Secure Element SUPI Switching for 5G Roaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The multi-IMSI solution for roaming in 3G/4G networks does not work in 5G networks because the IMSI (SUPI) is encrypted and cannot be routed to the home MNO for authentication.
Innovation Solution
A method is proposed where a secure element switches to a new SUPI recognized by a support entity, builds an entity support SUCI with a corresponding public key and routing ID, and routes an attachment request to the support entity for decryption and authentication with the home MNO.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the SUPI is encrypted as SUCI in 5G networks, then security and privacy are improved, but the ability to route authentication requests to the home MNO is lost
Solution Approach 1:
The patent introduces a support entity (roaming hub or sponsor MNO) as an intermediary that possesses the private key to decrypt the SUCI. This intermediary receives the attachment request with the encrypted SUCI, decrypts it to obtain the SUPI, performs the routing decision, and then forwards the request to the appropriate home MNO. This resolves the contradiction by maintaining encryption for security while enabling routing through the intermediary's decryption capability.
Solution Approach 2:
The patent segments the authentication process into distinct phases: (1) the terminal encrypts SUPI as SUCI and sends to support entity, (2) the support entity decrypts SUCI to obtain SUPI and performs routing, (3) the home MNO receives the routed request and completes authentication. This segmentation allows different entities to have different capabilities - the terminal maintains security through encryption, while the support entity enables routing through decryption.
2Adaptability or versatility
If a multi-IMSI applet switches IMSI to sponsor IMSI for roaming, then roaming connectivity is improved, but the solution becomes incompatible with 5G encryption
Solution Approach 1:
The patent changes the parameter from using plaintext IMSI/SUPI to using encrypted SUCI in 5G networks. The multi-IMSI applet now works with encrypted SUCI values instead of plaintext IMSI, and the support entity decrypts these SUCI values to obtain the original SUPI for routing. This parameter change maintains 5G security requirements while preserving multi-IMSI roaming functionality.
Solution Approach 2:
The support entity acts as a mediator that bridges the gap between the encrypted SUCI used by the terminal and the plaintext SUPI required by the home MNO for authentication. The support entity decrypts the SUCI, performs the IMSI switching logic, and forwards appropriate requests, enabling multi-IMSI functionality to work within the 5G encryption framework.
3Adaptability or versatility
If the secure element stores multiple IMSIs for roaming, then flexibility for visiting different countries is improved, but the routing mechanism cannot identify the home MNO with encrypted SUPI
Solution Approach 1:
The support entity serves as an intermediary that recovers the routing information (home MNO identity) from the encrypted SUCI. The terminal stores multiple SUCI values corresponding to different home MNOs, and the support entity decrypts the appropriate SUCI to obtain the SUPI, which contains the routing information needed to forward the request to the correct home MNO.
Solution Approach 2:
The routing information is prepared in advance by encrypting the SUPI as SUCI with the support entity's public key before storage in the secure element. This preliminary encryption action preserves the routing information in encrypted form, which the support entity can later decrypt to identify the home MNO without compromising security.
Data Source
AI summary
Provided is a method for attaching a terminal cooperating with a secure element to the network of a MNO of a visited country. The method includes steps of switching a set of files of said secure element to a new value, including a new SUPI, called entity support SUPI; Building at the level of said secure element an entity support SUCI; Routing an attachment request to said support entity with said entity support SUCI; Decrypting in said support entity said entity support SUCI back in said entity support SUPI; and Swapping said support entity SUPI to the SUPI corresponding to the MNO of the home country. If an authentication is performed that is positive, an attachment acknowledgement message is sent to connect said terminal to said network of said MNO of said visited country.


