device acts as an intermediary that validates whether the device is authorized for null-scheme access by checking authorization parameters against network policies, preventing unauthorized access while allowing legitimate access.
Solution Approach 2:
The patent implements a feedback mechanism where the network device checks the authorization parameter and provides feedback by either accepting or rejecting the null-scheme access request. This feedback loop ensures that only authorized devices can access the network via null-scheme, maintaining security while enabling accessibility.
3Reliability
If encryption is used to transmit SUPI, then privacy protection is improved, but device complexity increases due to SUCI generation requirements
Solution Approach 1:
The patent extracts the encryption functionality from the device by allowing null-scheme access for devices that cannot generate SUCI. Instead of requiring every device to have encryption capability, the system separates the encryption requirement from the access requirement, allowing unencrypted access paths for devices without encryption capability while maintaining encrypted access for devices with it.
Data Source
AI summary
A method may include receiving, at a network device, a registration request that comprises a subscription concealed identifier (SUCI) associated with a particular user equipment (UE) device. The network device determines whether the SUCI indicates a request for null-scheme network access; and retrieves a scheme authorization parameter for the UE device when it is determined that the SUCI indicates a request for null-scheme network access. The scheme authorization parameter indicates whether the UE device is authorized for null-scheme access to a service provider network. The network device determines whether the UE device is authorized for null-scheme network access based on the retrieved scheme authorization parameter and performs processing associated with null-scheme network access when it is determined that the particular UE device is authorized for null-scheme network access.


