Virtual SUPI Generation for Wireless Identity Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The transmission of permanent user identities in clear text within 3GPP wireless networks poses a risk of identity theft and leakage, particularly due to the IMSI-catching attack, and existing methods like SUCI encryption are inadequate, especially in partially trusted network environments.
Innovation Solution
A method that involves generating a virtual Subscription Permanent Identifier (SUPI) by the User Equipment (UE) and a UDM unit, which is then used to create an authentication vector sent to the server network, allowing secure communication while maintaining user privacy and adhering to legal interception requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If permanent user identity (SUPI/IMSI) is transmitted in clear text for authentication and lawful interception, then authentication and lawful interception functions are enabled, but user privacy is compromised and vulnerability to identity theft attacks increases
Solution Approach 1:
The patent segments the user identity protection into multiple layers: SUCI encryption layer for initial transmission, virtual SUPI layer for authentication vectors, and temporary identifier layer for ongoing communication. Each layer provides security while enabling specific network functions, thus resolving the contradiction between authentication reliability and identity protection.
Solution Approach 2:
The patent introduces virtual SUPI as an intermediary between the real SUPI and the authentication process. The virtual SUPI is generated by the UDM and used in authentication vectors, preventing exposure of the real SUPI while maintaining authentication functionality. This intermediary mechanism enables both secure authentication and lawful interception without transmitting the permanent identity in clear text.
2Object-affected harmful factors
If SUCI encryption is used to protect user identity, then privacy is improved, but clear text transmission of SUPI is still permitted in certain scenarios creating security gaps
Solution Approach 1:
The patent implements dynamic identity protection where the network transitions from SUCI-encrypted transmission to virtual SUPI-based authentication vectors after initial authentication. This dynamic approach ensures that even when SUPI transmission is permitted by standards, the actual permanent identity remains protected through the virtual identifier mechanism, maintaining security consistency across all scenarios.
Solution Approach 2:
The patent performs preliminary generation of virtual SUPI by the UDM before authentication occurs. This preliminary action ensures that when authentication vectors are created, they already contain the virtual identifier instead of the real SUPI, preventing any potential clear text exposure of the permanent identity from the outset.
3Object-affected harmful factors
If virtual SUPI is generated and used in authentication vectors, then user identity protection is enhanced, but system complexity increases due to additional mapping and generation processes
Solution Approach 1:
The patent implements self-service by having the UDM automatically generate and manage the mapping between real SUPI and virtual SUPI without requiring external intervention. The UDM maintains the mapping internally and seamlessly substitutes virtual identifiers in authentication vectors, reducing the operational complexity despite the enhanced protection mechanism.
Data Source
AI summary
The present disclosure provides a method to protect clear text transmission of user identity in wireless networks. The method includes sending a registration request to a Home Network (HN) to start an authentication process of a User Equipment (UE). In addition, the method includes receiving a subscription concealed identifier (SUCI) at the server network (SN). Further, the method includes generating a Subscription permanent identifier (SUPI) and a privacy key. The Subscription permanent identifier (SUPI) is de-concealed from the subscription concealed identifier (SUCI). Furthermore, the method includes generating and mapping, a virtual Subscription permanent identifier (SUPI) corresponding to the received Subscription permanent identifier (SUPI). Also, the method includes generating and sending, an authentication vector (AV) to the server network (SN). The response message includes the virtual Subscription permanent identifier (SUPI). The server network (SN) generates a globally unique temporary identifier (GUTI).


