Description
The Subscription Concealed Identifier (SUCI) is a fundamental security and privacy feature introduced in 5G, defined in 3GPP Release 15. It is a one-time-use identifier transmitted by the User Equipment (UE) in place of the permanent Subscription Permanent Identifier (SUPI) during the initial registration procedure, specifically in the Registration Request message. The SUCI is generated by the UE itself using a standardized scheme called ECIES (Elliptic Curve Integrated Encryption Scheme) profile A. The UE encrypts the SUPI using the public key of the home network's Subscription Identifier De-concealing Function (SIDF), which is securely provisioned in the UE (e.g., in the Universal Integrated Circuit Card (UICC)). The output is a string that includes the Home Network Public Key Identifier, the ECIES scheme identifier, the ciphertext, and the MAC tag.
Upon receiving the SUCI, the serving network (e.g., the Visited Public Land Mobile Network (VPLMN)) forwards it to the home network (HPLMN) as part of the authentication procedure. The home network's SIDF, which holds the corresponding private key, is the only entity capable of decrypting the SUCI to retrieve the plaintext SUPI. This decryption occurs within the home network's Unified Data Management (UDM) or Authentication Server Function (AUSF). The SUPI is then used for subscriber authentication and to derive the 5G Globally Unique Temporary Identifier (5G-GUTI) for subsequent signaling. Crucially, the serving network never sees the SUPI in clear text, protecting the subscriber's permanent identity from the visited operator and any passive eavesdroppers on the radio link.
The architecture for SUCI involves several network functions. The UE contains the USIM application which stores the home network public key and performs the encryption. The Access and Mobility Management Function (AMF) in the serving network receives the SUCI and routes it to the appropriate home network. The SIDF, typically collocated with the UDM/AUSF, performs the de-concealment. SUCI is mandatory for 5G initial registration when the UE does not have a valid 5G-GUTI, making it a cornerstone of 5G's enhanced subscriber privacy. Its use is governed by the subscriber's privacy settings, but the default and encouraged mode is to always use SUCI for initial registration, marking a significant shift from 4G where the permanent International Mobile Subscriber Identity (IMSI) was often sent in clear text during initial attach.
Purpose & Motivation
SUCI was created to solve a critical and long-standing privacy vulnerability in cellular networks: the exposure of the user's permanent subscriber identity (IMSI in 2G/3G/4G) over the radio interface. In previous generations, the IMSI was often transmitted in clear text during initial network attachment or in certain failure scenarios. This allowed passive eavesdroppers with inexpensive equipment (IMSI catchers or stingrays) to track individuals' locations and movements, conduct targeted attacks, or perform identity mapping. This vulnerability was a major privacy concern and eroded user trust.
The motivation for SUCI stemmed from regulatory pressures (e.g., GDPR), heightened societal awareness of digital privacy, and the technical opportunity presented by the clean-slate design of the 5G core network (5GC). 3GPP designed SUCI as a key component of 5G's enhanced subscriber privacy architecture. It addresses the limitation of previous temporary identifiers (like TMSI/GUTI) which could not always be used—if a UE entered a new area without a valid temporary ID, it had to fall back to sending the IMSI in clear text. SUCI eliminates this fallback vulnerability by ensuring the permanent identity is never exposed, even on the first contact.
Furthermore, SUCI supports the separation of the serving network from the home network in terms of identity knowledge. This aligns with the network slicing and service-based architecture principles of 5G, where a serving network should provide connectivity without necessarily knowing the subscriber's true identity. By solving the pervasive tracking problem, SUCI enables more secure and privacy-respecting use cases, including critical IoT and government services, where anonymity of the device is paramount until authenticated by the home domain.
Classification
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (55 CRs across 5 releases). Complements the general historical overview above with the evidence-based evolution of this function.
- Modify structure of SUCI Calc EF and introduce Routing Indicator TS 31.102CR0797
- AMF functionality clarification - to add SUCI TS 23.501CR0220
- UDM functionality support for SUCI TS 23.501CR0225
- SUPI and SUCI as user identities TS 24.502CR0045
- SUCI coding TS 29.503CR0045
- SUCI Encoding TS 29.503CR0107
+ 12 more changes
- SUPI and SUCI for wireline access TS 23.501CR0744
- SUPI and SUCI for legacy wireline access TS 24.502CR0118
- SUPI/SUCI of N5GC devices TS 24.502CR0143
- SUCI value with SUPI format NSI TS 31.102CR0879
- Support of SUCI for SUPI Type GLI and GCI TS 31.102CR0896
- Avoid specifying SUPI / SUCI and PEI used for FN RG both in 23.501 and 23.316 TS 23.501CR1920
+ 5 more changes
- Anonymous SUCI TS 23.003CR0626
- Format of SUCI/SUPI used for Onboarding TS 23.501CR3097
- AUSF/UDM discovery based SUCI information TS 23.501CR3170
- NF discovery based on SUCI information TS 29.518CR0444
- Decorated NAI format for SUCI TS 23.003CR0633
- Realm in SUCI in NAI format TS 23.003CR0634
+ 8 more changes
- Key identifier in AN-parameter when anonymous SUCI is used TS 24.502CR0297
- Clarification of NAI format for Anonymous SUCI TS 23.003CR0690
- SUCI format TS 23.003CR0697
- NAI format for anonymous SUCI with modified username for trusted non-3GPP access connected to 5GCN of an SNPN TS 23.003CR0699
- Anonymous SUCI used by N5CW in SNPN TS 24.502CR0269
- SUCI 5G NSWO context, NOTE 3 modification TS 31.102CR1018
+ 4 more changes
Explore further
Broader topics and technologies where SUCI plays a role.
Defining Specifications
3GPP specifications that define or reference SUCI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 23.003 vk00 | Numbering, Addressing and Identification | Rel-20 |
| TS 23.501 vk20 | 5G System Architecture Stage 2 | Rel-20 |
| TS 24.501 vk00 | 5G System (5GS) Non-Access Stratum (NAS) Protocol | Rel-20 |
| TS 24.502 vk00 | Non-3GPP Access Network Discovery and Selection | Rel-20 |
| TS 29.503 vk00 | UDM Service Based Interface Stage 3 | Rel-20 |
| TS 29.518 vk00 | 3GPP TS 29518 vk00: Namf Service Based Interface | Rel-20 |
| TS 31.102 vj50 | USIM Application for 3GPP Telecom Networks | Rel-19 |
| TS 31.122 vi60 | USIM UICC Conformance Test Specification | Rel-18 |
| TS 33.126 vj30 | Lawful Interception Requirements | Rel-19 |
| TS 33.127 vj70 | Lawful Interception Architecture and Functions | Rel-19 |
| TS 33.501 vk20 | 5G Security Architecture and Procedures | Rel-20 |
| TS 33.514 vk10 | 3GPP TS 33514 vk10: UDM Network Product Security Requirements | Rel-20 |
| TS 33.835 vg10 | Study on authentication and key management for apps | Rel-16 |
| TR 33.841 vg10 | Security aspects; Study on 256-bit algorithms for 5G | Rel-16 |