SUCI De-Concealing for Secure SUPI Authentication Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems expose the long-term subscription identifier of a user equipment (UE) over the air interface, compromising confidentiality, and legacy mechanisms are inadequate in protecting this identifier.
Innovation Solution
A method involving a UE and an authentication server that utilizes a Subscription Concealed Identifier (SUCI) with an encrypted part and clear-text part, using a home network public key for encryption, and a de-concealing server to decrypt the SUCI, ensuring confidentiality through Elliptic Curve Integrated Encryption Scheme (ECIES) and distributed SIDF deployments for fault tolerance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the SUPI is transmitted in clear text during authentication, then the authentication process is simple and fast, but the user's subscription identifier becomes vulnerable to interception and misuse by unauthorized networks
Solution Approach 1:
The authentication process is segmented into multiple stages: initial authentication using clear text SUPI, followed by a second authentication stage using a different identifier. This segmentation allows the system to balance security and simplicity by using different authentication methods for different purposes.
Solution Approach 2:
The network introduces an intermediary identifier (different from both SUPI and traditional IMSI) that acts as a mediator between the clear text SUPI and the authentication server. This intermediary protects the SUPI from direct exposure while enabling authentication, thus resolving the contradiction between security and simplicity.
2Reliability
If a new identifier different from SUPI and traditional IMSI is introduced, then the SUPI is protected from interception, but the network requires more information to identify and authenticate the UE
Solution Approach 1:
The new intermediary identifier serves multiple functions: it protects the SUPI from interception, enables authentication without exposing the permanent identifier, and can be used for both initial network access and subsequent secure communications. This multi-functionality reduces the need for separate mechanisms for each purpose.
Solution Approach 2:
The network performs preliminary actions by establishing the intermediary identifier and authentication mechanisms before the actual authentication process. This preliminary setup ensures that the SUPI is protected from the outset without requiring complex real-time processing during authentication.
3Reliability
If the network stores and processes additional identifier information, then UE identification and authentication are secured, but the network's information storage and processing requirements increase
Solution Approach 1:
The patent applies local quality by storing and processing different types of identifier information in different network locations and contexts. The intermediary identifier is stored and processed in specific network elements where it is needed for authentication, rather than duplicating all identifier information across the entire network, thus optimizing storage requirements.
Data Source
Figure 1
Figure 2~3
Figure 4~5
AI summary
A method performed by an authentication server (14) in a home network (3) of a user equipment (1), UE, for obtaining a subscription permanent identifier, SUPI. The method comprises: - receiving a subscription concealed identifier, SUCI, which comprises an encrypted part in which at least a part of the SUPI is encrypted, and a clear-text part which comprises a home network identifier and an encryption scheme identifier that identifies an encryption scheme used by the UE to encrypt the SUPI in the SUCI, - determining a de-concealing server (19) to use to decrypt the encrypted part of the SUCI; - sending the SUCI to the de-concealing server (19), and - receiving the SUPI in response. Methods performed by a UE and a de-concealing server are also disclosed. Furthermore, UEs, de-concealing servers, authentication servers, computer program (133) and a memory circuitry (12) are also disclosed.