5G SUCI Segmentation for NPN Subscription Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The current 5G system lacks a means to identify a UE's NPN subscription, which is necessary for supporting 5G systems that provide both PLMN and NPN services. This leads to issues in selecting the appropriate Access Management Function/Security Anchor Function (AMF/SEAF), Authentication Function (AUSF), and Unified Data Management (UDM) instances for NPN services, resulting in NPN UE identification and node selection failures. Additionally, the lack of privacy protection for UE NPN IDs makes the 5G system vulnerable to user tracking, Denial of Service (DOS), and Distributed Denial of Service (DDOS) attacks.
Innovation Solution
The proposed solution involves enhancing the Subscription Concealed Identifier (SUCI) to include Network Subscription Type information, which allows the 5G system to identify the specific network type a UE is subscribed to. This is achieved by modifying the UE to include a transceiver circuit and a controller that sends an identifier to the AMF, maintaining a secure connection upon successful authentication. The system also involves a method where the UE sends a registration request with SUCI information, which is verified by the AMF and routed to appropriate AUSF and UDM instances based on the network subscription type.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the SUCI contains only PLMN specific information, then the routing to PLMN nodes is simplified, but the identification of NPN subscriptions and selection of appropriate NPN nodes fails
Solution Approach 1:
The SUCI is segmented into distinct components: PLMN-specific routing information (for routing to correct AMF/AUSF/UDM) and NPN-specific subscription information (for identifying NPN service eligibility). This segmentation allows each part to serve its specific function without compromising the other, resolving the contradiction between simplified routing and complete identification.
Solution Approach 2:
The NPN subscription information is extracted as a separate element within the SUCI structure, distinct from the PLMN identification components. This extracted NPN-specific information can be independently processed by the network nodes to determine NPN service eligibility while maintaining the PLMN routing functionality.
2Device complexity
If the UE uses a single SUPI for both PLMN and NPN subscriptions, then the subscription management is simplified, but privacy protection is compromised and the system becomes vulnerable to tracking and attacks
Solution Approach 1:
The identification system is segmented into PLMN-level identification (for network routing) and NPN-level identification (for service-specific authentication and privacy protection). This segmentation allows the network to route signaling correctly while protecting the UE's NPN subscription privacy, preventing tracking and DOS attacks targeting specific NPN services.
Solution Approach 2:
The enhanced SUCI acts as an intermediary that carries both PLMN routing information and NPN subscription information without exposing the underlying SUPI. This intermediary structure enables the network to perform routing and authentication functions while maintaining privacy protection, as the actual SUPI remains concealed.
3Productivity
If the PLMN hosts NPN services, then resource utilization is improved, but the selection of appropriate AUSF and UDM instances for NPN services fails due to lack of NPN-specific information
Solution Approach 1:
The SUCI structure is segmented to include NPN-specific service information that enables the PLMN to identify which NPN services a UE is subscribed to. This allows the network to efficiently route NPN-related signaling to the appropriate AUSF and UDM instances that handle NPN services, improving resource utilization while maintaining service-specific functionality.
Solution Approach 2:
Different parts of the SUCI structure serve different local functions: PLMN-specific components enable general network routing, while NPN-specific components enable precise routing to NPN service handling nodes. This local quality differentiation ensures that each network node receives the specific information it needs for its function, improving overall system efficiency.
Data Source
AI summary
The present disclosure provides a User Equipment (UE) comprising a transceiver circuit; and a controller configured to control the transceiver circuit to send, to an Access and mobility Management Function (AMF) of a communication node, an identifier, wherein upon successful authentication of a network access function of the UE in the communication node, the controller is configured to maintain a secure connection with the communication node.


