Anonymity Server for Push-to-Talk Over Cellular Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current push-to-talk over cellular (PoC) communication systems lack mechanisms to ensure user anonymity, allowing identities to be revealed within group communications, which is a concern for privacy and security, especially in preventing illegal activities.

Innovation Solution

A communication system that includes a server mechanism to detect anonymity requests from user equipment, removing identifying information from user plane messages and inserting anonymous tokens, ensuring that participating users cannot identify the requesting user, while maintaining the ability for authorized monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user plane messages contain identifying information for authentication and billing, then communication reliability is improved, but user privacy and anonymity deteriorate

Engineering Contradiction:
Improvecommunication reliabilityVSAvoiduser privacy violation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary mechanism (anonymization server or gateway) that sits between the user equipment and the network core. This intermediary receives user plane messages, removes identifying information while preserving communication functionality, and forwards anonymized messages to the network. The intermediary enables the system to maintain communication reliability without exposing user identity to network entities, thus resolving the contradiction between reliability and privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts identifying information (such as MSISDN, IMEI, or other unique identifiers) from user plane messages before they reach the network core. By taking out these identifying elements while retaining the essential communication data, the system maintains the functionality needed for reliable communication while eliminating the privacy risks associated with exposing user identity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If identifying information is removed from user plane messages, then user anonymity is improved, but the ability to monitor communications by authorized parties deteriorates

Engineering Contradiction:
Improveuser anonymityVSAvoidmonitoring capability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent applies local quality by differentiating the treatment of different information elements within user plane messages. Certain identifying information is removed to protect user anonymity, while other information elements (such as communication metadata, timing, or content) are preserved to enable authorized monitoring. This selective anonymization allows the system to simultaneously achieve user privacy and maintain legitimate surveillance capabilities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the information contained in user plane messages into two categories: identifying information that should be removed for anonymity, and non-identifying information that should be retained for monitoring purposes. By segmenting and treating these information types differently, the system can provide user anonymity without completely eliminating the ability of authorized parties to monitor communications.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If a server mechanism is added to detect and process anonymity requests, then user privacy protection is improved, but device complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent makes the anonymity server multi-functional by enabling it to perform several tasks: detecting anonymity requests, extracting identifying information, injecting fake identifiers, and forwarding anonymized messages. By combining these functions into a single server entity, the system achieves comprehensive privacy protection without proportionally increasing complexity, as one server handles multiple privacy-related operations rather than requiring separate servers for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs copying by creating fake or dummy identifying information that mimics real identifiers but does not correspond to actual users. The anonymity server generates these fake identifiers and substitutes them for real ones in user plane messages. This copying approach allows the system to maintain the structure and functionality of identifying information while protecting actual user privacy, adding privacy protection with minimal complexity increase.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7889726B2Communication system
Publication Date: 2011.02.15 NOKIA TECHNOLOGIES OY
  • US7889726B2 patent drawing
  • US7889726B2 patent drawing
  • US7889726B2 patent drawing

AI summary

A communication system including a first and second user equipment in communication over a shared floor and a server means for managing the shared floor. According to the system, the server means is arranged to detect an anonymity request from the first user equipment and, responsive to the anonymity request, to prevent the second user equipment from identifying the first user equipment from user plane messages transmitted from the first user equipment to the second user equipment.