Description
The Subscription Concealed Identifier (SUCI) is a fundamental security and privacy feature introduced in 5G, defined in 3GPP Release 15. It is a one-time-use identifier transmitted by the User Equipment (UE) in place of the permanent Subscription Permanent Identifier (SUPI) during the initial registration procedure, specifically in the Registration Request message. The SUCI is generated by the UE itself using a standardized scheme called ECIES (Elliptic Curve Integrated Encryption Scheme) profile A. The UE encrypts the SUPI using the public key of the home network's Subscription Identifier De-concealing Function (SIDF), which is securely provisioned in the UE (e.g., in the Universal Integrated Circuit Card (UICC)). The output is a string that includes the Home Network Public Key Identifier, the ECIES scheme identifier, the ciphertext, and the MAC tag.
Upon receiving the SUCI, the serving network (e.g., the Visited Public Land Mobile Network (VPLMN)) forwards it to the home network (HPLMN) as part of the authentication procedure. The home network's SIDF, which holds the corresponding private key, is the only entity capable of decrypting the SUCI to retrieve the plaintext SUPI. This decryption occurs within the home network's Unified Data Management (UDM) or Authentication Server Function (AUSF). The SUPI is then used for subscriber authentication and to derive the 5G Globally Unique Temporary Identifier (5G-GUTI) for subsequent signaling. Crucially, the serving network never sees the SUPI in clear text, protecting the subscriber's permanent identity from the visited operator and any passive eavesdroppers on the radio link.
The architecture for SUCI involves several network functions. The UE contains the USIM application which stores the home network public key and performs the encryption. The Access and Mobility Management Function (AMF) in the serving network receives the SUCI and routes it to the appropriate home network. The SIDF, typically collocated with the UDM/AUSF, performs the de-concealment. SUCI is mandatory for 5G initial registration when the UE does not have a valid 5G-GUTI, making it a cornerstone of 5G's enhanced subscriber privacy. Its use is governed by the subscriber's privacy settings, but the default and encouraged mode is to always use SUCI for initial registration, marking a significant shift from 4G where the permanent International Mobile Subscriber Identity (IMSI) was often sent in clear text during initial attach.
Purpose & Motivation
SUCI was created to solve a critical and long-standing privacy vulnerability in cellular networks: the exposure of the user's permanent subscriber identity (IMSI in 2G/3G/4G) over the radio interface. In previous generations, the IMSI was often transmitted in clear text during initial network attachment or in certain failure scenarios. This allowed passive eavesdroppers with inexpensive equipment (IMSI catchers or stingrays) to track individuals' locations and movements, conduct targeted attacks, or perform identity mapping. This vulnerability was a major privacy concern and eroded user trust.
The motivation for SUCI stemmed from regulatory pressures (e.g., GDPR), heightened societal awareness of digital privacy, and the technical opportunity presented by the clean-slate design of the 5G core network (5GC). 3GPP designed SUCI as a key component of 5G's enhanced subscriber privacy architecture. It addresses the limitation of previous temporary identifiers (like TMSI/GUTI) which could not always be used—if a UE entered a new area without a valid temporary ID, it had to fall back to sending the IMSI in clear text. SUCI eliminates this fallback vulnerability by ensuring the permanent identity is never exposed, even on the first contact.
Furthermore, SUCI supports the separation of the serving network from the home network in terms of identity knowledge. This aligns with the network slicing and service-based architecture principles of 5G, where a serving network should provide connectivity without necessarily knowing the subscriber's true identity. By solving the pervasive tracking problem, SUCI enables more secure and privacy-respecting use cases, including critical IoT and government services, where anonymity of the device is paramount until authenticated by the home domain.
Classification
Release Timeline
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (80 CRs across 5 releases). Complements the general historical overview above with the evidence-based evolution of this function.
In Release 15, the SUCI (Subscription Concealed Identifier) was introduced as a privacy-preserving identifier containing the concealed SUPI. It was defined with a specific structure including a SUPI Type, a Routing Indicator for network routing, and support for a null protection scheme. The release also standardized the SUCI's encoding in a Network Access Identifier (NAI) format, such as `username@realm`, and defined its use for procedures like registration for emergency services and transmission in a DEREGISTRATION REQUEST message.
- SUCI encoding format and protection scheme TS 24.501CR0254
- Modify structure of SUCI Calc EF and introduce Routing Indicator TS 31.102CR0797
- AMF functionality clarification - to add SUCI TS 23.501CR0220
- UDM functionality support for SUCI TS 23.501CR0225
- SUCI encoding and support of NAI format TS 24.501CR0615
- Transmission of SUCI in DEREGISTRATION REQUEST TS 24.501CR0690
+ 24 more changes
In Release 16, the SUCI function was extended to support new SUPI types and access scenarios. Key additions included formal definitions for SUCI containing a GLI (Generic Line Identifier) or GCI (Generic Cable Identifier) for wireline access, and the specification of a "Decorated NAI" format for SUCI to support specific roaming use cases like 5G NSWO. The release also provided clarifications on the use of the null-scheme, anonymous SUCI procedures, and the SUCI's application for devices like 5G-RG and FN-RG.
- SUPI and SUCI for wireline access TS 23.501CR0744
- SUPI and SUCI for legacy wireline access TS 24.502CR0118
- SUPI/SUCI of N5GC devices TS 24.502CR0143
- SUCI value with SUPI format NSI TS 31.102CR0879
- Support of SUCI for SUPI Type GLI and GCI TS 31.102CR0896
- SUCI computation: implementers' test data for network specific identifier-based SUPI TS 33.501CR0847
+ 11 more changes
In Release 17, key enhancements for the SUCI function included the formal definition and usage procedures for an "anonymous SUCI" for privacy, the specification of a "Decorated NAI format" to support specific roaming use cases like 5G NSWO, and clarifications for SUCI handling in SNPN and trusted non-3GPP access scenarios. These updates also provided detailed examples and regular expression patterns for SUCI formatting to ensure consistent implementation.
- Anonymous SUCI TS 23.003CR0626
- Format of SUCI/SUPI used for Onboarding TS 23.501CR3097
- AUSF/UDM discovery based SUCI information TS 23.501CR3170
- Anonymous SUCI TS 24.501CR3847
- NF discovery based on SUCI information TS 29.518CR0444
- Decorated NAI format for SUCI TS 23.003CR0633
+ 16 more changes
In Release 18, key enhancements for the SUCI function included clarifications and new formats for anonymous SUCI usage, particularly for trusted non-3GPP access in SNPNs and for 5G NSWO contexts. Specifically, the release defined a modified username format for anonymous SUCI in SNPN scenarios, appending a 64-bit random number, and provided updates for the Decorated NAI format for 5G NSWO roaming. It also removed the Network Identifier (NID) from the realm for IMSI-based SUCI and introduced test cases for SUCI decryption validation.
- Key identifier in AN-parameter when anonymous SUCI is used TS 24.502CR0297
- Clarification of NAI format for Anonymous SUCI TS 23.003CR0690
- SUCI format TS 23.003CR0697
- NAI format for anonymous SUCI with modified username for trusted non-3GPP access connected to 5GCN of an SNPN TS 23.003CR0699
- Anonymous SUCI used by N5CW in SNPN TS 24.502CR0269
- SUCI 5G NSWO context, NOTE 3 modification TS 31.102CR1018
+ 4 more changes
In Release 19, the enhancement for the SUCI function introduced specific handling procedures for SUCI calculation failures. This new functionality provides a defined mechanism to manage scenarios where the generation of a Subscription Concealed Identifier is unsuccessful, ensuring system robustness. The change addresses a previously unspecified error condition within the subscriber identity concealment process.
- SUCI calculation failure handling TS 24.501CR6335
Explore further
Broader topics and technologies where SUCI plays a role.
Defining Specifications
3GPP specifications that define or reference SUCI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 23.003 vj50 | Numbering, addressing and identification in 3GPP | Rel-19 |
| TS 23.501 vk00 | 5G System Architecture Stage 2 | Rel-20 |
| TS 24.501 vj50 | 5G NAS Protocols Specification | Rel-19 |
| TS 24.502 vj20 | 5G Core Access via Non-3GPP Networks; Stage 3 | Rel-19 |
| TS 29.503 vj50 | UDM Service Based Interface Stage 3 | Rel-19 |
| TS 29.518 vj50 | AMF Service Based Interface Protocol | Rel-19 |
| TS 31.102 vj40 | USIM Application Specification | Rel-19 |
| TS 31.122 vi50 | USIM Conformance Test Specification | Rel-18 |
| TS 33.126 vj30 | Lawful Interception Requirements | Rel-19 |
| TS 33.127 vj50 | Lawful Interception Architecture and Functions | Rel-19 |
| TS 33.501 vk00 | 5G Security Architecture and Procedures | Rel-20 |
| TS 33.514 vk00 | 5G Security Assurance for UDM | Rel-20 |
| TS 33.835 vg10 | Study on authentication and key management for apps | Rel-16 |
| TR 33.841 vg10 | Security aspects; Study on 256-bit algorithms for 5G | Rel-16 |