Secure Element SUPI Switching for 5G Roaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The multi-IMSI solution for roaming in 3G/4G networks does not work in 5G networks because the IMSI (SUPI) is encrypted and cannot be routed to the home MNO for authentication.

Innovation Solution

A method is proposed where a secure element switches to a new SUPI recognized by a support entity, builds an entity support SUCI with a corresponding public key and routing ID, and routes an attachment request to the support entity for decryption and authentication with the home MNO.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the SUPI is encrypted as SUCI in 5G networks, then security and privacy are improved, but the ability to route authentication requests to the home MNO is lost

Engineering Contradiction:
ImprovesecurityVSAvoidrouting capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a support entity (roaming hub or sponsor MNO) as an intermediary that possesses the private key to decrypt the SUCI. This intermediary receives the attachment request with the encrypted SUCI, decrypts it to obtain the SUPI, performs the routing decision, and then forwards the request to the appropriate home MNO. This resolves the contradiction by maintaining encryption for security while enabling routing through the intermediary's decryption capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process into distinct phases: (1) the terminal encrypts SUPI as SUCI and sends to support entity, (2) the support entity decrypts SUCI to obtain SUPI and performs routing, (3) the home MNO receives the routed request and completes authentication. This segmentation allows different entities to have different capabilities - the terminal maintains security through encryption, while the support entity enables routing through decryption.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a multi-IMSI applet switches IMSI to sponsor IMSI for roaming, then roaming connectivity is improved, but the solution becomes incompatible with 5G encryption

Engineering Contradiction:
Improveroaming connectivityVSAvoid5G compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent changes the parameter from using plaintext IMSI/SUPI to using encrypted SUCI in 5G networks. The multi-IMSI applet now works with encrypted SUCI values instead of plaintext IMSI, and the support entity decrypts these SUCI values to obtain the original SUPI for routing. This parameter change maintains 5G security requirements while preserving multi-IMSI roaming functionality.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The support entity acts as a mediator that bridges the gap between the encrypted SUCI used by the terminal and the plaintext SUPI required by the home MNO for authentication. The support entity decrypts the SUCI, performs the IMSI switching logic, and forwards appropriate requests, enabling multi-IMSI functionality to work within the 5G encryption framework.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If the secure element stores multiple IMSIs for roaming, then flexibility for visiting different countries is improved, but the routing mechanism cannot identify the home MNO with encrypted SUPI

Engineering Contradiction:
Improveroaming flexibilityVSAvoidrouting information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The support entity serves as an intermediary that recovers the routing information (home MNO identity) from the encrypted SUCI. The terminal stores multiple SUCI values corresponding to different home MNOs, and the support entity decrypts the appropriate SUCI to obtain the SUPI, which contains the routing information needed to forward the request to the correct home MNO.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The routing information is prepared in advance by encrypting the SUPI as SUCI with the support entity's public key before storage in the secure element. This preliminary encryption action preserves the routing information in encrypted form, which the support entity can later decrypt to identify the home MNO without compromising security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12335895B2Method to enable a multi-IMSI solution within 5G networks
Publication Date: 2025.06.17 THALES DIS FRANCE SA
  • US12335895B2 patent drawing
  • US12335895B2 patent drawing
  • US12335895B2 patent drawing

AI summary

Provided is a method for attaching a terminal cooperating with a secure element to the network of a MNO of a visited country. The method includes steps of switching a set of files of said secure element to a new value, including a new SUPI, called entity support SUPI; Building at the level of said secure element an entity support SUCI; Routing an attachment request to said support entity with said entity support SUCI; Decrypting in said support entity said entity support SUCI back in said entity support SUPI; and Swapping said support entity SUPI to the SUPI corresponding to the MNO of the home country. If an authentication is performed that is positive, an attachment acknowledgement message is sent to connect said terminal to said network of said MNO of said visited country.