5G SUCI Segmentation for NPN Subscription Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current 5G system lacks a means to identify a UE's NPN subscription, which is necessary for supporting 5G systems that provide both PLMN and NPN services. This leads to issues in selecting the appropriate Access Management Function/Security Anchor Function (AMF/SEAF), Authentication Function (AUSF), and Unified Data Management (UDM) instances for NPN services, resulting in NPN UE identification and node selection failures. Additionally, the lack of privacy protection for UE NPN IDs makes the 5G system vulnerable to user tracking, Denial of Service (DOS), and Distributed Denial of Service (DDOS) attacks.

Innovation Solution

The proposed solution involves enhancing the Subscription Concealed Identifier (SUCI) to include Network Subscription Type information, which allows the 5G system to identify the specific network type a UE is subscribed to. This is achieved by modifying the UE to include a transceiver circuit and a controller that sends an identifier to the AMF, maintaining a secure connection upon successful authentication. The system also involves a method where the UE sends a registration request with SUCI information, which is verified by the AMF and routed to appropriate AUSF and UDM instances based on the network subscription type.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the SUCI contains only PLMN specific information, then the routing to PLMN nodes is simplified, but the identification of NPN subscriptions and selection of appropriate NPN nodes fails

Engineering Contradiction:
ImproveSUCI structureVSAvoidUE network subscription information
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The SUCI is segmented into distinct components: PLMN-specific routing information (for routing to correct AMF/AUSF/UDM) and NPN-specific subscription information (for identifying NPN service eligibility). This segmentation allows each part to serve its specific function without compromising the other, resolving the contradiction between simplified routing and complete identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The NPN subscription information is extracted as a separate element within the SUCI structure, distinct from the PLMN identification components. This extracted NPN-specific information can be independently processed by the network nodes to determine NPN service eligibility while maintaining the PLMN routing functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

2Device complexity

If the UE uses a single SUPI for both PLMN and NPN subscriptions, then the subscription management is simplified, but privacy protection is compromised and the system becomes vulnerable to tracking and attacks

Engineering Contradiction:
ImproveSubscription managementVSAvoidUser tracking and DOS attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The identification system is segmented into PLMN-level identification (for network routing) and NPN-level identification (for service-specific authentication and privacy protection). This segmentation allows the network to route signaling correctly while protecting the UE's NPN subscription privacy, preventing tracking and DOS attacks targeting specific NPN services.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The enhanced SUCI acts as an intermediary that carries both PLMN routing information and NPN subscription information without exposing the underlying SUPI. This intermediary structure enables the network to perform routing and authentication functions while maintaining privacy protection, as the actual SUPI remains concealed.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If the PLMN hosts NPN services, then resource utilization is improved, but the selection of appropriate AUSF and UDM instances for NPN services fails due to lack of NPN-specific information

Engineering Contradiction:
ImproveNetwork resource utilizationVSAvoidNPN service subscription information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The SUCI structure is segmented to include NPN-specific service information that enables the PLMN to identify which NPN services a UE is subscribed to. This allows the network to efficiently route NPN-related signaling to the appropriate AUSF and UDM instances that handle NPN services, improving resource utilization while maintaining service-specific functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the SUCI structure serve different local functions: PLMN-specific components enable general network routing, while NPN-specific components enable precise routing to NPN service handling nodes. This local quality differentiation ensures that each network node receives the specific information it needs for its function, improving overall system efficiency.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12289597B2Method for establishing a secure connection between a UE and a network, a user equipment and a communication system
Publication Date: 2025.04.29 NEC CORP
  • US12289597B2 patent drawing
  • US12289597B2 patent drawing
  • US12289597B2 patent drawing

AI summary

The present disclosure provides a User Equipment (UE) comprising a transceiver circuit; and a controller configured to control the transceiver circuit to send, to an Access and mobility Management Function (AMF) of a communication node, an identifier, wherein upon successful authentication of a network access function of the UE in the communication node, the controller is configured to maintain a secure connection with the communication node.