Temporary Identification for Anonymized 5G Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication networks, particularly in 5G systems, the use of anonymized subscriber identifiers like anonymous SUCI poses challenges for network access and authentication, especially when a user equipment (UE) registers for the first time or switches access points, as the network cannot correlate sessions due to the anonymous identifier, leading to issues with identification and key usage.

Innovation Solution

A temporary identification, similar to TMSI or GUTI, is generated and shared with the UE, allowing the network to identify and authenticate the UE correctly during registration and mobility scenarios, even when anonymized SUCI is used, by combining network node identifiers, contact information, or random numbers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If anonymized subscriber identifiers (anonymous SUCI) are used for registration, then user privacy is improved, but the network cannot correlate sessions leading to identification and authentication issues

Engineering Contradiction:
Improveuser privacyVSAvoidsession correlation
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent introduces a temporary identification (TMSI-like identifier) as an intermediary between the anonymized SUCI and the network's session management system. This temporary identifier allows the network to correlate sessions and authenticate users without exposing the actual subscriber identity, thus maintaining privacy while enabling reliable session correlation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The identification system is segmented into multiple layers: the anonymized SUCI for initial privacy protection, a temporary identification for session correlation, and the actual subscriber identity stored securely in the network. This segmentation allows each layer to serve its specific function without compromising overall system reliability or privacy.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If anonymized identifiers are used for first-time registration, then user privacy is protected, but authentication and key usage become problematic

Engineering Contradiction:
Improvesubscriber identity privacyVSAvoidauthentication process
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The network performs preliminary actions by generating and assigning a temporary identification to the user equipment during the initial registration process. This temporary identifier is established before actual authentication and key derivation occur, enabling subsequent authentication operations to proceed smoothly without directly exposing the anonymized SUCI.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The temporary identification acts as a mediator that enables authentication and key management operations. Instead of using the anonymized SUCI directly for authentication (which would be problematic), the system uses the temporary identifier that the network controls, allowing authentication to proceed while maintaining the privacy benefits of anonymization.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If temporary identification is generated and shared with UE, then session correlation and authentication are enabled, but network complexity increases

Engineering Contradiction:
Improvesession correlationVSAvoidnetwork node complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The temporary identification serves multiple functions simultaneously: it enables session correlation, facilitates authentication, and acts as a key derivation basis. This multi-functionality reduces the need for separate mechanisms for each purpose, thereby limiting the increase in network complexity despite the added functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240155533A1Anonymous registration with a communication network
Publication Date: 2024.05.09 NOKIA TECHNOLOGIES OY
  • US20240155533A1 patent drawing
  • US20240155533A1 patent drawing
  • US20240155533A1 patent drawing

AI summary

An apparatus for a network node acting as a gateway entity of a second communication network providing access to a first communication network being different to the second communication network, the apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to receive a registration request of a user equipment for a registration to the first communication network via the second communication network, wherein the registration request comprises an anonymized subscriber identification element, to obtain a temporary identification for the user equipment, and to forward the temporary identification for the user equipment to the user equipment.