Encrypted Identifier Decryption via Visited Network Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication systems, the transmission of sensitive information like IMSI over the air interface is vulnerable to attacks, as devices may be forced to send permanent identifiers in clear text, even when roaming, and existing encryption methods do not adequately protect these identifiers during roaming scenarios where the home network's secret key is unknown.
Innovation Solution
A method where a first network entity receives an identifier with encrypted parts, determines a second network entity for assistance, and requests decryption assistance from that entity, allowing the use of public and secret key pairs to decrypt the identifier, ensuring secure transmission even when the home network's secret key is not locally available.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If identifiers are transmitted in clear text over the air interface, then transmission simplicity is maintained, but security is compromised and devices are vulnerable to IMSI catching attacks
Solution Approach 1:
The patent introduces a visited network mobile management entity as an intermediary that receives encrypted identifiers from the user equipment, determines the home network entity, requests decryption assistance, and facilitates secure identifier transmission without requiring the user equipment to store home network secret keys. This mediator approach resolves the contradiction by enabling encrypted transmission (improving security) while maintaining operational simplicity through automated decryption assistance.
2Object-affected harmful factors
If encryption is applied to identifiers, then security is improved, but device complexity increases due to key management requirements
Solution Approach 1:
The visited network mobile management entity acts as an intermediary that handles the complex key management operations. It receives the encrypted identifier, determines the appropriate home network entity, and requests decryption assistance without requiring the user equipment to manage home network secret keys. This distributes the complexity to the network side while keeping the user equipment simple.
Solution Approach 2:
The system implements self-service decryption where the home network entity automatically provides decryption assistance to the visited network entity without requiring manual intervention or complex key distribution protocols. The encrypted identifier is sent to the home network, which automatically decrypts it and returns the result, simplifying the overall system operation.
3Reliability
If the home network's secret key is stored locally at the visiting network entity, then decryption capability is improved, but security is worsened due to exposure of sensitive keys across network boundaries
Solution Approach 1:
The patent uses the home network entity as an intermediary that holds the secret keys securely. Instead of storing home network secret keys at the visiting network entity, the system establishes a secure channel to the home network where key management occurs. The home network entity decrypts the identifier using its secure key storage and returns the decrypted result, eliminating the risk of key exposure at network boundaries.
Data Source
AI summary
An identifier containing at least one encrypted part is received at a first network entity. A second network entity may then be determined based on the identifier. A request for assistance in decryption of the identifier from the second network entity may be sent from the first entity to the second network entity. The second network entity may then assist the first networks entity in an appropriate manner.


