Pseudo-AUSF Identity Resolution for Concealed 5G UE Identifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge in 5G mobile networks is the encryption of UE identifiers, which makes it difficult to determine the identity and location of devices, hindering security and privacy, and complicating legal investigations.
Innovation Solution
Implementing a pseudo-AUSF component with a narrow subset of functionalities, routing requests for identity resolution through a server to de-conceal encrypted UE identifiers using the existing UDM module, and providing the decrypted identifiers to authorized devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the permanent identifier (SUPI) is encrypted to create a concealed identifier (SUCI) for privacy and security, then user privacy and security are improved, but the ability to resolve identity and locate devices deteriorates
Solution Approach 1:
The patent introduces a pseudo-AUSF component as an intermediary between the encrypted SUCI and the UDM module. This pseudo-AUSF receives the concealed identifier, performs de-concealment to retrieve the permanent identifier, and forwards it to the UDM module for resolution. This mediator enables authorized entities to resolve identities without exposing unencrypted identifiers in the open network, thus maintaining security while restoring identity resolution capability.
2Reliability
If the concealed identifier changes with each self-identification to prevent tracking, then privacy protection is improved, but the ability to correlate signal readings and determine location deteriorates
Solution Approach 1:
The system performs preliminary de-concealment of the SUCI to obtain the permanent identifier before location determination processes. By resolving the identity in advance through the pseudo-AUSF and UDM module, the system can associate multiple changing SUCI instances with the same permanent identifier, enabling correlation of signal strength readings and trilateration for accurate location determination while the UE maintains privacy through ever-changing concealed identifiers.
3Difficulty of detecting and measuring
If a pseudo-AUSF component is implemented to resolve encrypted identifiers, then identity resolution capability is improved, but system complexity increases
Solution Approach 1:
The patent segments the AUSF functionality by introducing a pseudo-AUSF component that handles only the specific task of de-concealing SUCI to SUPI conversion. This segmentation isolates the complexity of handling encrypted identifiers into a dedicated, narrow-functionality component, while the existing AUSF and UDM modules continue to operate with their original functionalities. This modular approach adds capability without proportionally increasing overall system complexity.
4Ease of operation
If unencrypted permanent identifiers are used for self-identification, then ease of network authentication is improved, but vulnerability to criminal exploitation and privacy violations worsens
Solution Approach 1:
The pseudo-AUSF acts as a trusted intermediary that enables simplified authentication for authorized entities. When law enforcement or network operators need to authenticate or locate a device, they can use the permanent identifier obtained through the pseudo-AUSF's de-concealment process, enjoying the simplicity of unencrypted identifier handling. Meanwhile, regular network operations continue to use encrypted SUCI, protecting against criminal exploitation. The intermediary thus enables simple authentication where needed without exposing the system to widespread vulnerability.
Data Source
AI summary
A method includes implementing, through a server of a Fifth Generation (5G) mobile network, a pseudo-Authentication Server Function (AUSF) component as a component of an architecture of a core mobile network of the 5G mobile network distinct from an existing AUSF module thereof executing on the server, and automatically routing a request for identity resolution of a User Equipment (UE) connectable to the 5G mobile network to the pseudo-AUSF component instead of the existing AUSF module, with the request including a concealed identifier of the UE. The method also includes automatically resolving the concealed identifier into a permanent identifier of the UE utilizing an existing Unified Data Management (UDM) module of the core mobile network based on communication between the pseudo-AUSF component and the existing UDM module, and automatically providing, through the existing UDM module and the pseudo-AUSF component, the permanent identifier of the UE to address the request.


