5G SUCI Routing Indicator Update for Dynamic UDM Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The static configuration of the correspondence between a Routing Indicator (RI) and a Unified Data Management (UDM) network element in 5G networks lacks flexibility, failing to meet diverse service requirements and is vulnerable to attacks due to the transmission of the International Mobile Subscriber Identifier (IMSI) in plaintext during initial authentication.
Innovation Solution
A dynamic routing system is implemented using an encrypted Subscription Concealed Identifier (SUCI) that includes an RI, allowing network elements to determine the correct UDM network element based on the SUCI, and includes mechanisms for updating and securing the RI transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static configuration is used for RI-UDM correspondence, then routing stability is ensured, but flexibility and adaptability to diverse service requirements deteriorate
Solution Approach 1:
The patent transforms the static RI-UDM correspondence into a dynamic one by allowing the network device to determine the UDM network element based on the SUCI received from the terminal. The RI in the SUCI dynamically indicates the routing information, enabling flexible adaptation to different service requirements while maintaining routing stability through structured determination processes.
2Ease of operation
If IMSI is transmitted in plaintext during initial authentication, then authentication process is simplified, but security against attacks deteriorates
Solution Approach 1:
The patent extracts the routing information (RI) from the terminal identity and embeds it within the encrypted SUCI. This allows the authentication process to remain simple while enhancing security, as the RI is now protected within the encrypted identifier rather than being transmitted separately or in plaintext.
Solution Approach 2:
The SUCI acts as an intermediary that carries both the encrypted terminal identity and the routing indicator. This intermediary structure enables secure transmission by protecting the RI within encryption while still allowing network devices to route authentication requests to the correct UDM network element.
3Object-affected harmful factors
If SUCI with RI is used for authentication, then security against attacks is improved, but routing flexibility to meet diverse service requirements deteriorates
Solution Approach 1:
The patent changes the parameter structure of the SUCI to include the RI as an integral component. By embedding the routing indicator within the encrypted identifier, the system achieves both security (through encryption) and flexibility (through the RI that can indicate different routing scenarios for diverse services).
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
This application provides a routing method, apparatus, and system, and relates to the field of communications technologies, to update a routing indicator in a subscription concealed identifier when a user is migrated to a new unified subscriber data management UDM network element and the routing indicator in the subscription concealed identifier changes. The method includes: sending, by an authentication server function AUSF network element, a first authentication vector obtaining request to a first unified data management UDM network element; and if the AUSF network element receives a routing indicator RI sent by the first UDM network element, sending the RI to an access and mobility management function AMF network element. The method is applied to a process in which a terminal updates the RI.