Device Identification Encryption via Segmented Routing and Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized entities can access sensitive device information, such as International Mobile Subscriber Identity (IMSI), leading to potential location tracking and account access, especially on less secure networks, necessitating the concealment of device information during network communication.

Innovation Solution

An authentication server employs a combination engine to combine encrypted device identification with a routing indicator, using a first encryption key unknown to other network entities and a second encryption key known to them, ensuring device information is concealed while maintaining data size compliance with network standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device information is transmitted in clear text for network routing, then network entities can access routing indicators, but unauthorized entities can also access sensitive device information such as IMSI

Engineering Contradiction:
ImprovesecurityVSAvoidrouting indicator accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The device information is segmented into two distinct parts: a routing indicator that remains accessible for network routing purposes, and sensitive device information (such as IMSI) that is encrypted. This segmentation allows the routing function to operate normally while protecting sensitive data from unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authentication server acts as an intermediary between the device and the network. It receives the routing indicator in clear text for routing purposes, while simultaneously encrypting the sensitive device information before transmission to the target network entity. This intermediary approach enables both routing functionality and security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device information is fully encrypted to protect security, then unauthorized access is prevented, but network entities cannot access the routing indicator for proper data routing

Engineering Contradiction:
ImprovesecurityVSAvoidrouting capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The data structure is segmented into a routing indicator portion and a sensitive information portion. The routing indicator is transmitted in clear text to maintain routing capability, while the sensitive information is encrypted to maintain security. This selective encryption approach resolves the contradiction between security and routing functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the transmitted data have different security qualities. The routing indicator portion maintains clear text quality for accessibility by network entities, while the device information portion has encrypted quality for security. This local differentiation of security properties allows both routing and security requirements to be satisfied simultaneously.

Inventive Principle:
Principle #3Local quality

3Reliability

If encryption is applied to device information, then security is enhanced, but data size may increase violating network standards

Engineering Contradiction:
ImprovesecurityVSAvoiddata size
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Instead of encrypting the entire device information packet, only the necessary sensitive portions (such as IMSI) are encrypted. The routing indicator remains in clear text. This partial encryption approach provides security where needed while avoiding unnecessary data size increases that would violate network standards.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11438317B2Device identification encryption
Publication Date: 2022.09.06 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11438317B2 patent drawing
  • US11438317B2 patent drawing
  • US11438317B2 patent drawing

AI summary

In one example in accordance with the present disclosure, a system may comprise a a combination engine to combine an encrypted device identification and a routing indicator resulting in a combined device identification. The system may also include an encryption engine to encrypt the combined device identification and a transmission engine to transmit the encrypted combined device identification.