UE Challenge Procedure for 5G Network Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security mechanisms in 5G mobile networks are vulnerable to malicious attacks, particularly linkability attacks, due to the lack of robust verification of the network's identity before primary authentication.

Innovation Solution

A UE challenge procedure is introduced, where the user equipment (UE) sends a challenge to the network before primary authentication, and the network responds with a computation proving its possession of the home network's private key, thereby verifying the network's identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE provides its identity to the network before authentication, then the network can establish a security association, but the UE becomes vulnerable to linkability attacks and identity tracking

Engineering Contradiction:
Improvesecurity association establishmentVSAvoidlinkability attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The network performs a preliminary authentication verification by decrypting the SUCI and validating the UE's identity before the UE fully reveals its identity. The network sends an authentication request with encrypted identity information first, verifies it, and only then proceeds with full authentication, preventing premature identity exposure to attackers

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses encrypted identity information (SUCI) as an intermediary between the UE and network. Instead of transmitting plain identity, the UE encrypts it with the network's public key, and the network decrypts it using its private key. This intermediary encryption layer protects the identity from being directly observable by potential attackers while still enabling authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the network uses standard primary authentication procedures, then authentication can be completed, but the mechanism remains vulnerable to malicious attacks

Engineering Contradiction:
Improveauthentication completionVSAvoidmalicious attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by having the network decrypt and verify the UE's encrypted identity (SUCI) before the standard primary authentication procedure begins. This preliminary verification step creates a security barrier that prevents malicious attacks by ensuring only legitimately authenticated UEs proceed to the main authentication flow

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The network performs preliminary actions by decrypting the SUCI and validating the UE identity before engaging in the main authentication exchange. This preliminary step establishes a trusted foundation that makes the subsequent authentication more resistant to attacks, as the network already knows the UE is legitimate before committing to full authentication

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12231586B2UE challenge to a network before authentication procedure
Publication Date: 2025.02.18 NOKIA TECHNOLOGIES OY
  • US12231586B2 patent drawing
  • US12231586B2 patent drawing
  • US12231586B2 patent drawing

AI summary

Systems, methods, and software of performing a UE challenge. In one embodiment, User Equipment (UE) initiates a UE challenge procedure to a home network before engaging in a primary authentication procedure by generating a UE challenge by encrypting a random nonce with a home network public key, and transmitting a first message containing the UE challenge toward the home network. The UE receives a second message containing a challenge response to the UE challenge, processes the challenge response to determine whether the home network decrypted the random nonce in response to the UE challenge, and verifies an identity of the home network when the home network decrypted the random nonce in response to the UE challenge.