5G SUCI Routing Indicator Update for Dynamic UDM Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The static configuration of the correspondence between a Routing Indicator (RI) and a Unified Data Management (UDM) network element in 5G networks lacks flexibility, failing to meet diverse service requirements and is vulnerable to attacks due to the transmission of the International Mobile Subscriber Identifier (IMSI) in plaintext during initial authentication.

Innovation Solution

A dynamic routing system is implemented using an encrypted Subscription Concealed Identifier (SUCI) that includes an RI, allowing network elements to determine the correct UDM network element based on the SUCI, and includes mechanisms for updating and securing the RI transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static configuration is used for RI-UDM correspondence, then routing stability is ensured, but flexibility and adaptability to diverse service requirements deteriorate

Engineering Contradiction:
Improverouting stabilityVSAvoidflexibility for diverse service requirements
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static RI-UDM correspondence into a dynamic one by allowing the network device to determine the UDM network element based on the SUCI received from the terminal. The RI in the SUCI dynamically indicates the routing information, enabling flexible adaptation to different service requirements while maintaining routing stability through structured determination processes.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If IMSI is transmitted in plaintext during initial authentication, then authentication process is simplified, but security against attacks deteriorates

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the routing information (RI) from the terminal identity and embeds it within the encrypted SUCI. This allows the authentication process to remain simple while enhancing security, as the RI is now protected within the encrypted identifier rather than being transmitted separately or in plaintext.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The SUCI acts as an intermediary that carries both the encrypted terminal identity and the routing indicator. This intermediary structure enables secure transmission by protecting the RI within encryption while still allowing network devices to route authentication requests to the correct UDM network element.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If SUCI with RI is used for authentication, then security against attacks is improved, but routing flexibility to meet diverse service requirements deteriorates

Engineering Contradiction:
Improveprotection against attacksVSAvoidrouting flexibility for diverse services
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameter structure of the SUCI to include the RI as an integral component. By embedding the routing indicator within the encrypted identifier, the system achieves both security (through encryption) and flexibility (through the RI that can indicate different routing scenarios for diverse services).

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3709692B1Routing method, apparatus and system
Publication Date: 2025.12.24 HUAWEI TECH CO LTD
  • EP3709692B1 patent drawingFigure 1
  • EP3709692B1 patent drawingFigure 2~3
  • EP3709692B1 patent drawingFigure 4

AI summary

This application provides a routing method, apparatus, and system, and relates to the field of communications technologies, to update a routing indicator in a subscription concealed identifier when a user is migrated to a new unified subscriber data management UDM network element and the routing indicator in the subscription concealed identifier changes. The method includes: sending, by an authentication server function AUSF network element, a first authentication vector obtaining request to a first unified data management UDM network element; and if the AUSF network element receives a routing indicator RI sent by the first UDM network element, sending the RI to an access and mobility management function AMF network element. The method is applied to a process in which a terminal updates the RI.