SUCI De-Concealing for Secure SUPI Authentication Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems expose the long-term subscription identifier of a user equipment (UE) over the air interface, compromising confidentiality, and legacy mechanisms are inadequate in protecting this identifier.

Innovation Solution

A method involving a UE and an authentication server that utilizes a Subscription Concealed Identifier (SUCI) with an encrypted part and clear-text part, using a home network public key for encryption, and a de-concealing server to decrypt the SUCI, ensuring confidentiality through Elliptic Curve Integrated Encryption Scheme (ECIES) and distributed SIDF deployments for fault tolerance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the SUPI is transmitted in clear text during authentication, then the authentication process is simple and fast, but the user's subscription identifier becomes vulnerable to interception and misuse by unauthorized networks

Engineering Contradiction:
Improvesecurity of subscription identifierVSAvoidcomplexity of authentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into multiple stages: initial authentication using clear text SUPI, followed by a second authentication stage using a different identifier. This segmentation allows the system to balance security and simplicity by using different authentication methods for different purposes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network introduces an intermediary identifier (different from both SUPI and traditional IMSI) that acts as a mediator between the clear text SUPI and the authentication server. This intermediary protects the SUPI from direct exposure while enabling authentication, thus resolving the contradiction between security and simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a new identifier different from SUPI and traditional IMSI is introduced, then the SUPI is protected from interception, but the network requires more information to identify and authenticate the UE

Engineering Contradiction:
Improveprotection of SUPI from interceptionVSAvoidamount of information required for authentication
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The new intermediary identifier serves multiple functions: it protects the SUPI from interception, enables authentication without exposing the permanent identifier, and can be used for both initial network access and subsequent secure communications. This multi-functionality reduces the need for separate mechanisms for each purpose.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The network performs preliminary actions by establishing the intermediary identifier and authentication mechanisms before the actual authentication process. This preliminary setup ensures that the SUPI is protected from the outset without requiring complex real-time processing during authentication.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the network stores and processes additional identifier information, then UE identification and authentication are secured, but the network's information storage and processing requirements increase

Engineering Contradiction:
Improvesecurity of UE authenticationVSAvoidamount of information stored in network
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by storing and processing different types of identifier information in different network locations and contexts. The intermediary identifier is stored and processed in specific network elements where it is needed for authentication, rather than duplicating all identifier information across the entire network, thus optimizing storage requirements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4535719B1Subscription concealed identifier
Publication Date: 2026.05.13 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4535719B1 patent drawingFigure 1
  • EP4535719B1 patent drawingFigure 2~3
  • EP4535719B1 patent drawingFigure 4~5

AI summary

A method performed by an authentication server (14) in a home network (3) of a user equipment (1), UE, for obtaining a subscription permanent identifier, SUPI. The method comprises: - receiving a subscription concealed identifier, SUCI, which comprises an encrypted part in which at least a part of the SUPI is encrypted, and a clear-text part which comprises a home network identifier and an encryption scheme identifier that identifies an encryption scheme used by the UE to encrypt the SUPI in the SUCI, - determining a de-concealing server (19) to use to decrypt the encrypted part of the SUCI; - sending the SUCI to the de-concealing server (19), and - receiving the SUPI in response. Methods performed by a UE and a de-concealing server are also disclosed. Furthermore, UEs, de-concealing servers, authentication servers, computer program (133) and a memory circuitry (12) are also disclosed.