Roaming Network Node Identifier Translation for Untrusted 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile communication systems lack an architecture that enables safe communication for terminals roaming outside their home operator's network when the home operator does not trust the visited network, as they are designed on the premise of mutual trust, leaving them vulnerable to threats like eavesdropping and spoofing.
Innovation Solution
Introduce a network node apparatus with a transmission unit that assigns identifiers linked to terminal contexts and performs processing without using permanent identifiers, separating authentication and service provisioning controls between home and visited networks, and implementing concealment and integrity protection mechanisms in the user and control planes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the HPLMN uses permanent identifiers (SUPI) for terminal identification in roaming networks, then authentication control can be performed, but the terminal becomes vulnerable to eavesdropping and spoofing attacks in untrusted VPLMN environments
Solution Approach 1:
The patent introduces an identifier translation mechanism where the VPLMN AMF acts as an intermediary. It receives messages containing permanent identifiers (SUPI) from the HPLMN, translates them into temporary identifiers (5G-S-TMSI), and forwards the translated identifiers to the terminal. This intermediary translation process prevents the terminal from directly exposing its permanent identifier in the untrusted VPLMN environment, thereby maintaining authentication control while protecting against eavesdropping and spoofing attacks.
Solution Approach 2:
The patent creates a copy mechanism where the permanent identifier (SUPI) is copied and translated into a temporary identifier (5G-S-TMSI). The terminal uses this copied temporary identifier for communication in the VPLMN instead of the original permanent identifier. This copying approach allows the system to maintain the functionality of identifier-based authentication while protecting the original permanent identifier from exposure to untrusted networks.
2Ease of operation
If the system architecture assumes mutual trust between HPLMN and VPLMN, then communication is simplified, but security is compromised when the VPLMN cannot be trusted
Solution Approach 1:
The patent segments the identifier management function into two distinct parts: permanent identifier (SUPI) management in the trusted HPLMN and temporary identifier (5G-S-TMSI) management in the VPLMN. The HPLMN AMF handles authentication using the permanent identifier, while the VPLMN AMF handles mobility and session management using the temporary identifier. This segmentation allows the system to maintain simple communication procedures in the VPLMN while ensuring security through the trusted HPLMN's control over the permanent identifier.
Solution Approach 2:
The HPLMN AMF serves as a security intermediary that mediates between the terminal and the untrusted VPLMN. It performs authentication control using the permanent identifier and then translates it to a temporary identifier for use in the VPLMN. This intermediary mechanism allows simplified communication in the VPLMN while maintaining security boundaries, as the HPLMN AMF controls and protects the permanent identifier from exposure to untrusted networks.
3Ease of operation
If the VPLMN AMF directly uses the SUPI for terminal identification, then authentication and service provisioning are straightforward, but the terminal's privacy is compromised in untrusted networks
Solution Approach 1:
The HPLMN AMF acts as an intermediary that receives the permanent identifier (SUPI) for authentication processing, translates it into a temporary identifier (5G-S-TMSI), and then provides this temporary identifier to the VPLMN AMF. This intermediary translation process maintains the ease of authentication processing (as the HPLMN AMF still has access to the SUPI) while protecting terminal privacy by preventing the VPLMN AMF and the terminal from directly exposing the permanent identifier in untrusted environments.
Solution Approach 2:
The system creates a copy of the permanent identifier's functionality through the temporary identifier. The VPLMN AMF receives and processes the copied temporary identifier (5G-S-TMSI) instead of the original permanent identifier (SUPI). This copying mechanism maintains the operational simplicity of identifier-based authentication and service provisioning while protecting terminal privacy, as the temporary identifier cannot be used to directly identify or trace the terminal's permanent identity in untrusted networks.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A network node apparatus includes: a transmission unit configured to assign, to another network node apparatus that handles authentication control or service provisioning control, an identifier linked with a terminal context within the other network node apparatus, and to transmit to the other network node apparatus a message including the identifier; and a control unit configured to perform processing for mobility control or connection control using the identifier without using a permanent identifier of a terminal.