School of Specs 24.501v20.0.0

3GPP 24.501 v20.0.0 — the document's own text

5.3.2 Permanent identifiers

Taught in 4. Inside TS 24.501, the document at the centre (CT1 — the group that writes what your phone says, overview).

A globally unique permanent identity, the 5G subscription permanent identifier (SUPI), is allocated to each subscriber for 5GS-based services. The IMSI, the network specific identifier, the GCI and the GLI are valid SUPI types. When the SUPI contains a network specific identifier, a GCI or a GLI, it shall take the form of a network access identifier (NAI). When the UE performs initial registration for onboarding services in SNPN or is registered for onboarding services in SNPN, the SUPI contains the onboarding SUPI derived from the default UE credentials for primary authentication. The UE derives the onboarding SUPI before or during the initial registration for onboarding services in SNPN and uses the derived onboarding SUPI in the initial registration for onboarding services in SNPN and while registered for onboarding services in SNPN.

The structure of the SUPI and its derivatives are specified in 3GPP TS 23.003 [4].

The UE provides the SUPI to the network in concealed form. The SUCI is a privacy preserving identifier containing the concealed SUPI. When the SUPI contains a network specific identifier, a GCI or a GLI, the SUCI shall take the form of an NAI as specified in 3GPP TS 23.003 [4].

A UE supporting N1 mode includes a SUCI:

  • in the REGISTRATION REQUEST message when the UE is attempting initial registration procedure and a valid 5G-GUTI is not available;
  • in the IDENTITY RESPONSE message, if the SUCI is requested by the network during the identification procedure; and
  • in the DEREGISTRATION REQUEST message when the UE initiates a de-registration procedure and a valid 5G-GUTI is not available.

If the UE uses the "null-scheme" as specified in 3GPP TS 33.501 [24] to generate a SUCI, the SUCI contains the unconcealed SUPI.

When:

  • not operating in SNPN access operation mode; or
  • operating in SNPN access operation mode but not performing initial registration for onboarding services and not registered for onboarding services;

the UE shall use the "null-scheme" if:

  • the home network has not provisioned the public key needed to generate a SUCI;
  • the home network has configured "null-scheme" to be used for the UE;
  • the UE needs to perform a registration procedure for emergency services and the USIM is still considered as valid after the failure of authentication procedure or after reception of a REGISTRATION REJECT message with the 5GMM cause #3 "Illegal UE", #6 "Illegal ME" or #7 "5GS services not allowed", or to initiate a de-registration procedure before the registration procedure for emergency services was completed successfully, and the UE does not have a valid 5G-GUTI for the selected PLMN; or
  • the UE receives an identity request for SUCI during a registration procedure for emergency services or during a de-registration procedure that was initiated before the registration procedure for emergency services was completed successfully.

When operating in SNPN access operation mode and:

  • performing initial registration for onboarding services; or
  • registered for onboarding services;

the UE shall use the "null-scheme" if:

  • the public key needed to generate a SUCI is not configured as part of the default UE credentials for primary authentication; or
  • "null-scheme" usage is configured as part of the default UE credentials for primary authentication.

If:

  • the UE uses the "null-scheme" as specified in 3GPP TS 33.501 [24] to generate a SUCI;
  • the UE operates in SNPN access operation mode and:
    • an indication to use anonymous SUCI which is associated with the selected entry of the "list of subscriber data", is configured in the ME, if the UE is not registering or registered for onboarding services in SNPN; or
    • an indication to use anonymous SUCI which is associated with the default UE credentials for primary authentication, is configured in the ME, if the UE is registering or registered for onboarding services in SNPN;

NOTE 1: The ME can be configured with an indication to use anonymous SUCI associated with an entry of "list of subscriber data" when the EAP method associated with the credentials of the entry supports SUPI privacy at the EAP layer, or can be configured with an indication to use anonymous SUCI associated with the default UE credentials for primary authentication when the EAP method associated with the default UE credentials for primary authentication supports SUPI privacy at the EAP layer, or both.

  • the UE does not need to perform a registration procedure for emergency services, or to initiate a de-registration procedure before the registration procedure for emergency services was completed successfully; and
  • the UE does not receive an identity request for SUCI during a registration procedure for emergency services or during a de-registration procedure that was initiated before the registration procedure for emergency services was completed successfully;

then the UE shall use anonymous SUCI as specified in 3GPP TS 23.003 [4].

A W-AGF acting on behalf of an FN-RG shall use the "null-scheme" as specified in 3GPP TS 33.501 [24] to generate a SUCI.

A W-AGF acting on behalf of an N5GC device shall use the "null-scheme" as specified in 3GPP TS 33.501 [24] to generate a SUCI.

If the 5G-RG acting on behalf of the AUN3 device has not obtained a SUCI from the AUN3 device, the 5G-RG acting on behalf of the AUN3 device shall use the "null-scheme" as specified in 3GPP TS 33.501 [24] to generate a SUCI for the AUN3 device.

If a UE is a MUSIM UE, the UE shall use a separate permanent equipment identifier (PEI) for each USIM, if any, and each entry of "list of subscriber data", if any, the UE operates for accessing 5GS-based services; otherwise, a UE contains and uses a permanent equipment identifier (PEI) for accessing 5GS-based services. When the UE is registered with a network by using a USIM or an entry of "list of subscriber data", and has provided a PEI, then until the UE is de-registered from the network using the USIM or the entry of "list of subscriber data", the UE shall keep using that PEI in the registration using the USIM or the entry of "list of subscriber data" and shall not provide that PEI in registration using another USIM or another entry of "list of subscriber data".

In this release of the specification, the IMEI, the IMEISV, the MAC address together with the MAC address usage restriction indication and the EUI-64 are the only PEI formats supported by 5GS. The structure of the PEI and its formats are specified in 3GPP TS 23.003 [4].

Each UE supporting at least one 3GPP access technology (i.e. satellite NG-RAN, NG-RAN, satellite E-UTRAN, E-UTRAN, UTRAN or GERAN) contains a PEI in the IMEI format and shall be able to provide an IMEI and an IMEISV upon request from the network.

Each UE not supporting any 3GPP access technologies and supporting NAS over untrusted or trusted non-3GPP access shall have a PEI in the form of the Extended Unique Identifier EUI-64 [48] of the access technology the UE uses to connect to the 5GC.

A UE supporting N1 mode includes a PEI:

  • when neither SUPI nor valid 5G-GUTI is available to use for emergency services in the REGISTRATION REQUEST message with 5GS registration type IE set to "emergency registration";
  • when the network requests the PEI by using the identification procedure, in the IDENTITY RESPONSE message; and
  • when the network requests the IMEISV by using the security mode control procedure, in the SECURITY MODE COMPLETE message.

Each 5G-RG supporting only wireline access and each FN-RG shall have a permanent MAC address configured by the manufacturer. For 5G-CRG, the permanent MAC address configured by the manufacturer shall be a cable modem MAC address.

When the 5G-RG contains neither an IMEI nor an IMEISV, the 5G-RG shall use as a PEI the 5G-RG's permanent MAC address configured by the manufacturer and the MAC address usage restriction indication set to "no restrictions".

The W-AGF acting on behalf of the FN-RG shall use as a PEI the MAC address provided by the FN-RG and if the MAC address provided by the FN-RG is not unique or does not correspond to the FN-RG's permanent MAC address according to W-AGF's configuration, the MAC address usage restriction indication set to "MAC address is not usable as an equipment identifier" otherwise the MAC address usage restriction indication set to "no restrictions".

The 5G-RG, when acting on behalf of an AUN3 device, shall use the MAC address provided by the AUN3 device as a PEI.

The 5G-RG containing neither an IMEI nor an IMEISV or the 5G-RG acting on behalf of the AUN3 device shall include the PEI containing the MAC address together with the MAC address usage restriction indication:

  • when neither SUPI nor valid 5G-GUTI is available to use for emergency services in the REGISTRATION REQUEST message with 5GS registration type IE set to "emergency registration";
  • when the network requests the PEI by using the identification procedure, in the IDENTIFICATION RESPONSE message; and
  • when the network requests the IMEISV by using the security mode control procedure, in the SECURITY MODE COMPLETE message.

NOTE 2: In case c) above, the MAC address is provided even though AMF requests the IMEISV.

The W-AGF acting on behalf of the FN-RG shall include the PEI containing the MAC address together with the MAC address usage restriction indication:

  • when the network requests the PEI by using the identification procedure, in the IDENTIFICATION RESPONSE message; and
  • when the network requests the IMEISV by using the security mode control procedure, in the SECURITY MODE COMPLETE message.

NOTE 3: In case b) above, the MAC address is provided even though AMF requests the IMEISV.

The W-AGF acting on behalf of the N5GC device shall use as a PEI the MAC address provided by the N5GC device and the MAC address usage restriction indication set to "no restrictions". Based on operator policy, the W-AGF acting on behalf of the N5GC device may encode the MAC address of the N5GC device using the EUI-64 format as specified in [48] and use as a PEI the derived EUI-64.

NOTE 4: The MAC address of an N5GC device is universally/globally unique.

The AMF can request the PEI at any time by using the identification procedure.

If the TWIF acting on behalf of the N5CW device receives the decorated NAI for N5CW device as defined in clause 28.7.7.1 or 28.7.7.2 of 3GPP TS 23.003 [4] from the N5CW device, the TWIF shall first convert the decorated NAI into an NAI as specified in TS 23.502 [9], i.e. for decorated NAI taking the form "homerealm!username@otherrealm":

  • replace the 'otherrealm' part with the 'homerealm' part; and
  • remove 'homerealm!'.

As a result of specified above, the converted NAI takes the form "username@homerealm". The TWIF shall include the converted NAI as a SUPI with SUPI format "network specific identifier" in the REGISTRATION REQUEST message.