Sign In to Follow Application
View All Documents & Correspondence

Communication Terminal, Network Device, Communication Method, And De Concealment Method

Abstract: A communication terminal (10) according to the present disclosure has a control means for generating a subscription concealed identifier (SUCI) that includes a subscription permanent identifier (SUPI) that is concealed using a prescribed protection scheme and a protection scheme identifier that identifies a protection scheme, and a transmission means for transmitting the SUCI to a first network device during a registration process in order for a second network device to de-conceal the SUPI from the SUCI on the basis of the protection scheme used for generating the SUCI.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
10 July 2020
Publication Number
37/2020
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
archana@anandandanand.com
Parent Application
Patent Number
Legal Status
Grant Date
2024-01-05
Renewal Date

Applicants

NEC CORPORATION
7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001

Inventors

1. BASKARAN Sheeba Backia Mary
c/o NEC Technologies India Pvt. Ltd., SP Infocity, Block-A, 9th Floor, Module-2A, 40, MGR Salai, Kandanchavadi, Perungudi, Chennai, Tamil Nadu 600096
2. LAKSHMINARAYANAN Sivakamy
c/o NEC Technologies India Pvt. Ltd., SP Infocity, Block-A, 9th Floor, Module-2A, 40, MGR Salai, Kandanchavadi, Perungudi, Chennai, Tamil Nadu 600096
3. PRASAD Anand Raghawa
c/o NEC Corporation, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001
4. ARUMUGAM Sivabalan
c/o NEC Technologies India Pvt. Ltd., SP Infocity, Block-A, 9th Floor, Module-2A, 40, MGR Salai, Kandanchavadi, Perungudi, Chennai, Tamil Nadu 600096
5. ITO Hironori
c/o NEC Corporation, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001
6. YOSHIZAWA Takahito
c/o NEC Laboratories Europe GmbH, Kurfursten-Anlage 36, Heidelberg 69115

Specification

Title of invention: communication terminal, network device, communication method, and non-concealment method
Technical field
[0001]
 The present disclosure relates to a next-generation system that can have UDM (Unified Data Management).
Background technology
[0002]
 In the field of mobile communication systems, as disclosed in Non-Patent Document 1 and Non-Patent Document 2, the configuration of a next-generation system called 5G (5 Generation) is under study. In the next-generation system, management of subscriber data and the like by UDM (Unified Data Management) is being considered. UDM provides a process of deciphering (decoding) SUCI (Subscription Concealed Identifier) ​​based on SIDF (Subscription Identifier De-concealing Function) service. SUCI is generated by a UE (User Equipment). SUCI includes a concealed SUPI (Subscription Permanent Identifier).
[0003]
 In the process of deciphering SUCI based on SIDF service, Non-Patent Document 1 discloses that UDM performs deciphering of SUCI to obtain SUPI. The UDM selects the authentication method used for the authentication process between the terminal and the network based on SUPI.
Prior art documents
Non-patent literature
[0004]
Non-Patent Document 1: 3GPP TS 33.501 V0.6.0 (2018-01), Security Architecture and Procedures for 5G System (Release 15)
Non-Patent Document 2: 3GPP TS 23.501 V15.0.0 (2017-12), System Architecture for 5G System Stage 2 (Release 15)
Summary of the invention
Problems to be Solved by the Invention
[0005]
 In the related art described above, the UDM has a problem that it cannot execute the SUCI non-concealment process because the protection method used for concealing the SUPI is unknown.
[0006]
 An object of the present disclosure is to provide a communication terminal, a network device, and a method that solve the above problems.
Means for solving the problems
[0007]
 A communication terminal according to a first aspect of the present disclosure includes a SUCI (subscription concealed identifier) ​​including a SUPI (subscription permanent identifier) ​​that is concealed using a predetermined protection scheme, and a protection scheme identifier that identifies the protection scheme. ) And the protection scheme used to generate the SUCI, the second network device de-conceals the SUPI from the SUCI during the registration process. Transmitting means for transmitting to the first network device.
[0008]
 A network device according to a second aspect of the present disclosure is a SUCI (subscription concealed identifier) ​​generated by a communication terminal, a SUPI (subscription permanent identifier) ​​concealed using a predetermined protection scheme, and the protection. A receiving means for receiving a message including the SUCI including a protection scheme identifier for identifying a scheme, and deciphering the SUPI from the SUCI based on the protection scheme used to generate the SUCI. And a control means.
[0009]
 A communication method according to a third aspect of the present disclosure includes a SUCI (subscription concealed identifier) ​​including a SUPI (subscription permanent identifier) ​​that is concealed using a predetermined protection scheme and a protection scheme identifier that identifies the protection scheme. ) Is generated and the second network device de-conceals the SUPI from the SUCI based on the protection scheme used to generate the SUCI, the first network during the registration process of the SUCI. Send to the device.
[0010]
 A non-concealment method according to a fourth aspect of the present disclosure is a SUCI (subscription concealed identifier) ​​generated by a communication terminal, and a SUPI (subscription permanent identifier) ​​that is concealed using a predetermined protection scheme, A message including the SUCI including a protection scheme identifier that identifies the protection scheme is received, and the SUPI is de-concealed from the SUCI based on the protection scheme used to generate the SUCI.
Effect of the invention
[0011]
 The effect of the present disclosure is that the SUPI can be reliably acquired in the network.
Brief description of the drawings
[0012]
FIG. 1 is a diagram illustrating a SUPI protection method and identification of the method according to the first embodiment, and SUPI non-concealment.
FIG. 2 is a diagram illustrating a MAC generation and SPSI integrity verification process according to the first embodiment.
FIG. 3 is a diagram illustrating an SPSI encryption/decryption process according to the first embodiment.
FIG. 4 is a configuration diagram of a communication terminal according to an embodiment.
FIG. 5 is a configuration diagram of a network device according to an embodiment.
MODE FOR CARRYING OUT THE INVENTION
[0013]
 The inventor says that there are the following two problems in the de-concealment process of SUCI based on the SIDF service.
[0014]
 (I) The UE (User Equipment) generates the SUCI from the SUPI (Subscription Permanent Identifier), but the notification of the SUPI protection scheme (SPSI: SUPI Protection Scheme Identifier/Indicator) used by the UE to the core network is insufficient. There is.
[0015]
 (Ii) Lack of protection against SPSI facilitates tampering with SPSI by an attacker, leading to failure of SUPI deciphering in the core network.
[0016]
 The above two problems will be described in detail below.
[0017]
 (I) Lack of SUPI protection method (SPSI) and its method indication
 (PLMN (Public Land Mobile Network)) Which protection method the home network (PLMN (Public Land Mobile Network) uses for SUPI concealment (for example, SUPI concealment method and its method, or If the home network is not aware of whether the elliptic curve (security profile or security profile) used in SUPI concealment is used in the UE, the home network cannot disguise SUPI. It becomes impossible to identify the subscription/subscriber.
[0018]
 The following scenarios can be considered as problematic scenarios. Various elliptic curves proposed for SUPI concealment in 5G include secp384r1, NIST P-384, NIST P-256, brainpool384, brainpool256, M-383, Curve41417, and Curve25519. UDMs in home networks provide SIDF services, where UDMs are required to handle SUPI de-concealment with different protection schemes simultaneously for multiple subscribers. One obstacle in UDM/SIDF affects the entire SUPI deciphering process in PLMN.
[0019]
 (Ii) SUPI Protection Scheme Identifier (SPSI) integrity and confidentiality protection If
 the SPSI sent by the UE is not protected in transit to the core network, the SPSI may be tampered with by an attacker and is correct in the core network. The SUPI de-concealment process fails, leaving the protection scheme unidentifiable.
[0020]
 (Embodiment 1)
 Hereinafter, a solution to the problems (i) and (ii) will be described in detail.
[0021]
 (1) SUPI protection scheme and its solution to the lack of notification The
 proposed SPSI is a protection scheme and/or method and/or an elliptic curve (ECC Curve) used by the UE to generate SUCI from SUPI. And/or a combination of indicators for identifying the security profile.
[0022]
 Modification: The SUPI security profile identifier is a KDF (Key derivation Function), hash, MAC (Message Authentication Code), mackeylen, maclen, ENC, enckeylen, EC Diffie-Hellman primitive, EC domain parameter, which is supported in SUCI deciphering. A security profile including security parameters such as point compression and backward compatibility mode is shown.
[0023]
 The SPSI is sent by the UE with the SUCI to the network as a sub-parameter thereof or as a sole parameter during the Registration Procedure.
[0024]
 Based on the SPSI received from the UE, the home network identifies the protection scheme or method used for SUPI concealment or the elliptic curve or security profile. The network uses this information to identify the appropriate protection scheme/method/ECC Curve/security profile and thereby decipher (decrypt) SUPI from SUCI.
[0025]
 Hereinafter, the SUPI protection method and the identification of the method, and the SUPI non-concealment will be described with reference to FIG. The numbers described below correspond to the numbers shown in FIG.
[0026]
 1. The SPSI is sent by the UE together with the SUCI in the Registration request message as an individual parameter or as part of the SUCI to an AMF (Authentication Management Field)/SEAF (SEcurity Anchor Function). The registration request message is included in the N1 message.
[0027]
 2. When SEAF sends SUCI to AUSF in Authentication Initiation Request, Authentication Initiation Request includes SPSI. Further, the Authentication Initiation Request includes an SN (Serving Network)-name. The Authentication Initiation Request is included in the N12 message.
[0028]
 3. The AUSF sends an Authentication Information Request (Auth Info-Req) to the UDM together with the following information.
       -SUCI;-Proposed SPSI;
       -serving
       network name;        -Indication
       indicating whether the authentication is intended for 3GPP access or non-3GPP access;
-AUSF performs 5G-AKA The number of AVs (Authentication Vevtor) requested, if configured to.
[0029]
 4. Upon receiving the Auth Info-Req including the SUCI together with the SPSI, the UDM identifies the protection scheme and the method used for generating the SUCI based on the SPSI.
[0030]
 5. The UDM calls the corresponding UDM/SIDF instance or service in order to hide the SUCI.
[0031]
 Variant of step 5: UDM instance calls SIDF service/functionality/function to conceal SUCI.
[0032]
 UDM may provide SIDF services specific to different SUPI protection schemes supported in 5G. (UDM has/provides multiple SIDF instances or services or functionality.)
[0033]
 The UDM/AUDF may use the correct UDM/SIDF to decipher SUCI based on the type of curve signaled by SPSI and/or the SUPI protection scheme and its method, or the security profile used for SUPI concealment. Invoke an instance or SIDF service.
[0034]
 Alternatively, the UDM/AUSF calls the correct UDM/SIDF instance or SIDF service based on the access type.
[0035]
 Alternatively, the UDM/AUSF calls the correct UDM/SIDF instance or SIDF service in order to hide the SUPI based on the SUPI type such as International Mobile Subscriber Identify (IMSI) and non-IMSI type.
[0036]
 Alternatively, the UDM/AUSF invokes the correct UDM/SIDF instance or SIDF service to disguise the SUPI based on the service type or network slice provided to the UE.
[0037]
 Next, the SUPI deciphering and SIDF calling by the home network for the subscription identification procedure initiated by the serving network will be described.
[0038]
 When the AUSF in the home network receives a Subscription identification Request/information request message with SUCI and SPSI from the serving network to hide the SUCI, the AUSF calls the SIDF.
[0039]
 The SPSI is notified by the UE to the AUSF via the serving network.
[0040]
 The home network entity/AUSF calls the correct UDM/SIDF instance to unconceal the SUCI based on the SUPI protection scheme indicated by SPSI.
[0041]
 Next, SUCI non-concealment in the case of a single or multiple UDM instances will be described.
[0042]
 Variant 1: Multiple UDM instances provide SIDF services, where each instance supports all SUPI protection schemes supported in 5G to prevent single points of failure.
[0043]
 Variant 2: Multiple UDM instances provide SIDF services, where each instance supports the specific SUPI protection scheme used in 5G to prevent single points of failure.
[0044]
 Variant 3: For all SUPI protection schemes supported in 5G, multiple UDM instances may provide similar services to prevent a single point of failure.
[0045]
 Variant 4: A particular UDM/SIDF instance is assigned and called to handle a SUPI non-private service request from AUSF/UDM to an entity outside the PLMN.
[0046]
 Variant 5: A particular UDM/SIDF instance is assigned and invoked to handle SUPI non-private service requests from AUSF to third party service providers.
[0047]
 Below are possible SUPI configurations and their formats. All options listed below relate to the SUPI concealment method.
[0048]
 Option 1: ||||
 (||||)
[0049]
 Option 2: ||||
 (||||)
[0050]
 Option 3: Method-Output=||
 (scheme-output =||)
[0051]
 Option 4: Scheme-output = ||
 (scheme-output =||)
[0052]
 Option 5: Method-Output =
 (scheme-output = )
[0053]
 Option 6: As individual parameters of
 N1 message:
[0054]
 Option 7:
 As separate parameters in the N1 message:
[0055]
 Option 8:
 As separate parameters in the N1 message:
[0056]
 Option 9: As an individual parameter of
 the N1 message:
[0057]
 Option 10:
 As separate parameters in the N1 message:
[0058]
 Option 11: Contains a set of all options, where each option 1-10 is concatenated with the MAC.
 (It includes set of all options, where each Option 1 to 10 concatenated with MAC)
[0059]
 (2) Solution of lack of integrity protection of SUPI protection scheme identifier
 SPSI is integrity protected by the UE using a secret key shared between the UE and the home network. The private key is prepared in the UE by the home network in advance or generated in the UE and the home network. If the shared secret key is used for SPSI integrity protection, it may be a temporary (Ephemeral) shared key or a temporary master shared key or a temporary mac key, or an Elliptic curve integrated encryption scheme. keys derived from these keys during implementation of an encryption scheme or other Elliptic curve based protection scheme. The MAC generation and SPSI integrity verification process is shown in FIG.
[0060]
 The home network uses the secret shared key to generate a MAC and verifies the SPSI MAC received from the UE to ensure that the SPSI has not been tampered with by an attacker.
[0061]
 The function (f) used for MAC generation may be any mac algorithm such as NIA-1, NIA-2, and NIA-3.
[0062]
 SPSI is optionally secured by the UE using the HN public key. If the SPSI is secured, the home network uses its private key or a key derived from it to decrypt the SPSI. The SPSI encryption and decryption process is shown in FIG.
[0063]
 The function (f) is a UE side encryption algorithm and a network side decryption algorithm used for SPSI security protection. SPSI security is based on public key cryptography (asymmetric) cryptographic algorithms such as RSA and Elliptic Curve Cryptography (ECC), or other schemes derived therefrom.
[0064]
 SPSI confidentiality has the effect of guaranteeing subscriber/subscription/user privacy in all scenarios, including when a null scheme is used for SUPI concealment/protection.
[0065]
 If an algorithm or function is used for integrity protection or SPSI encryption, it may be (i) negotiated between the UE and the core network, (ii) the algorithm ID/function ID Request) may be transmitted by the UE.
[0066]
 In the present disclosure, the identifiers shown below are used, and further the functions shown below are executed.
1) SUPI protection scheme used in SUPI concealment and an identifier for identifying the method
2) Identifier for identifying an elliptic curve used for
SUPI concealment 3) Identifier for identifying a security profile used in SUPI concealment
4 ) UDM/SIDF instance or service call specific to the protection scheme and method used in
SUPI deciphering 5) UDM/SIDF instance or service call based on SUPI type or access type
6) SPSI using HN public key by UE of security
7) integrity protection of SPSI to use a shared secret key of the UE and the HN
[0067]
 The SUPI protection scheme and its method for lack of method notification comprises the following steps.
 1) The UE sends to the core network entity the SUPI protection scheme used during the implementation of SUPI concealment and its method identifier, or elliptic curve identifier or security profile identifier, to support SUPI deconcealment in the core network. ..
 2) UDM/SIDF in the core network calls SIDF specific to the protection scheme and method used for SUPI concealment.
[0068]
 The method for lack of integrity and confidentiality protection of SUPI protection scheme identifiers includes the following steps.
1) The SPSI sent from the UE to the core network is secured using the HN public key.
2) The SPSI sent from the UE to the core network is integrity protected using the shared secret key.
[0069]
 It should be noted that the present disclosure is not limited to the above-described embodiment, and can be modified as appropriate without departing from the spirit of the present invention.
[0070]
 Subsequently, hereinafter, configuration examples of the communication terminal 10 and the network device 20 described in the above embodiment will be described.
[0071]
 FIG. 4 is a block diagram showing a configuration example of the communication terminal 10. The communication terminal 10 may be a UE. Radio Frequency (RF) transceiver 1101 performs analog RF signal processing for communicating with a base station. The analog RF signal processing performed by the RF transceiver 1101 includes frequency up conversion, frequency down conversion, and amplification. The RF transceiver 1101 is coupled with the antenna 1102 and the baseband processor 1103. That is, the RF transceiver 1101 receives the modulation symbol data from the baseband processor 1103, generates a transmission RF signal, and supplies the transmission RF signal to the antenna 1102. The modulation symbol data may be OFDM (Orthogonal Frequency Division Multiplexing) symbol data. The RF transceiver 1101 also generates a baseband received signal based on the received RF signal received by the antenna 1102, and supplies this to the baseband processor 1103.
[0072]
 The baseband processor 1103 performs digital baseband signal processing (data plane processing) and control plane processing for wireless communication. Digital baseband signal processing includes (a) data compression/decompression, (b) data segmentation/concatenation, and (c) transmission format (transmission frame) generation/decomposition. Further, digital baseband signal processing includes (d) channel coding/decoding, and (e) modulation (symbol mapping)/demodulation. Furthermore, digital baseband signal processing includes generation of OFDM symbol data (baseband OFDM signal) by (f) Inverse Fast Fourier Transform (IFFT). On the other hand, the control plane processing includes communication management of layer 1, layer 2, and layer 3. Layer 1 is, for example, transmission power control. Layer 2 is, for example, radio resource management and hybrid automatic repeat request (HARQ) processing. Layer 3, for example, is signaling for attach, mobility, and call management.
[0073]
 For example, in LTE and LTE-Advanced, digital baseband signal processing by the baseband processor 1103 includes signal processing of Packet Data Convergence Protocol (PDCP) layer, Radio Link Control (RLC) layer, MAC layer, and PHY layer. But it's okay. The control plane processing by the baseband processor 1103 may include processing of Non-Access Stratum (NAS) protocol, RRC protocol, and MAC CE.
[0074]
 The baseband processor 1103 may include a modem processor that performs digital baseband signal processing and a protocol stack processor that performs control plane processing. The modem processor is, for example, a Digital Signal Processor (DSP). The protocol stack processor that performs control plane processing is, for example, a Central Processing Unit (CPU) or a Micro Processing Unit (MPU). In this case, the protocol stack processor that performs the control plane processing may be shared with the application processor 1104 described below.
[0075]
 The application processor 1104 is also called a CPU, MPU, microprocessor, or processor core. The application processor 1104 may include a plurality of processors (a plurality of processor cores). The application processor 1104 realizes various functions of the communication terminal 10 by executing a system software program and various application programs read from the memory 1106 or a memory (not shown). The system software program may be, for example, an operating system (OS). The application program may be, for example, a call application, a WEB browser, a mailer, a camera operation application, or a music reproduction application.
[0076]
 In some implementations, the baseband processor 1103 and the application processor 1104 may be integrated on a single chip, as indicated by the dashed line (1105) in FIG. In other words, the baseband processor 1103 and the application processor 1104 may be implemented as one System on Chip (SoC) device 1105. SoC devices are also sometimes referred to as system large scale integration (LSI) or chipsets.
[0077]
 The memory 1106 is a volatile memory or a non-volatile memory or a combination thereof. Memory 1106 may include multiple physically independent memory devices. The volatile memory is, for example, Static Random Access Memory (SRAM) or Dynamic RAM (DRAM), or a combination thereof. The non-volatile memory is a mask Read Only Memory (MROM), Electrically Erasable Programmable ROM (EEPROM), flash memory, hard disk drive, or any combination thereof. For example, the memory 1106 may include a baseband processor 1103, an application processor 1104, and an external memory device accessible by the SoC 1105. Memory 1106 may include embedded memory devices integrated within baseband processor 1103, application processor 1104, or SoC 1105. Further, the memory 1106 may include a memory in a Universal Integrated Circuit Card (UICC).
[0078]
 The memory 1106 may store a software module (computer program) including a command group and data for performing processing by the communication terminal 10 described in the above embodiment. In some implementations, the baseband processor 1103 or the application processor 1104 may be configured to perform the processing of the communication terminal 10 described in the above embodiments by reading the software module from the memory 1106 and executing the software module. Good.
[0079]
 FIG. 5 is a block diagram showing a configuration example of the network device 20. The network device 20 may be a core network device. The core network device may be an AMF entity, a UDM entity, a SEAF entity, an AUSF entity, an ARPF entity. Referring to FIG. 5, the network device 20 includes a network interface 1201, a processor 1202, and a memory 1203. The network interface 1201 is used to communicate with a network node (eg, AN50, SMF30, etc.). The network interface 1201 may include, for example, a network interface card (NIC) compliant with IEEE (Insititute of Electrical and Electronics Engineers) 802.3 series.
[0080]
 The processor 1202 reads the software (computer program) from the memory 1203 and executes the software to perform the processing of the network device 20 described using the sequence diagram and the flowchart in the above-described embodiment. The processor 1202 may be, for example, a microprocessor, MPU, or CPU. The processor 1202 may include multiple processors.
[0081]
 The memory 1203 is composed of a combination of a volatile memory and a non-volatile memory. Memory 1203 may include storage located remotely from processor 1202. In this case, the processor 1202 may access the memory 1203 via an I/O interface (not shown).
[0082]
 In the example of FIG. 5, memory 1203 is used to store software modules. The processor 1202 can perform the processing of the network device 20 described in the above-described embodiment by reading these software modules from the memory 1203 and executing them.
[0083]
 As described with reference to FIGS. 4 and 5, each of the processors included in the communication terminal 10 and the network device 20 in the above-described embodiment has an instruction group for causing a computer to execute the algorithm described with reference to the drawings. Execute one or more programs that include. This program can be stored using various types of non-transitory computer readable media and supplied to a computer. Non-transitory computer readable media include various types of tangible storage media. Examples of non-transitory computer readable media include magnetic recording media, magneto-optical recording media (eg magneto-optical disks), Compact Disc Read Only Memory (CD-ROM), CD-R, CD-R/W, semiconductor memory. Including. The magnetic recording medium may be a flexible disk, a magnetic tape, or a hard disk drive. The semiconductor memory may be, for example, a mask ROM, a Programmable ROM (PROM), an Erasable PROM (EPROM), a flash ROM, or a Random Access Memory (RAM). For example, the program may also be supplied to the computer by various types of transitory computer readable media. Examples of transitory computer-readable media include electrical signals, optical signals, and electromagnetic waves. The transitory computer-readable medium can supply the program to the computer via a wired communication path such as an electric wire and an optical fiber, or a wireless communication path.
[0084]
 Although the present disclosure has been described with reference to the exemplary embodiments, the present disclosure is not limited to the above. Various modifications that can be understood by those skilled in the art can be made to the configurations and details of the present disclosure within the scope of the disclosure.
[0085]
 This application claims priority based on Indian application 201811100460 filed Jan. 12, 2018, the entire disclosure of which is incorporated herein.
[0086]
 The whole or part of the exemplary embodiments disclosed above can be described as, but not limited to, the following supplementary notes.
 (Supplementary Note 1)
 and SUPI which is concealed using a predetermined protection scheme (subscription permanent identifier), and a control means for generating a Suci (subscription concealed identifier) comprising a protection scheme identifier for identifying the protection scheme,
 the Transmission means for transmitting the SUCI to the first network device during the registration process so that the second network device can hide the SUPI from the SUCI based on the protection scheme used to generate the SUCI. And a communication terminal having.
 (Supplementary
 Note 2) The communication terminal according to Supplementary Note 1, wherein the transmission unit transmits the SUCI by including it in a NAS message.
 (Supplementary Note 3)
 The communication terminal according to Supplementary Note 2, wherein the NAS message is a Registration Request message.
 (Supplementary Note 4)
 The communication terminal according to any one of Supplementary Notes 1 to 3, wherein the second network device is a second core network device.
 (Supplementary Note 5)
 The communication terminal according to Supplementary Note 4, wherein the second core network device is UDM (Unified Data Management).
 (Appendix 6)
 The communication terminal according to any one of appendices 1 to 5, wherein the first network device is a first core network device.
 (Supplementary Note 7)
 The communication terminal according to Supplementary Note 6, wherein the first core network device is an AMF (Authentication Management Field).
 (Supplementary note 8)
 The communication terminal according to any one of supplementary notes 1 to 7, wherein the protection scheme identifier identifies a profile.
 (Supplementary
 Note 9) A SUCI (subscription concealed identifier) ​​generated by a communication terminal, which is concealed using a predetermined protection scheme, and a SUPI (subscription permanent identifier), and a protection scheme identifier for identifying the protection scheme,
 A network device comprising: a receiving unit that receives a message that includes the SUCI that includes the SUCI ;
 (Supplementary note 10) The
 network device according to supplementary note 9, wherein the network device is a core network device.
 (Supplementary Note 11) The
 network device according to Supplementary Note 10, wherein the core network device is UDM (Unified Data Management).
 (Appendix 12)

 Used to generate a  SUCI (subscription concealed identifier) ​​including a SUPI (subscription permanent identifier) ​​anonymized using a predetermined protection scheme and a protection scheme identifier for identifying the protection scheme, and to generate the SUCI. A communication method, wherein the second network device transmits the SUCI to the first network device during a registration process in order to hide the SUPI from the SUCI based on the protection method.
 (Supplementary
 note 13) The communication method according to supplementary note 12, wherein when the SUCI is transmitted to the first network device during the registration process, the SUCI is included in the NAS message and transmitted.
 (Supplementary Note 14)
 The communication method according to Supplementary Note 13, wherein the NAS message is a Registration Request message.
 (Supplementary note 15)
 The communication method according to any one of supplementary notes 12 to 14, wherein the second network device is a second core network device.
 (Supplementary Note 16)
 The communication method according to Supplementary Note 15, wherein the second core network device is UDM (Unified Data Management).
 (Supplementary note 17)
 The communication method according to any one of claims 12 to 16, wherein the first network device is a first core network device.
 (Appendix 18)
 18. The communication method according to attachment 17, wherein the first core network device is an AMF (Authentication Management Field).
 (Supplementary note 19)
 The communication method according to any one of supplementary notes 12 to 18, wherein the protection method identifier identifies a profile.
 (Supplementary
 Note 20) SUCI (subscription concealed identifier) ​​generated by the communication terminal, which is concealed using a predetermined protection scheme, and a SUPI (subscription permanent identifier), and a protection scheme identifier for identifying the protection scheme, A
 non-concealment method , which receives a message including the SUCI including, and de-conceals the SUPI from the SUCI based on the protection scheme used to generate the SUCI.
 (Supplementary Note 21) The
 non-concealment method according to Supplementary Note 20, wherein the non-concealment method is executed in a core network device.
 (Supplementary Note 22)
 The non-concealment method according to Supplementary Note 21, wherein the core network device is UDM (Unified Data Management).
Explanation of symbols
[0087]
 10 communication terminal
 20 network device
 1101 RF transceiver
 1102 antenna
 1103 baseband processor
 1104 application processor
 1105 SoC
 1106 memory
 1201 network interface
 1202 processor
 1203 memory
The scope of the claims
[Claim 1]
 SUPI which is concealed with the predetermined protection schemes and (subscription permanent identifier), a protection scheme identifier for identifying the protection system, and a control means for generating a SUCI (subscription concealed identifier) comprising,
 generating the Suci A second network device for transmitting the SUCI to the first network device during a registration process in order to keep the SUPI from the SUCI unencrypted, based on the protection scheme used for Communication terminal.
[Claim 2]
 The communication terminal according to claim 1, wherein the transmitting unit includes the SUCI in a NAS message and transmits the NAS message.
[Claim 3]
 The communication terminal according to claim 2, wherein the NAS message is a Registration Request message.
[Claim 4]
 The communication terminal according to any one of claims 1 to 3, wherein the second network device is a second core network device.
[Claim 5]
 The communication terminal according to claim 4, wherein the second core network device is UDM (Unified Data Management).
[Claim 6]
 The communication terminal according to any one of claims 1 to 5, wherein the first network device is a first core network device.
[Claim 7]
 The communication terminal according to claim 6, wherein the first core network device is an AMF (Authentication Management Field).
[Claim 8]
 The communication terminal according to any one of claims 1 to 7, wherein the protection scheme identifier identifies a profile.
[Claim 9]
 A SUCI (subscription concealed identifier) ​​generated by a communication terminal, the SUCI including a SUPI (subscription permanent identifier) ​​concealed using a predetermined protection scheme, and a protection scheme identifier for identifying the protection scheme.
 A network device comprising: a receiving unit that receives a message including a message, and a control unit that de-conceals the SUPI from the SUCI based on the protection scheme used to generate the SUCI.
[Claim 10]
 The network device according to claim 9, wherein the network device is a core network device.
[Claim 11]
 The network device according to claim 10, wherein the core network device is UDM (Unified Data Management).
[Claim 12]

 Used to generate a  SUCI (subscription concealed identifier) ​​including a SUPI (subscription permanent identifier) ​​concealed using a predetermined protection scheme and a protection scheme identifier for identifying the protection scheme, and to generate the SUCI. A communication method, in which the second network device transmits the SUCI to the first network device during the registration process in order to keep the SUPI secret from the SUCI based on the protection method.
[Claim 13]
 The communication method according to claim 12, wherein when the SUCI is transmitted to the first network device during the registration process, the SUCI is included in the NAS message and transmitted.
[Claim 14]
 The communication method according to claim 13, wherein the NAS message is a Registration Request message.
[Claim 15]
 The communication method according to any one of claims 12 to 14, wherein the second network device is a second core network device.
[Claim 16]
 The communication method according to claim 15, wherein the second core network device is UDM (Unified Data Management).
[Claim 17]
 The communication method according to any one of claims 12 to 16, wherein the first network device is a first core network device.
[Claim 18]
 The communication method according to claim 17, wherein the first core network device is an AMF (Authentication Management Field).
[Claim 19]
 The communication method according to claim 12, wherein the protection scheme identifier identifies a profile.
[Claim 20]
 A SUCI (subscription concealed identifier) ​​generated by a communication terminal, the SUCI including a SUPI (subscription permanent identifier) ​​concealed using a predetermined protection scheme, and a protection scheme identifier for identifying the protection scheme. A
 non-concealment method , wherein a message including a message is received, and the SUPI is non-concealed from the SUCI based on the protection scheme used to generate the SUCI.
[Claim 21]
 The non-concealment method according to claim 20, wherein the non-concealment method is executed in a core network device.
[Claim 22]
 The non-concealment method according to claim 21, wherein the core network device is UDM (Unified Data Management).

Documents

Application Documents

# Name Date
1 202017029434-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [10-07-2020(online)].pdf 2020-07-10
2 202017029434-STATEMENT OF UNDERTAKING (FORM 3) [10-07-2020(online)].pdf 2020-07-10
3 202017029434-REQUEST FOR EXAMINATION (FORM-18) [10-07-2020(online)].pdf 2020-07-10
4 202017029434-PRIORITY DOCUMENTS [10-07-2020(online)].pdf 2020-07-10
5 202017029434-POWER OF AUTHORITY [10-07-2020(online)].pdf 2020-07-10
6 202017029434-NOTIFICATION OF INT. APPLN. NO. & FILING DATE (PCT-RO-105) [10-07-2020(online)].pdf 2020-07-10
7 202017029434-FORM 18 [10-07-2020(online)].pdf 2020-07-10
8 202017029434-FORM 1 [10-07-2020(online)].pdf 2020-07-10
9 202017029434-DRAWINGS [10-07-2020(online)].pdf 2020-07-10
10 202017029434-DECLARATION OF INVENTORSHIP (FORM 5) [10-07-2020(online)].pdf 2020-07-10
11 202017029434-COMPLETE SPECIFICATION [10-07-2020(online)].pdf 2020-07-10
12 202017029434-MARKED COPIES OF AMENDEMENTS [18-07-2020(online)].pdf 2020-07-18
13 202017029434-FORM 13 [18-07-2020(online)].pdf 2020-07-18
14 202017029434-Annexure [18-07-2020(online)].pdf 2020-07-18
15 202017029434-AMMENDED DOCUMENTS [18-07-2020(online)].pdf 2020-07-18
16 202017029434-FORM 3 [23-12-2020(online)].pdf 2020-12-23
17 202017029434.pdf 2021-10-19
18 202017029434-FER.pdf 2021-10-19
19 202017029434-Proof of Right [27-01-2022(online)].pdf 2022-01-27
20 202017029434-PETITION UNDER RULE 137 [27-01-2022(online)].pdf 2022-01-27
21 202017029434-OTHERS [27-01-2022(online)].pdf 2022-01-27
22 202017029434-FORM 3 [27-01-2022(online)].pdf 2022-01-27
23 202017029434-FER_SER_REPLY [27-01-2022(online)].pdf 2022-01-27
24 202017029434-DRAWING [27-01-2022(online)].pdf 2022-01-27
25 202017029434-COMPLETE SPECIFICATION [27-01-2022(online)].pdf 2022-01-27
26 202017029434-CLAIMS [27-01-2022(online)].pdf 2022-01-27
27 202017029434-US(14)-HearingNotice-(HearingDate-04-12-2023).pdf 2023-11-10
28 202017029434-FORM 3 [28-11-2023(online)].pdf 2023-11-28
29 202017029434-FORM-26 [01-12-2023(online)].pdf 2023-12-01
30 202017029434-Correspondence to notify the Controller [01-12-2023(online)].pdf 2023-12-01
31 202017029434-Written submissions and relevant documents [19-12-2023(online)].pdf 2023-12-19
32 202017029434-GPA-051223.pdf 2023-12-22
33 202017029434-Correspondence-051223.pdf 2023-12-22
34 202017029434-Response to office action [04-01-2024(online)].pdf 2024-01-04
35 202017029434-PatentCertificate05-01-2024.pdf 2024-01-05
36 202017029434-IntimationOfGrant05-01-2024.pdf 2024-01-05

Search Strategy

1 6(1)E_29-07-2021.pdf

ERegister / Renewals

3rd: 01 Apr 2024

From 09/01/2021 - To 09/01/2022

4th: 01 Apr 2024

From 09/01/2022 - To 09/01/2023

5th: 01 Apr 2024

From 09/01/2023 - To 09/01/2024

6th: 01 Apr 2024

From 09/01/2024 - To 09/01/2025

7th: 03 Jan 2025

From 09/01/2025 - To 09/01/2026